malware – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Sat, 13 Sep 2025 20:37:29 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 malware – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Cross-OS Malware ‘ModStealer’ Threatens Crypto Wallets https://earlybirdsinvest.com/cross-os-malware-modstealer-threatens-crypto-wallets/ https://earlybirdsinvest.com/cross-os-malware-modstealer-threatens-crypto-wallets/#respond Sat, 13 Sep 2025 20:37:28 +0000 https://earlybirdsinvest.com/cross-os-malware-modstealer-threatens-crypto-wallets/

A new malware called ModStealer is spreading across macOS, Windows, and Linux, according to a report by 9to5Mac on September 11.

Researchers from the security company Mosyle found that the malware had been uploaded to VirusTotal but had gone unnoticed by antivirus tools for almost a month.

The malware is written in JavaScript using NodeJS and conceals its code to evade detection.

What is Fantom? | Animated FTM Explainer

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

Once installed, ModStealer runs in the background. It collects information such as wallet keys, certificates, account files, and browser extensions linked to crypto wallets.

Mosyle’s team identified code targeting more than 50 wallet extensions, including those on Safari and Chromium-based browsers.

The malware also records clipboard content, takes screenshots, and can run commands from a remote server. These features give attackers access to private information and control over infected systems.

On macOS, ModStealer exploits Apple’s launchctl tool to run as a LaunchAgent. This allows the malware to remain active even after a reboot. The stolen data is sent to a server that appears to be based in Finland but is connected to infrastructure in Germany.

Mosyle stated that ModStealer may be part of a Malware-as-a-Service model. In such setups, developers create the malware and sell it to affiliates, who then launch attacks without requiring deep technical skills.

Mosyle warned that antivirus tools that rely only on signatures are not enough to stop such threats. They recommend constant monitoring, behavior-based security systems, and more awareness of new attack methods.

Lucija Valentić at ReversingLabs recently reported that hackers have discovered a new method for spreading malicious software by using Ethereum
ETH


$4,656.30

smart contracts. How? Read the full story.


]]>
https://earlybirdsinvest.com/cross-os-malware-modstealer-threatens-crypto-wallets/feed/ 0 58284
Hackers Use Ethereum Smart Contracts to Mask Malware in NPM Packages https://earlybirdsinvest.com/hackers-use-ethereum-smart-contracts-to-mask-malware-in-npm-packages/ https://earlybirdsinvest.com/hackers-use-ethereum-smart-contracts-to-mask-malware-in-npm-packages/#respond Sat, 06 Sep 2025 22:44:13 +0000 https://earlybirdsinvest.com/hackers-use-ethereum-smart-contracts-to-mask-malware-in-npm-packages/

Hackers have discovered a new method for spreading malicious software by using Ethereum
ETH


$4,272.56

smart contracts to conceal crucial aspects of their attacks.

According to a blog post by Lucija Valentić at ReversingLabs, two suspicious software packages were found on the Node Package Manager (NPM), a platform used to share JavaScript code.

These packages, named “colortoolsv2” and “mimelib2“, were uploaded in July and designed to look like regular tools.

What is a Crypto Mining Pool? Is it Worth it? (Beginner-Friendly)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

The packages acted like simple downloaders. When someone installed one, it would reach out to the Ethereum blockchain and fetch data from a smart contract. That data contained the location of a second piece of malware, which would then be downloaded and installed.

This made it hard for security systems to flag the packages as harmful, since they did not include any direct links to malicious websites or files.

Valentić explained that while Ethereum contracts have been misused before, this setup was different. In this case, the smart contract did not hold the malware itself, but held the location where it could be found.

The campaign was not limited to NPM. It also involved a fake open-source project hosted on GitHub. Hackers created a fake cryptocurrency trading bot, complete with fake updates, detailed documentation, and several user accounts to make the project seem active and trustworthy.

On September 1, SlowMist’s Yu Xian reported that attackers stole WLFI tokens from Ethereum wallets. How? Read the full story.


]]>
https://earlybirdsinvest.com/hackers-use-ethereum-smart-contracts-to-mask-malware-in-npm-packages/feed/ 0 57122
VirusTotal finds hidden malware phishing campaign in SVG files https://earlybirdsinvest.com/virustotal-finds-hidden-malware-phishing-campaign-in-svg-files/ https://earlybirdsinvest.com/virustotal-finds-hidden-malware-phishing-campaign-in-svg-files/#respond Sat, 06 Sep 2025 21:43:44 +0000 https://earlybirdsinvest.com/virustotal-finds-hidden-malware-phishing-campaign-in-svg-files/

Malware phishing

VirusTotal has discovered a phishing campaign hidden in SVG files that create convincing portals impersonating Colombia’s judicial system that deliver malware.

VirusTotal detected this campaign after it added support for SVGs to its AI Code Insight platform.

VirusTotal’s AI Code Insight feature analyzes uploaded file samples using machine learning to generate summaries of suspicious or malicious behavior found in the files.

After adding support for SVGs, VirusTotal found an SVG file that had zero detections by antivirus scans, but whose AI-powered Code Insight feature detected using JavaScript to display HTML, impersonating a portal for Colombia’s government judiciary system.

VirusTotal Code insights detecting a malicious SVG file
VirusTotal Code insights detecting a malicious SVG file
Source: VirusTotal

SVG, or Scalable Vector Graphics, is used to generate images of lines, shapes, and text through textual mathematical formulas in the file.

However, threat actors have begun increasingly using SVG files in attacks, as they can also be used to display HTML using the element and execute JavaScript when the graphic is loaded.

In the campaign discovered by Virustotal, SVG image files are used to render fake portals that display a phony download progress bar, ultimately prompting the user to download a password-protected zip archive [VirusTotal]. The password for this file is displayed in the fake portal page.

“As shown in the screenshots below, the fake portal is rendered exactly as described, simulating an official government document download process,” explains VirusTotal.

“The phishing site includes case numbers, security tokens, and visual cues to build trust, all of it crafted within an SVG file.”

Fake portal for Colombia’s judicial system​​​​​​​
Fake portal for Colombia’s judicial system
Source: VirusTotal

BleepingComputer found that the extracted file contains four files: a legitimate executable from the Comodo Dragon web browser, renamed to be an official judicial document, a malicious DLL [VirusTotal], and what appears to be two encrypted files.

Extracted password-protected archive
Extracted password-protected archive
Source: BleepingComputer

If the user opens the executable, the malicious DLL will be sideloaded to install further malware on the system.

After detecting this initial SVG, VirusTotal identified 523 previously uploaded SVG files that were part of the same campaign but had evaded detection by security software.

The addition of SVG support to AI Code Insights was crucial in exposing this particular campaign, as VirusTotal noted that the use of AI makes it easier to identify new malicious campaigns.

“This is where Code Insight helps most: giving context, saving time, and helping focus on what really matters. It’s not magic, and it won’t replace expert analysis, but it’s one more tool to cut through the noise and get to the point faster,” concludes VirusTotal.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/virustotal-finds-hidden-malware-phishing-campaign-in-svg-files/feed/ 0 57116
Brokewell Android malware delivered through fake TradingView ads https://earlybirdsinvest.com/brokewell-android-malware-delivered-through-fake-tradingview-ads/ https://earlybirdsinvest.com/brokewell-android-malware-delivered-through-fake-tradingview-ads/#respond Mon, 01 Sep 2025 12:57:27 +0000 https://earlybirdsinvest.com/brokewell-android-malware-delivered-through-fake-tradingview-ads/

Brokewell Android malware delivered through fake TradingView ads

Cybercriminals are abusing Meta’s advertising platforms with fake offers of a free TradingView Premium app that spreads the Brokewell malware for Android.

The campaign targets cryptocurrency assets and has been running since at least July 22nd through an estimated 75 localized ads.

Brokewell has been around since early 2024 and features a broad set of capabilities that include stealing sensitive data, remote monitoring and control of the compromised device.

Taking over the device

Researchers at cybersecurity company Bitdefender investigated the ads in the campaign, which use the TradingView branding and visuals and lure potential victims with the promise of a free premium app for Android.

Fake TradingView ad leading to Brokwell malware
sourcce Bitdefender

They note that the campaign was specifically designed for mobile users, as accessing the ad from a different operating system would lead to harmless content.

Clicking from Android, however, redirected to a webpage mimicking the original TradingView site that provided a malicious tw-update.apk file hosted at tradiwiw[.]online/

“The dropped application asks for accessibility, and after receiving it, the screen is covered with a fake update prompt. In the background, the application is giving itself all the permissions it needs,” the researchers say in a report this week..

Furthermore, the malicious app also tries to obtain the PIN for unlocking the device by simulating an Android update request that needs the lockscreen password.

Fake TradingView app tries to obtain Android device lockscreen code
source: Bitdefender

According to Bitdefender, the fake TradingView app is “an advanced version of the Brokewell malware” that comes “with a vast arsenal of tools designed to monitor, control, and steal sensitive information:”

  • Scans for BTC, ETH, USDT, bank account numbers (IBANs)
  • Steals and exports codes from Google Authenticator (2FA bypass)
  • Steals account by overlaying fake login screens
  • Records screens and keystrokes, steals cookies, activates the camera and microphone, and tracks the location
  • Hijacks the default SMS app to intercept messages, including banking and 2FA codes
  • Remote control – can receive commands over Tor or Websockets to send texts, place calls, uninstall apps, or even self-destruct

The researchers provide a technical overview of how the malware works and an extended list of supported commands that includes more than 130 rows.

Bitdefender says that this campaign is part of a larger operation that initially used Facebook ads impersonating “dozens of well-known brands” to target Windows users.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/brokewell-android-malware-delivered-through-fake-tradingview-ads/feed/ 0 56221
Google to verify all Android devs to block malware on Google Play https://earlybirdsinvest.com/google-to-verify-all-android-devs-to-block-malware-on-google-play/ https://earlybirdsinvest.com/google-to-verify-all-android-devs-to-block-malware-on-google-play/#respond Wed, 27 Aug 2025 03:46:13 +0000 https://earlybirdsinvest.com/google-to-verify-all-android-devs-to-block-malware-on-google-play/

Google to verify all Android devs to block malware on Google Play

Google is introducing a new defense for Android called ‘Developer Verification’ to block malware installations from sideloaded apps sourced from outside the official Google Play app store.

For apps on Google Play, there was already a requirement for publishers to provide a D-U-N-S (Data Universal Numbering System) number, introduced on August 31, 2023.

Google says this has had a notable effect in reducing malware on the platform. However, the system didn’t apply to the vast developer ecosystem outside the app store.

“We’ve seen how malicious actors hide behind anonymity to harm users by impersonating developers and using their brand image to create convincing fake apps,” reads Google’s announcement.

“The scale of this threat is significant: our recent analysis found over 50 times more malware from internet-sideloaded sources than on apps available through Google Play.”

Although the threat is more prevalent outside Google Play, the developer verification requirement applies to both apps on Google Play and apps hosted on third-party app stores.

Starting in 2026, all apps installed on certified Android devices must come from developers who have verified their identity with Google.

Early access to the Developer Verification program will begin this year in October, and the system will open to all Android application developers in March 2026.

In September 2026, the identity verification requirement will become mandatory for Brazil, Indonesia, Singapore, and Thailand, before it rolls out globally in 2027.

The expected effect is to have sideloading, non-compliant apps blocked by the operating system with a security message on certified devices.

Certified Android devices are those that have passed Google’s Compatibility Test Suite (CTS) and are approved to ship with Google Play Services, Play Store, and Play Protect.

In practice, this encompasses all mainstream devices from Samsung, Xiaomi, Motorola, OnePlus, Oppo, Vivo, and the Google Pixel line.

Non-certified devices are those from Huawei, Amazon Fire tablets, and shady Chinese TV boxes or smartphones that use heavily modified OS images and questionable components.

Those devices are not subject to the new rule enforcement, and their users will be able to continue sideloading APKs from unverified and anonymous developers.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/google-to-verify-all-android-devs-to-block-malware-on-google-play/feed/ 0 55307
APT36 hackers abuse Linux .desktop files to install malware in new attacks https://earlybirdsinvest.com/apt36-hackers-abuse-linux-desktop-files-to-install-malware-in-new-attacks/ https://earlybirdsinvest.com/apt36-hackers-abuse-linux-desktop-files-to-install-malware-in-new-attacks/#respond Sun, 24 Aug 2025 11:11:13 +0000 https://earlybirdsinvest.com/apt36-hackers-abuse-linux-desktop-files-to-install-malware-in-new-attacks/

Linux

The Pakistani APT36 cyberspies are using Linux .desktop files to load malware in new attacks against government and defense entities in India.

The activity, documented in reports by CYFIRMA and CloudSEK, aims at data exfiltration and persistent espionage access. APT 36 has previously used .desktop files to load malware in targeted espionage operations in South Asia.

The attacks were first spotted on August 1, 2025, and based on the latest evidence, are still ongoing.

Desktop file abuse

Although the attacks described in the two reports use different infrastructure and samples (based on hashes), the techniques, tactics and procedures (TTPs), attack chains, and apparent goals are the same.

Victims receive ZIP archives through phishing emails containing a malicious .desktop file disguised as a PDF document, and named accordingly.

Linux .desktop files are text-based application launchers that contain configuration options dictating how the desktop environment should display and run an application.

Users open the .desktop file thinking it’s a PDF, which causes a bash command hidden in the ‘Exec=” field to create a temporary filename in “/tmp/’ where it writes a hex-encoded payload fetched from the attacker’s server or Google Drive.

Then, it runs ‘chmod +x’ to make it executable and launches it in the background.

To lower suspicion for the victim, the script also launches Firefox to display a benign decoy PDF file hosted on Google Drive.

Sample of a decoy PDF used in the attacks
Sample of a decoy PDF used in the attacks
Source: CloudSEK

In addition to the manipulation of the ‘Exec=” field to run a sequence of shell commands, the attackers also added fields like “Terminal=false’ to hide the terminal window from the user, and ‘X-GNOME-Autostart-enabled=true’ to run the file at every login.

A malicious desktop file
A malicious desktop file
Source: CloudSEK

Typically, .desktop files on Linux are plain-text shortcut files, defining an icon, name, and command to execute when the user clicks it.

However, in APT36 attacks, the attackers abuse this launcher mechanism to turn it essentially into a malware dropper and persistence establishment system, similarly to how the ‘LNK’ shortcuts are abused on Windows.

Because .desktop files on Linux are typically text, not binaries, and as their abuse isn’t widely documented, security tools on the platform are unlikely to monitor them as potential threats.

The payload dropped by the malformed .desktop file in this case is a Go-based ELF executable that performs espionage functions.

Although packing and obfuscation made analysis challenging, the researchers found that it can be set to stay hidden, or attempt to set up its separate persistence using cron jobs and systemd services.

Communication with the C2 is made through a bi-directional WebSocket channel, allowing data exfiltration and remote command execution.

Overview of the attack
Overview of the attack
Source: CloudSEK

Both cybersecurity firms find this latest campaign to be a sign of the evolution of APT36’s tactics, which are turning more evasive and sophisticated.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/apt36-hackers-abuse-linux-desktop-files-to-install-malware-in-new-attacks/feed/ 0 54866
ERMAC Android malware source code leak exposes banking trojan infrastructure https://earlybirdsinvest.com/ermac-android-malware-source-code-leak-exposes-banking-trojan-infrastructure/ https://earlybirdsinvest.com/ermac-android-malware-source-code-leak-exposes-banking-trojan-infrastructure/#respond Tue, 19 Aug 2025 02:29:15 +0000 https://earlybirdsinvest.com/ermac-android-malware-source-code-leak-exposes-banking-trojan-infrastructure/

ERMAC Android malware source code leak exposes banking trojan infrastructure

The source code for version 3 of the ERMAC Android banking trojan has been leaked online, exposing the internals of the malware-as-a-service platform and the operator’s infrastructure.

The code base was discovered in an open directory by Hunt.io researchers while scanning for exposed resources in March 2024.

They located an archive named Ermac 3.0.zip, which contained the malware’s code, including backend, frontend (panel), exfiltration server, deployment configurations, and the trojan’s builder and obfuscator.

The researchers analyzed the code, finding that it significantly expanded the targeting capabilities compared to previous versions, with more than 700 banking, shopping, and cryptocurrency apps.

ERMAC was first documented in September 2021  by ThreatFabric – a provider of online payment fraud solutions and intelligence for the financial services sector, as an evolution of the Cerberus banking trojan operated by a threat actor known as ‘BlackRock.’

ERMAC v2.0 was spotted by ESET in May 2022, rented to cybercriminals for a monthly fee of $5,000, and targeting 467 apps, up from 378 in the previous version.

In January 2023, ThreatFabric observed BlackRock promoting a new Android malware tool named Hook, which appeared to be an evolution of ERMAC.

ERMAC v3.0 capabilities

Hunt.io found and analyzed ERMAC’s PHP command-and-control (C2) backend, React front-end panel, Go-based exfiltration server, Kotlin backdoor, and the builder panel for generating custom trojanized APKs.

According to the researchers, ERMAC v3.0 now targets sensitive user information in more than 700 apps.

One of ERMAC's form injections
One of ERMAC’s form injections
Source: Hunt.io

Additionally, the latest version expands on previously documented form-injection techniques, uses AES-CBC for encrypted communications, features an overhauled operator panel, and enhances data theft and device control.

Specifically, Hunt.io has documented the following capabilities for the latest ERMAC release:

  • Theft of SMS, contacts, and registered accounts
  • Extraction of Gmail subjects and messages
  • File access via ‘list’ and ‘download’ commands
  • SMS sending and call forwarding for communication abuse
  • Photo capturing via the front camera
  • Full app management (launch, uninstall, clear cache)
  • Displaying fake push notifications for deception
  • Uninstalls remotely (killme) for evasion

Infrastructure exposed

Hunt.io analysts used SQL queries to identify live, exposed infrastructure currently used by the threat actors, identifying C2 endpoints, panels, exfiltration servers, and builder deployments.

Exposed ERMAC C2 servers
Exposed ERMAC C2 servers
Source: Hunt.io

Apart from exposing the malware’s source code, the ERMAC operators had several other major opsec failures, including hardcoded JWT tokens, default root credentials, and no registration protections on the admin panel, allowing anyone to access, manipulate, or disrupt ERMAC panels.

Finally, the panel names, headers, package names, and various other operational fingerprints left little doubt about attribution and made discovery and mapping of the infrastructure a lot easier.

Accessing the ERMAC panel
Accessing the ERMAC panel
Source: Hunt.io

The ERMAC V3.0 source code leak weakens the malware operation, first by eroding customer trust in the MaaS in its ability to protect information from law enforcement or allow running campaigns with low detection risk.

Threat detection solutions are also likely to get better at spotting ERMAC. However, if the source code falls into the hands of other threat actors, it is possible to observe in the future modified variants of ERMAC that are more difficult to detect.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/ermac-android-malware-source-code-leak-exposes-banking-trojan-infrastructure/feed/ 0 53931
200,000 Potential Victims Identified As Malware Disguised As Legitimate Apps Crack Bank Accounts, Warns CIFAS https://earlybirdsinvest.com/200000-potential-victims-identified-as-malware-disguised-as-legitimate-apps-crack-bank-accounts-warns-cifas/ https://earlybirdsinvest.com/200000-potential-victims-identified-as-malware-disguised-as-legitimate-apps-crack-bank-accounts-warns-cifas/#respond Sun, 03 Aug 2025 10:44:50 +0000 https://earlybirdsinvest.com/200000-potential-victims-identified-as-malware-disguised-as-legitimate-apps-crack-bank-accounts-warns-cifas/

A prominent fraud prevention service says international crime groups are spreading malware designed to steal victims’ banking information.

The London-based Credit Industry Fraud Avoidance System (CIFAS) says it is witnessing a surge in Android malware attacks targeting banking apps.

CIFAS says that while the malware targets Android users, other mobile platforms are not immune to attacks, noting that the malicious software may have hit 200,000 victims in just six months.

“These malicious apps often look like legitimate tools – such as file managers, PDF readers, phone cleaners, or even browsers like Google Chrome. Once installed, they can appear harmless but later activate harmful features through hidden updates.

Key techniques criminals use include:

Overlaying fake login screens on top of real banking apps to steal login credentials.

Displaying deceptive ‘busy’ or ‘waiting’ screens to mask fraudulent activity.

Preventing users from exiting the app or restarting their device.

Requesting excessive permissions, especially ‘accessibility’ access.”

According to CIFAS, users should be on the lookout for signs that their phones are infected with malware, including prompts to reauthenticate during a banking session, “busy” messages from banking apps, unexpected notifications to update or install Google Chrome and prompts to grant unusual permissions, particularly accessibility access.

Says CIFAS CEO Mike Haley,

“The surge in Android malware is not just a tech issue – it’s a growing threat to consumers and to banking services we all rely on. Criminals are evolving their tactics faster than ever, using deception and stealth to bypass traditional security measures.

The best defence is awareness. If something feels off – an unexpected update, a strange app request – stop before you tap and always seek a second opinion. Education and vigilance are our frontline tools in the fight against fraud.”

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

 

]]>
https://earlybirdsinvest.com/200000-potential-victims-identified-as-malware-disguised-as-legitimate-apps-crack-bank-accounts-warns-cifas/feed/ 0 51222
Hackers Attack Android Users’ Bank Accounts As Rapidly Improving Malware Steals PIN Codes and Login Credentials, Unlocks Patterns and Records Screens: Cybersecurity Researchers https://earlybirdsinvest.com/hackers-attack-android-users-bank-accounts-as-rapidly-improving-malware-steals-pin-codes-and-login-credentials-unlocks-patterns-and-records-screens-cybersecurity-researchers/ https://earlybirdsinvest.com/hackers-attack-android-users-bank-accounts-as-rapidly-improving-malware-steals-pin-codes-and-login-credentials-unlocks-patterns-and-records-screens-cybersecurity-researchers/#respond Sat, 02 Aug 2025 08:37:13 +0000 https://earlybirdsinvest.com/hackers-attack-android-users-bank-accounts-as-rapidly-improving-malware-steals-pin-codes-and-login-credentials-unlocks-patterns-and-records-screens-cybersecurity-researchers/

A rapidly evolving bank malware now has far greater capabilities to infect Android devices and steal personal information, according to researchers.

The cybersecurity firm Zimperium says the so-called DoubleTrouble trojan “has rapidly evolved in both its distribution methods and capabilities,” and is now permeating channels on the social platform Discord.

“In its latest evolution, the malware has integrated several new and advanced features, significantly expanding its capabilities beyond earlier iterations. These enhancements enable more effective data theft, device manipulation, and evasion techniques.

The new functionalities include: displaying malicious UI overlays to steal PIN codes or unlock patterns, comprehensive screen recording capabilities, the ability to block the opening of specific applications, and advanced keylogging functionality.”

Researchers say the malware convinces users to download it by masking itself as an extension or an add-on, and it uses the Google Play icon to appear trustworthy.

It also manipulates device functionality by exploiting Android’s Accessibility Services, allowing it to block legitimate banking or security apps with misleading “system maintenance” prompts.

In addition, the malicious software simulates user actions like taps and swipes, allowing attackers to remotely control infected devices and steal data, including passwords and banking details, with alarming precision.

The trojan’s attacks are ongoing, primarily targeting users in Europe through phishing websites and Discord-hosted APKs. Specific victim counts remain unknown at time of publishing.

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/hackers-attack-android-users-bank-accounts-as-rapidly-improving-malware-steals-pin-codes-and-login-credentials-unlocks-patterns-and-records-screens-cybersecurity-researchers/feed/ 0 51025
Lumma infostealer malware returns after law enforcement disruption https://earlybirdsinvest.com/lumma-infostealer-malware-returns-after-law-enforcement-disruption/ https://earlybirdsinvest.com/lumma-infostealer-malware-returns-after-law-enforcement-disruption/#respond Wed, 23 Jul 2025 06:58:25 +0000 https://earlybirdsinvest.com/lumma-infostealer-malware-returns-after-law-enforcement-disruption/

Hacker

The Lumma infostealer malware operation is gradually resuming activities following a massive law enforcement operation in May, which resulted in the seizure of 2,300 domains and parts of its infrastructure.

Although the Lumma malware-as-a-service (MaaS) platform suffered significant disruption from the law enforcement action, as confirmed by early June reports on infostealer activity, it didn’t shut down.

The operators immediately acknowledged the situation on XSS forums, but claimed that their central server had not been seized (although it had been remotely wiped), and restoration efforts were already underway.

Lumma admin's first message after the law enforcement action
Lumma admin’s first message after the law enforcement action
Source: Trend Micro

Gradually, the MaaS built up again and regained trust within the cybercrime community, and is now facilitating infostealing operations on multiple platforms again.

According to Trend Micro analysts, Lumma has almost returned to pre-takedown activity levels, with the cybersecurity firm’s telemetry indicating a rapid rebuilding of infrastructure.

“Following the law enforcement action against Lumma Stealer and its associated infrastructure, our team has observed clear signs of a resurgence in Lumma’s operations,” reads the Trend Micro report.

“Network telemetry indicates that Lumma’s infrastructure began ramping up again within weeks of the takedown.”

New Lumma C2 domains tracked by Trend Micro
New Lumma C2 domains
Source: Trend Micro

Trend Micro reports that Lumma still uses legitimate cloud infrastructure to mask malicious traffic, but has now shifted from Cloudflare to alternative providers, most notably the Russian-based Selectel, to avoid takedowns.

The researchers have highlighted four distribution channels that Lumma currently uses to achieve new infections, indicating a full-on return to multifaceted targeting.

  1. Fake cracks/keygens: Fake software cracks and keygens are promoted via malvertising and manipulated search results. Victims are directed to deceptive websites that fingerprint their system using Traffic Detection Systems (TDS) before serving the Lumma Downloader.
  2. ClickFix: Compromised websites display fake CAPTCHA pages that trick users into running PowerShell commands. These commands load Lumma directly into memory, helping it evade file-based detection mechanisms.
  3. GitHub: Attackers are actively creating GitHub repositories with AI-generated content advertising fake game cheats. These repos host Lumma payloads, like “TempSpoofer.exe,” either as executables or in ZIP files.
  4. YouTube/Facebook: Current Lumma distribution also involves YouTube videos and Facebook posts promoting cracked software. These links lead to external sites hosting Lumma malware, which sometimes abuses trusted services like sites.google.com to appear credible.
Malicious GitHub repository (left) and YouTube video (right) distributing Lumma
Malicious GitHub repository (left) and YouTube video (right) distributing Lumma payloads
Source: Trend Micro

The re-emergence of Lumma as a significant threat demonstrates that law enforcement action, devoid of arrests or at least indictments, is ineffective in stopping these determined threat actors.

MaaS operations, such as Lumma, are incredibly profitable, and the leading operators behind them likely view law enforcement action as routine obstacles they merely have to navigate.

Wiz

Contain emerging threats in real time – before they impact your business.

Learn how cloud detection and response (CDR) gives security teams the edge they need in this practical, no-nonsense guide.

]]>
https://earlybirdsinvest.com/lumma-infostealer-malware-returns-after-law-enforcement-disruption/feed/ 0 49167