FluHorse Mobile Malware

General News

Summary

A new email phishing campaign targeting East Asian regions aims to distribute a new strain of Android malware known as FluHorse. The FluHorse applications are designed to appear similar or outright imitate popular apps in the targeted regions, such as ETC and VPBank Neo, which are widely used in Taiwan and Vietnam. The phishing scheme utilized in the infection chain of FluHorse is quite straightforward - attackers lure victims by sending them scam emails containing links to a dedicated website that hosts unsafe APK files. To make matters worse, the threat actors can abuse their access to SMS messages to intercept all incoming 2FA codes and redirect them to the Command-and-Control (C2, C&C) server of the operation. This is a noteworthy development as threat actors often use tactics such as evasion techniques, obfuscation, and delayed execution to avoid detection by virtual environments and analysis tools.

Classifications

industries
Entertainment
applications
Customer Service & Support

AskAI Classifications

Labels
Cybersecurity Software Anti-Malware Software SaaS Security

Linked Companies

EnigmaSoft
$1M to $5M