FluHorse Mobile Malware
Summary
A new email phishing campaign targeting East Asian regions aims to distribute a new strain of Android malware known as FluHorse. The FluHorse applications are designed to appear similar or outright imitate popular apps in the targeted regions, such as ETC and VPBank Neo, which are widely used in Taiwan and Vietnam. The phishing scheme utilized in the infection chain of FluHorse is quite straightforward - attackers lure victims by sending them scam emails containing links to a dedicated website that hosts unsafe APK files. To make matters worse, the threat actors can abuse their access to SMS messages to intercept all incoming 2FA codes and redirect them to the Command-and-Control (C2, C&C) server of the operation. This is a noteworthy development as threat actors often use tactics such as evasion techniques, obfuscation, and delayed execution to avoid detection by virtual environments and analysis tools.