Globe-trotting Roaming Mantis malware is hitting Android and iOS users alike

A white padlock on a dark digital background.
(Image credit: Shutterstock.com)

Roaming Mantis, an Android malware operation that aims to steal sensitive data, and potentially even money, from its victims, has now set its sights to the people of France, cybersecurity researchers are saying. 

Before targeting the French, Roaming Mantis attacked people in Germany, Taiwan, South Korea, Japan, the US, and the U.K., BleepingComputer reports.

This is not the same thing as the Mantis botnet, which recently emerged as one of the largest and most powerful botnets to ever appear.

Tens of thousands of victims

The operation migration was spotted by cybersecurity researchers from SEKOIA. After analyzing the campaign, the researchers discovered that the methodology hasn’t changed much: the victims would first get an SMS, and depending on whether they’re an iOS, or Android user, would be redirected to different sites. 

Apple users would be redirected to a phishing page where the attackers would try and trick them into giving away their credentials, while Android users would be invited to download XLoader (MoqHao), powerful malware that allows threat actors remote access to the compromised endpoint, access to sensitive data, as well as SMS apps (possibly to expand the operation further). 

The researchers believe Roaming Mantis roamed to France in February 2022. Users outside the country, getting the SMS, are safe, as the servers will show a 404 and stop the attack. 

Apparently, the campaign is quite a success, as more than 90,000 unique IP addresses have downloaded XLoader from the main command & control server so far, the researchers have found. With iOS users in the mix, the number grows even further but is, unfortunately, impossible to determine. 

Roaming Mantis is also quite good at keeping a low profile and evading antivirus solutions. It gets C2 configuration from hardcoded Imgur profile destinations, further encoded in base64, it was said. 

Other than that, the campaign’s infrastructure is mostly the same, compared to April, when it was last analyzed, the publication found. The servers still have open ports at TCP/443, TCP/5985, TCP/10081, and TCP/47001, and use the same certificates.

“Domains used inside SMS messages are either registered with Godaddy or use dynamic DNS services such as duckdns.org,” SEKOIA said. 

Via: BleepingComputer

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Malware worm
Coordinated global mobile malware campaign targets banking apps and cryptocurrency platforms
Android phone malware
BADBOX malware hits 30,000 Android devices - make sure you update now
An iPhone sitting on a wooden table
Millions at risk as malicious PDF files designed to steal your data are flooding SMS inboxes - how to stay safe
Android phone malware
Screen reading malware found in iOS app stores for first time - and it might steal your cryptocurrency
A display showing off the Google TV homepage, with icons for 1917, Scoob!, YouTube and Twitch (among others)
This dangerous malware botnet now covers 1.6 million Android TVs - find out if you're at risk
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Industrial routers are being hit by zero-days from new Mirai botnets
Latest in Security
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
AI agents can be hijacked to write and send phishing attacks
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Latest in News
Google Pixel 8a in aloe green showing
Google Pixel 9a benchmark link teases the performance of the upcoming mid-ranger
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 17 (game #1148)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 17 (game #379)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 17 (game #645)
Apple iPhone 16 Pro HANDS ON
Leaked iPhone 17 dummy units may have given us our best look yet at all four models
A super close up image of the Google Gemini app in the Play Store
It's official: Google Assistant will be retired for phones this year, with Gemini taking over