Stories
Slash Boxes
Comments

SoylentNews is people

posted by janrinok on Saturday August 31 2019, @09:57PM   Printer-friendly
from the don't-mess-with-Russian-banks dept.

Arthur T Knackerbracket has found the following story:

Russian authorities have arrested members of the TipTop cybercrime group, believed to have infected more than 800,000 Android smartphones with malware since 2015.

The group operated by renting Android banking trojans from underground hacking forums, which they later hid inside Android apps distributed via search engine ads and third-party app stores.

TipTop has been active since 2015, and operators have been making between $1,500 and $10,500 in daily profits, according to Group-IB, the cyber-security firm who helped Russian authorities track down the gang's members. The group's favorite malware was the Hqwar (Agent.BID) banking trojan, which they rented and used in most of their campaigns.

Hqwar is capable of reading SMS messages, recording phone calls, and initiating USSD-requests. However, it's primary function is to show fake login screens on top of legitimate banking apps, and steal victims' login credentials. Group-IB said TipTop temporarily stopped distributing Hqwar in 2016, when they experimented with its competitors, such as Asacub (Honli), Cron, and CatsElite (MarsElite), but returned to it in 2017 when they used it alongside the Lokibot and modernized Marcher (Rahunok) trojans.

[...] In 2017, Kaspersky ranked Hqwar as the fourth most popular Android malware. A year later, Kaspersky cited Hqwar as one of the root causes in the sudden jump in the number of Android mobile banking trojans, together with Asacub.

[...] While official documents or statements don't mention anything about the suspect collaborating with authorities, officials from the Russian Ministry of Internal Affairs said they also made other arrests with the information gathered from this case, while other suspects are under investigation.


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 0) by Anonymous Coward on Saturday August 31 2019, @11:52PM (2 children)

    by Anonymous Coward on Saturday August 31 2019, @11:52PM (#888348)

    I was just waiting for someone making bad Russians theme out of this...

  • (Score: 0) by Anonymous Coward on Sunday September 01 2019, @12:06AM

    by Anonymous Coward on Sunday September 01 2019, @12:06AM (#888350)

    Those poor, poor Russian victims!

    Why doesn't anyone think of the Russian victims?

  • (Score: 2) by JoeMerchant on Monday September 02 2019, @12:55AM

    by JoeMerchant (3937) on Monday September 02 2019, @12:55AM (#888678)

    Was thinking I should have said: 800,000 more phones, but, to give equal time, I'd bet however many infected phones the Russian authorities are spying on, the U.S. agencies have many more, foreign and domestic.

    --
    🌻🌻 [google.com]