Тёмный

Android WhatsApp Worm | spreads via WhatsApp messages to contacts | impersonates Huawei Mobile app 

Android Infosec
Подписаться 392 тыс.
Просмотров 152 тыс.
50% 1

Analysis of Android worm that spreads via WhatsApp messages to your contacts
This malware spreads via victim's WhatsApp by automatically replying to any received WhatsApp message notification with a link to malicious Huawei Mobile app. Message and link that will be send is received dynamically from C&C server. Replying to messages is done via Android Notification Direct Reply actions (if you receive WhatsApp message notification, you can right away “Reply” or “Mark as Read/dismiss”). That is what malware misuses to reply back.
Message is sent only once per hour to the same contact.
Its main functionality looks to be adware or subscription scam.
Warning: Be caution when analyzing malware, this isn't a testing sample, it is actual Android malware found in the wild that will harm your device.
Discovered by @ReBensk: / 1352201093728518149
Sample: koodous.com/apks/1adeaa0dc086...
More information: www.welivesecurity.com/2021/0...
Follow me on Twitter: / lukasstefanko

Наука

Опубликовано:

 

21 янв 2021

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 51   
@ciph3r836
@ciph3r836 3 года назад
Such neat research. The malware author is quite resourceful
@kinjamuruvatin6971
@kinjamuruvatin6971 3 года назад
Great demonstration!! Thank you!!
@imatifktk
@imatifktk 3 года назад
Brilliantly researched analysis!!!
@mobilehacker
@mobilehacker 3 года назад
Thanks a lot Atif!
@bijuverghese8012
@bijuverghese8012 3 года назад
Hi Lukas Stefanko nice demo by the way. How can we verify if the developer is genuine one or not like the Huawei one demo which you showed just now. I was thinking if this could happen with Huawei then it can happen with other apps in google play store also how can users those who are not technically sound protect themselves from being victim of such malware
@ankshitdey3126
@ankshitdey3126 2 года назад
Good job nowadays your sound quality is better
@matthewlemon
@matthewlemon 3 года назад
If you check the APK's on something like Virus Total, most of the top AV's detect the fact that it's a virus.
@currency9641
@currency9641 3 года назад
Nice I am from India
@karakurt8516
@karakurt8516 3 года назад
Is it possible that the hacker sends a picture of his own gallery instead of a message?
@arthursumer6012
@arthursumer6012 3 года назад
bro I want to try to analyze this APK. Can you give me a download address?
@johnantony7803
@johnantony7803 3 года назад
I have just clicked the link but didn't download the app I came back...whether it's ok? Pls reply
@RedOpsArena
@RedOpsArena 3 года назад
Nice video bruh ❤️
@RedOpsArena
@RedOpsArena 3 года назад
But why did Google Play Protect didn't scan the source code
@izpcshop7326
@izpcshop7326 3 года назад
@@RedOpsArena it's a fake google play store website.
@mughalmughal9212
@mughalmughal9212 2 года назад
Nice
@IvanSchob
@IvanSchob 3 года назад
super video like to you
@sivakillergaming9686
@sivakillergaming9686 3 года назад
😍😍😍😍😍😍😍😍
@nayelialmonasi9948
@nayelialmonasi9948 3 года назад
What if you uninstall the app? Does it stay in the system or is it completely deleted?
@mobilehacker
@mobilehacker 3 года назад
If you uninstall the app, it would be completely deleted from the system. It doesn't use such tricks.
@nayelialmonasi9948
@nayelialmonasi9948 3 года назад
@@mobilehacker Oh I see. It only affects as long as it is installed and has all the permissions. Right?
@mobilehacker
@mobilehacker 3 года назад
@@nayelialmonasi9948 Yes, affects only as long as it is installed. It doesn't have all the permissions, it could have been suspicious for user, since user has to manually enable them, but only permissions that are necessary for its functionality.
@nayelialmonasi9948
@nayelialmonasi9948 3 года назад
@@mobilehacker One last question. how did you analyze the app? I mean, you extracted the apk and... How did you get its code? Is it reverse engineering?
@mobilehacker
@mobilehacker 3 года назад
@@nayelialmonasi9948 yes, I used reverse engineering to decompille the apk and then identify its functionality
@kwakuboateng6987
@kwakuboateng6987 3 года назад
what language was the malware written in
@mobilehacker
@mobilehacker 3 года назад
Java
@anandvamsi
@anandvamsi 3 года назад
I want app link
@erpandistro4118
@erpandistro4118 3 года назад
are you androidmalware on instagram ?
@editing_with_ajay
@editing_with_ajay 2 года назад
INDIA se kon h
@DkReaction27
@DkReaction27 4 месяца назад
Me
@teslagaming7444
@teslagaming7444 3 года назад
what will the developer of this fake application get by doing this.
@mobilehacker
@mobilehacker 3 года назад
Its main functionality looks to be adware or subscription scam. Also, at some point, it can switch and start to send more dangerous type of malware or phishing websites to WhatsApp contacts.
@A-M182
@A-M182 3 года назад
@@mobilehacker can a iPhone get that worm too ?
@mobilehacker
@mobilehacker 3 года назад
@@A-M182 no, iPhone can't get that worm
@A-M182
@A-M182 3 года назад
@@mobilehacker thank you I was a bit afraid
@santosh5572
@santosh5572 3 года назад
Could you give that app link?
@mobilehacker
@mobilehacker 3 года назад
You can download the APK sample from here: koodous.com/apks/1adeaa0dc086ed8e362f5aa9335af23866fb2eafcf1b73dd66465f48aadee5f7
@arthursumer6012
@arthursumer6012 3 года назад
@@mobilehacker I can't find a place to download
@mobilehacker
@mobilehacker 3 года назад
@@arthursumer6012 Koodous requires registration before allowing to download any APK samples.
@arthursumer6012
@arthursumer6012 3 года назад
@@mobilehacker thank you bro
@naky73able
@naky73able 3 года назад
v
@thomas_mensen3080
@thomas_mensen3080 3 года назад
Maak langere vids
Далее
Викторина от МАМЫ 🆘 | WICSUR #shorts
00:58
How to Use Whatsapp - 2024 Beginner's Guide
10:21
Просмотров 105 тыс.
How many Spy Cameras are Recording you right now?
10:09
Remotely Control Any Phone and PC with this Free tool!
17:15
Do NOT buy the Freedom Phone!! 🤬
11:47
Просмотров 7 млн
How to Crash Anyone's WhatsApp with 1 Special msg.
4:47
Новые iPhone 16 и 16 Pro Max
0:42
Просмотров 2,2 млн
Battery  low 🔋 🪫
0:10
Просмотров 13 млн