Massive SMS stealer campaign infects Android devices in 113 countries

Share:

A malicious campaign targeting Android devices worldwide utilizes thousands of Telegram bots to infect devices with SMS-stealing malware and steal one-time 2FA passwords (OTPs) for over 600 services.

Zimperium researchers discovered the operation and have been tracking it since February 2022. They report finding at least 107,000 distinct malware samples associated with the campaign.

The cybercriminals are motivated by financial gain, most likely using infected devices as authentication and anonymization relays.

Telegram entrapment

The SMS stealer is distributed either through malvertising or Telegram bots that automate communications with the victim.

In the first case, victims are led to pages mimicking Google Play, reporting inflated download counts to add legitimacy and create a false sense of trust.

On Telegram, the bots promise to give the user a pirated application for the Android platform, asking for their phone number before they share the APK file.

The Telegram bot uses that number to generate a new APK, making personalized tracking or future attacks possible.

Zimperium says the operation uses 2,600 Telegram bots to promote various Android APKs, which are controlled by 13 command and control (C2) servers.

Most of the victims of this campaign are located in India and Russia, while Brazil, Mexico, and the United States also have significant victim counts.

Generating money

Zimperium found that the malware transmits the captured SMS messages to a specific API endpoint at the website ‘fastsms.su.’

The site allows visitors to purchase access to “virtual” phone numbers in foreign countries, which they can use for anonymization and to authenticate to online platforms and services.

It is very likely that the infected devices are actively used by that service without the victims knowing it.

The requested Android SMS access permissions allow the malware to capture the OTPs required for account registrations and two-factor authentication.

BleepingComputer has contacted the Fast SMS service to ask about Zimperium’s findings, but a response wasn’t available by publication.

For the victims, this can incur unauthorized charges on their mobile account, while they may also be implicated in illegal activities traced back to their device and number.

To avoid phone number abuse, avoid downloading APK files from outside Google Play, do not grant risky permissions to apps with unrelated functionality, and ensure Play Protect is active on your device.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
11:54 pm, Jan 21, 2025
weather icon 3°C
L: 2° | H: 4°
overcast clouds
Humidity: 89 %
Pressure: 1009 mb
Wind: 3 mph SSE
Wind Gust: 5 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:53 am
Sunset: 4:29 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 9:00 pm
weather icon
2° | 4°°C 1 mm 100% 5 mph 97 % 1009 mb 0 mm/h
Thu Jan 23 9:00 pm
weather icon
3° | 8°°C 1 mm 100% 18 mph 92 % 1005 mb 0 mm/h
Fri Jan 24 9:00 pm
weather icon
5° | 10°°C 1 mm 100% 25 mph 88 % 1004 mb 0 mm/h
Sat Jan 25 9:00 pm
weather icon
2° | 5°°C 0.26 mm 26% 8 mph 84 % 1014 mb 0 mm/h
Sun Jan 26 9:00 pm
weather icon
3° | 7°°C 0 mm 0% 14 mph 85 % 1013 mb 0 mm/h
Tomorrow 12:00 am
weather icon
3° | 3°°C 0 mm 0% 3 mph 89 % 1009 mb 0 mm/h
Tomorrow 3:00 am
weather icon
3° | 3°°C 0 mm 0% 3 mph 92 % 1008 mb 0 mm/h
Tomorrow 6:00 am
weather icon
3° | 4°°C 1 mm 100% 3 mph 95 % 1006 mb 0 mm/h
Tomorrow 9:00 am
weather icon
4° | 4°°C 1 mm 100% 2 mph 97 % 1004 mb 0 mm/h
Tomorrow 12:00 pm
weather icon
4° | 4°°C 0.8 mm 80% 3 mph 94 % 1003 mb 0 mm/h
Tomorrow 3:00 pm
weather icon
4° | 4°°C 0 mm 0% 5 mph 93 % 1002 mb 0 mm/h
Tomorrow 6:00 pm
weather icon
4° | 4°°C 0 mm 0% 4 mph 89 % 1003 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
4° | 4°°C 0 mm 0% 4 mph 90 % 1004 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€101,686.04
2.72%
Ethereum(ETH)
€3,186.69
0.70%
XRP(XRP)
€3.03
0.69%
Tether(USDT)
€0.96
0.12%
Solana(SOL)
€239.02
0.56%
Dogecoin(DOGE)
€0.355845
3.27%
USDC(USDC)
€0.96
0.01%
Shiba Inu(SHIB)
€0.000020
1.65%
Pepe(PEPE)
€0.000015
-0.17%
Peanut the Squirrel(PNUT)
€0.355110
-2.89%
Scroll to Top