• Latest
  • Trending

Infected zoom apps for target home work users Android – Security Boulevard

01.04.2020
The Grammys Celebrate 50 Years Of Hip-Hop With A Star-Studded Tribute Performance – POPSUGAR

The Grammys Celebrate 50 Years Of Hip-Hop With A Star-Studded Tribute Performance – POPSUGAR

06.02.2023
Jennifer Lopez Shines in a Plunging Gucci Dress at the 2023 Grammys – Page Six

Jennifer Lopez Shines in a Plunging Gucci Dress at the 2023 Grammys – Page Six

06.02.2023
U.S. economy and stocks face tough year — and may even lag Europe – CNBC

U.S. economy and stocks face tough year — and may even lag Europe – CNBC

06.02.2023
Apple Loop: iPhone 15 Pro disappointment, iPhone 14 crash notice, embarrassing macOS issues – Forbes

Apple Loop: iPhone 15 Pro disappointment, iPhone 14 crash notice, embarrassing macOS issues – Forbes

06.02.2023
Stolen Kim Kardashian’s Engagement Ring – What Really Happened?  – New idea

Stolen Kim Kardashian’s Engagement Ring – What Really Happened? – New idea

06.02.2023
Grammys 2023 Live Updates: Beyoncé Makes History, Becomes Artist With Most Grammys Ever – ABC News

Grammys 2023 Live Updates: Beyoncé Makes History, Becomes Artist With Most Grammys Ever – ABC News

06.02.2023
George Santos accused of sexual misconduct by future staffer – CBS News

George Santos accused of sexual misconduct by future staffer – CBS News

06.02.2023
India Urged To Accelerate Blockchain Transition For… – CoinGeek

India Urged To Accelerate Blockchain Transition For… – CoinGeek

06.02.2023
How to Use ChatGPT AI Tool on Android, iPhone – Hindustan Times

How to Use ChatGPT AI Tool on Android, iPhone – Hindustan Times

06.02.2023
Why Taylor Swift skipped the Golden Globes in 2023 – ELLE

Taylor Swift shows her support for Harry Styles at the 2023 Grammys – ELLE

06.02.2023
8 LGBTQ artists who are in the Rock and Roll Hall of Fame – Metro Weekly

8 LGBTQ artists who are in the Rock and Roll Hall of Fame – Metro Weekly

06.02.2023
Grammy Awards 2023: Beyoncé becomes the biggest winner in history – BBC News BBC Homepage

Grammy Awards 2023: Beyoncé becomes the biggest winner in history – BBC News BBC Homepage

06.02.2023
Monday, February 6, 2023
  • World
  • Economics
  • Sport
    • Basketball
    • Football
    • Nfl
    • Golf
    • F1
    • UFC
  • Technology
  • Culture
    • Arts
  • Media
    • Film
    • Celebs
    • TV
  • LifeStyle
    • Auto
  • Travel
OLTNEWS
  • World
  • Economics
  • Sport
    • Basketball
    • Football
    • Nfl
    • Golf
    • F1
    • UFC
  • Technology
  • Culture
    • Arts
  • Media
    • Film
    • Celebs
    • TV
  • LifeStyle
    • Auto
  • Travel
OLTNEWS
No Result
View All Result

Home » Technology » Infected zoom apps for target home work users Android – Security Boulevard

Infected zoom apps for target home work users Android – Security Boulevard

01/04/2020 02:17:15
in Technology
0
0
SHARES
Share on WhatsappShare on Facebook

Related posts

Apple Loop: iPhone 15 Pro disappointment, iPhone 14 crash notice, embarrassing macOS issues – Forbes

Apple Loop: iPhone 15 Pro disappointment, iPhone 14 crash notice, embarrassing macOS issues – Forbes

06.02.2023
How to Use ChatGPT AI Tool on Android, iPhone – Hindustan Times

How to Use ChatGPT AI Tool on Android, iPhone – Hindustan Times

06.02.2023


For more than two weeks, most of the world’s population has been held in pre-trial detention and forced to work in the security of their homes.

In order to stay connected, many have turned to videoconferencing software to keep businesses open or to attend classes. It was only a matter of time until cybercriminals began to trick users into installing flawed video conferencing applications in order to take advantage of the increased number of users.

Malicious Zoom Clones for the Ignorant

Zoom has recently been in the spotlight as one of the booming video conferencing applications, despite its end-to-end encryption issues and liberalized data sharing with Facebook. It didn’t take long for cybercriminals to repackage it, distribute it to third-party markets, and wait for new victims to install it. The examples documented in this article have spread outside of the Google Play Store and exclusively target users who download apps on their droids.

Sample analyzed: 30a1a22dcf7fa0b62809f510a43829b1
Packagename: us.zoom.videomeetings
Detection: Android.Trojan.Downloader.UJ
Application label: Zoom

This malware has components injected into the refurbished Zoom application, as shown in Figure 1 below.

Although the user interface is identical to the original application, it has additional “functionalities” to which the user has not registered. Malware tries to download main payload from command and control infrastructure on TCP[:]// googleteamsupport[.]ddns.net:4444

The choice of domains is probably not random, as this could indicate what attackers could target next (GoogleTeamSupportapplication is a collaborative B2B platform which also increases during COVID-19 isolation).

The sample has the same package name as the original Zoom app and has even taken additional steps to keep even more subtle differences in certificate details as close as possible to the original Zoom app. .

Aggressive adware gangs can’t miss the show

Bitdefender researchers also discovered a corrupt APK APK that specifically targets Chinese users. Once downloaded, the application requests phone, location and photo permissions at startup

Sample analyzed: fb5243138a920129dd85bb0e1545c2be
Packagename: us.zoom.videomeetings
Detection: Android.Adware.Downloader.BC
Application label: Zoom
Targets: China

Each time the victim presses the application icon, the application does nothing or briefly displays an announcement before closing.

The piece of code below shows that the main activity is transparent:

As soon as the application is opened, a native ad is loaded and displayed on the screen for one second.

When the application finally starts, the victim is presented with advertisements as soon as he tries to join a meeting and he will continue to receive these advertisements until he presses the X button.

The APK we analyzed retrieves information about adware from:
https[:]//sf3-ttcdn-tos.pstatp[.]com / obj / ad-pattern / renderer / package.json (the prefix part sf3 is different from one application to another with the same SDK)

Hard coded links:

http[:]// sf3-ttcdn-tos[.]pstatp.com/

More malware Zoom

This is another malicious example that attempts to impersonate the Zoom application and lure victims into its installation.

Sample analyzed: 9930b683d4b31a3398da0fb75c27d056
Packagename: app.z1_android_421120320_app_original_file
Detection: Android.Trojan.HiddenAds.AJR
Application label: ZOOM Cloud Meetings

When open, the application initially hides in the menu. It then triggers a repetitive alarm which will randomly send an intention to an advertising service. This service then starts an AdActivity which opens an ad. The link is in the resources: adsforapp1[.]com

The malicious application verifies another hard-coded chain in the assets, called “admin”. If the string is true, then it requests administrator rights to the device. If the value is set to false (as in our case), it then tries to download another file (theapkEntrance).

Once opened, the application will redirect to download the additional component.

At the time of this writing, this sample has been seen in the wild in the United States.

The example combines functionality to request device administrator permissions in English or Russian, depending on the default language of the mobile phone. The malware also has the ability to start itself when the device is turned on.

Bitdefender Mobile Security for Android detects and blocks these applications like Android.Trojan.Downloader.UJ, Android.Adware.Downloader.BC and Android.Trojan.HiddenAds.AJR. To minimize the risk of compromise, Android users are encouraged to install a security solution and limit their downloads to application stores recommended by the supplier.

Related

Previous Post

Huawei MateBook D 14 review: excellent value for money – AndroidPIT

Next Post

Alessandra Ambrosio joins girlfriend Brooke Burke for booty and toning ab training on Instagram Live

Related Posts

Apple Loop: iPhone 15 Pro disappointment, iPhone 14 crash notice, embarrassing macOS issues – Forbes
Technology

Apple Loop: iPhone 15 Pro disappointment, iPhone 14 crash notice, embarrassing macOS issues – Forbes

06.02.2023
0

Looking back on another week of news and headlines from Cupertino, this week's Apple Loop includes a disappointing iPhone 15...

Read more
How to Use ChatGPT AI Tool on Android, iPhone – Hindustan Times

How to Use ChatGPT AI Tool on Android, iPhone – Hindustan Times

06.02.2023
For the Tenth Consecutive Year, Persistent Ranked as a Leader in Zinnov Zones Engineering Research and Development Services Ratings

Zum zehnten Mal in Folge nimmt Persistent eine führende Position bei den Zinnov Zones Engineering Research and Development Services Ratings ein

06.02.2023

Motorcyclist falls off southern Utah cliff, rescuers sent via… – St George News

06.02.2023

Best Features Introduced by Samsung Galaxy S Series Over the… – XDA Developers

06.02.2023

Huawei looks to patents for a lifeline – including those in the US – CNBC

06.02.2023
Load More
Next Post

Alessandra Ambrosio joins girlfriend Brooke Burke for booty and toning ab training on Instagram Live

Recent Posts

  • The Grammys Celebrate 50 Years Of Hip-Hop With A Star-Studded Tribute Performance – POPSUGAR
  • Jennifer Lopez Shines in a Plunging Gucci Dress at the 2023 Grammys – Page Six
  • U.S. economy and stocks face tough year — and may even lag Europe – CNBC
  • Apple Loop: iPhone 15 Pro disappointment, iPhone 14 crash notice, embarrassing macOS issues – Forbes
  • Stolen Kim Kardashian’s Engagement Ring – What Really Happened? – New idea

Archives

  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • 0
  • EN

© 2020

No Result
View All Result
  • World
  • Economics
  • Sport
    • Basketball
    • Football
    • Nfl
    • Golf
    • F1
    • UFC
  • Technology
  • Culture
    • Arts
  • Media
    • Film
    • Celebs
    • TV
  • LifeStyle
    • Auto
  • Travel

© 2020

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.