You really shouldn't be installing this Flash Player update - here's why

Adobe Flash
(Image credit: Adobe)

If you were surprised to see a prompt for Flash Player update on your phone, thinking the poor thing died years ago - you’re right. It did die, and the “update” that’s been making rounds online is actually an attempt to get gullible people to install malware onto the endpoints.

Cybersecurity researchers from MalwareHunterTeam have spotted an SMS phishing campaign targeting Android users. In that campaign, the target would receive an SMS message saying that video upload that they initiated couldn’t be completed without an update to the Flash Player. The same SMS message also provides a link where the “update” ca be found.

However, instead of the actual update, the victims would download the FluBot malware - an Android banking trojan that steals login information by overlaying many global banks.

Downloading Android apps from trusted sources

Besides stealing the users’ online identity, FluBot also accesses the device’s contact list and sends out the same message to as many people as possible

It’s been exactly a year since Flash Player was pronounced dead and was no longer available for download. FluBot, on the other hand, gets regular updates. The most recent one, according to the report, was published “only a few days ago”. 

In this version (5.2), the Domain Generation Algorithm (DGA) system generates many new Command and Control (C2) domains on the spot. That way, it is able to circumvent many security measures, such as the DNS blocklist. The newest version now uses 30 top-level domains, compared to three, used in previous versions.

All Android devices come with a simple security measure - they don’t allow any APKs to be installed from anywhere else but the Play Store. Users who decide to turn this feature off and wish to install APKs from elsewhere across the web, should make sure they’re downloading from trusted sources. 

  • You might also want to check out our list of the best firewalls right now

Via: BleepingComputer

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
These fake macOS updates are actually just looking to spread malware
Android phone malware
BADBOX malware hits 30,000 Android devices - make sure you update now
An iPhone sitting on a wooden table
Millions at risk as malicious PDF files designed to steal your data are flooding SMS inboxes - how to stay safe
Android phone malware
This nasty Android malware is posing as the Telegram Premium app
Malware worm
Coordinated global mobile malware campaign targets banking apps and cryptocurrency platforms
 In this photo illustration a Google Play logo seen displayed on a smartphone.
Why is there so much spyware hidden in the Play Store?
Latest in Security
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com
Ransomware
Microsoft uncovers sleuthy new XCSSET MacOS malware campaign
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Meta warns of worrying security flaw hitting open source type software
Hand holding smartphone and scan fingerprint biometric identity for unlock her mobile phone
Biometrics add another layer of security to passwordless authentication
Data leak
Hacked Tata Technologies data leaked by ransomware gang
A close-up photo of an iPhone, with the App Store icon prominent in the center of the image.
Thousands of iOS apps found to expose user data and leak Stripe keys
Latest in News
A graphic of the PC Gaming Show
Get ready for a bounty of PC games on June 8, as the PC Gaming show is back
A smartphone on a sofa showing the WhatsApp, Telegram and Signal apps
Forget AI – WhatsApp is planning a simple messages feature that could be its most useful upgrade in years
NordicTrack Ultra 1
The new NordicTrack Ultra 1 treadmill looks like it was designed by an architect and costs $15,000
An Nvidia GeForce RTX 5070
Nvidia RTX 5080 stock is so barren that retailers are holding competitions where you can "win" the right to buy one for MSRP
Assassin's Creed Shadows
Ubisoft shareholder accuses publisher of 'misleading investors', plans protest outside Paris HQ
Google Gemini AI logo on a smartphone with Google background
I made an AI version of Bilbo Baggins using Goggle Gemini for free, and shared a pipe with him outside Bag End – here’s what you can now do with Gems