This new SMS smishing malware is targeting Android mobile users

Phone malware
(Image credit: Shutterstock)

Security researchers from Proofpoint company Cloudmark have discovered a new piece of mobile malware strain spread via SMS that cybercriminals are using to target users across the US and Canada with Covid-19 lures.

The malware has been dubbed TangleBot because of its many levels of obfuscation and how it is able to control a multitude of entangled device functions including contacts, SMS and phone capabilities, call logs, internet access, camera and microphone.

Just like with the FluBot malware which continues to be a threat in Europe and the UK, TangleBot tries to trick mobile users into downloading malicious software by sending out fake Covid-19 warning notifications. While some of the text messages used in the campaign contain information about regulations, others provide details on vaccine booster shots.

As is the case with many phishing campaigns, these messages create a sense of urgency as users may want to know how Covid regulations have changed in their region or they may be interested in a Covid-19 vaccine booster shot to better protect themselves against new variants of the virus.

TangleBot malware

If a user does happen to click on the link contained in one of the campaign's text messages, a website appears notifying them that Adobe Flash Player is out of date and must be updated. Clicking on the subsequent dialog boxes then installs the TangleBot malware on their Android smartphone.

TangleBot is then granted privileges to access and control numerous devices functions as mentioned above. With this access, an attacker can now make and block phone calls, send, obtain and process text messages, record using the device's camera or microphone as well as record its screen, place overlay screens on the device to cover legitimate apps and implement other device observation capabilities according to a blog post from Cloudmark.

Just like the company's researchers observed with FluBot, TangleBot can overlay banking or financial apps and directly steal a victim's account credentials. However, an attacker can also use a victim's device to message other mobile devices to spread their malware even further. Even if a user discovers TangleBot is installed on their device and removes it, an attacker may not use their stolen information for some time which renders the victim oblivious to the fact that their account credentials have been stolen.

To avoid falling victim to TangleBot and other mobile malware, Cloudmark recommends that users be on the lookout for suspicious text messages from unknown senders and avoid clicking on any links these messages may contain. Also users should avoid installing apps from sources besides the Google Play Store or other official app stores.

TOPICS
Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
Malware worm
Coordinated global mobile malware campaign targets banking apps and cryptocurrency platforms
An iPhone sitting on a wooden table
Millions at risk as malicious PDF files designed to steal your data are flooding SMS inboxes - how to stay safe
mobile phone
Forget phishing, now "mishing" is the new security threat to worry about
Close up of a business person using a smartphone.
Watch out, malicious PDF files are being used again in phishing attacks
Android phone malware
This nasty Android malware is posing as the Telegram Premium app
A display showing off the Google TV homepage, with icons for 1917, Scoob!, YouTube and Twitch (among others)
This dangerous malware botnet now covers 1.6 million Android TVs - find out if you're at risk
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)