Site navigation

Network of Infected Androids Used for Fraudulent Activities

Michael Edgar

,

Infected android
Cybersecurity experts uncovered a criminal enterprise known as Lemon Group, which has been exploiting pre-infected mobile devices to carry out fraudulent activities. 

The findings came from research from Trend Micro presented last week at the Black Hat Asia 2023 conference. It shows that Lemon Group established a global network of over 8.9 million pre-infected Android smartphones. 

Made up of primarily low-cost models, the Android phones served as mobile proxies enabling the group to carry out various nefarious activities, including the theft and sale of SMS messages. Over 490,000 mobile numbers were detected in use for one-time passwords (OTP) requests from platforms like WhatsApp and Facebook to carry out account hijacking. However, researchers warn the actual number may be much higher.

The group also employed plugins that intercepted activities on Facebook-related apps, harvested data such as cookies, and hijacked WhatsApp sessions to send unwanted messages for overseas marketing purposes.

According to Trend Micro, Lemon Group’s operations have spread across more than 180 countries, with the highest concentration of infections detected in the United States, Mexico, Indonesia, Thailand, Russia, South Africa, India, Angola, the Philippines, and Argentina. 

The group operates by implanting a tampered zygote dependency library into the mobile devices, which then loads a downloader referred to as the main plugin. The main plugin is capable of downloading and managing other plugins, each of which is able to serve a specific criminal purpose. 


Recommended


The research team at Trend Micro analysed one of the pre-infected devices and discovered a system library called “libandroid_runtime.so”, which had been tampered with to inject malicious code. This injected code decrypted a DEX file associated with Lemon Group and loaded it into memory. The DEX file contained a configuration linked to the group’s domain and the main plugin called “Sloth.”

Researchers warn the cybersecurity community to be vigilant and to be aware of the indicators of compromise (IOCs) associated with the main plugin “Sloth”.

Michael Edgar

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data