{"id":10181,"date":"2021-11-27T11:01:44","date_gmt":"2021-11-27T10:01:44","guid":{"rendered":"http:\/\/dubawa.org\/dir\/?p=10181"},"modified":"2021-11-27T11:01:46","modified_gmt":"2021-11-27T10:01:46","slug":"flubot-what-you-need-to-know-about-new-malware-that-targets-users-financial-credentials","status":"publish","type":"post","link":"https:\/\/dubawa.org\/dir\/flubot-what-you-need-to-know-about-new-malware-that-targets-users-financial-credentials\/","title":{"rendered":"FLUBOT: What you need to know about new Malware that targets users&#8217; financial credentials"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">On October 21, 2021, the Nigeria Computer Emergency Response Team (ngCERT), <a href=\"https:\/\/www.ncc.gov.ng\/media-centre\/news-headlines\/1081-press-statement-ncc-alerts-telecom-consumers-on-flubot-malware\" target=\"_blank\" rel=\"noreferrer noopener\">announced and warned <\/a>online users about the emergence of a new malware that \u201ctargets Androids with fake security updates and app installations.\u201d\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The malware called \u2018Flubot\u2019 is said to \u201cimpersonate Android mobile banking applications to draw fake web views on targeted applications.\u201d&nbsp; It also steals the personal data and financial information of unsuspecting persons.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Although multiple reports show it uses different schemes found in older malware families, Flubot has caused a lot of damage within the few months of its emergence.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>What is Flubot?<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A malware is a generic word used to describe a virus or a malicious software, designed specially to disrupt damage or gain unauthorised access to a computer system. As such,<strong> <\/strong>flubot is a malware-like computer virus that can be installed on an android device via a malicious link that is sent through an SMS.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This malware can take over a user\u2019s phone and send text messages to other people from the device without the user\u2019s knowledge, potentially infecting them as well.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Flubot malware was first <a href=\"https:\/\/www.theguardian.com\/technology\/2021\/aug\/20\/australians-hit-by-flubot-malware-that-arrives-by-text-message\" target=\"_blank\" rel=\"noreferrer noopener\">identified <\/a>on Australian shores in August 2021. It was characterised by a text sent from an Australian phone number that enticed users to click on a link that would then infect their android device with malware.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>How Flubots works<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The malware<a href=\"https:\/\/tech.hindustantimes.com\/how-to\/bitcoin-ethereum-investors-beware-of-flubot-check-cryptocurrency-scam-howto-71637726221497.html\" target=\"_blank\" rel=\"noreferrer noopener\"> targets different<\/a> mobile apps based on the device\u2019s language setting. So far, there have been detections of the malware targeting bank apps mainly in Spain, but evidence suggests it may move on to other markets, such as Poland, Germany, Hungary and the UK. Aside from targeting mobile banking apps, flubot also operates on cryptocurrency-related mobile apps as well, regardless of the device\u2019s language setting.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Flubot is crafted to deceive intended targets.&nbsp; First, the victim receives a text message informing them about the delivery of a package. These delivery messages usually contain a link to a website that serves as a host for the malware (disguised as the delivery company\u2019s application).&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/punchng.com\/flubot-things-to-know-about-new-virus-that-steals-banking-details-from-android-devices\/\" target=\"_blank\" rel=\"noreferrer noopener\">In recent times<\/a>, flubot has used the DHL, UPS and FedEx brands to lure unsuspecting members of the public. When the victim downloads and installs the application, the malware uploads the victim&#8217;s contacts to its C&amp;C (Command &amp; Control server) and from there, the scheme is launched.\u00a0<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh5.googleusercontent.com\/pRjy908MeOT0ytdTzQ2Sf8qM6h-ABA8pygJOic2X2DaYGowT8EyISsN9-OqGNIDL1qEpSMfYN_9lYdhGylSX6_6v87-4MR4Fx8pHGWeXPLfz-JFgSFH9hkh5Varpk6tOW-82B191\" alt=\"\" title=\"\"><figcaption><strong><em>A typical Flubot link in the guise of a DHL delivery message<\/em><\/strong><\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Once the malware application has been installed and opened, it asks the victim to enable its accompanying accessibility service. After the rights are granted, the malware agent grants itself several permissions by abusing the access.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Nonetheless, the questions users usually ask is: <strong>How do I know I have Flubot?<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When you start to receive text messages and calls from unknown numbers inquiring about messages you sent their way,&nbsp; your device is most likely infected already.&nbsp; Also, your device is definitely under the control of flubots if it carries an application that looks like a blue cassette wrapped in a yellow envelope tagged \u2018voicemail\u2019.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh4.googleusercontent.com\/WijHmYhU5s4N7ZdFoHEZp8nVvd6a5K1FG6XVOFTOXInXutPkb48WnbVOD_L2ySEYDNe1ixtGA2iPCFmumUGeVbF0amXzuF_Q4Chca8ZEzJTevN65dSpKOAcD9C0tWU8t_HDeGbXu\" alt=\"\" title=\"\"><figcaption><strong><em>A typical Flubot infected device\u00a0<\/em><\/strong><\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>How do I remove Flubot from my phone?<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Although it actively protects itself from deletion, you can manually remove Flubot from your device by using android\u2019s safe boot.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Hold down the power button and restart your phone, confirming that you wish to reboot the device in safe mode. In the system settings, look for the malware app and uninstall it. Users can also restore the factory setting of their device.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Conclusion<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Flubots are designed to target the financial credentials of a user. While the malware is only a functional android device, experts are warning all mobile users to be wary of unusual activities on their devices.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><em>This article was produced per 2021 Kwame Karikari&nbsp; fact &#8211; checking fellowship in partnership with National Orientation Agency (NOA) to facilitate the ethos of truth in journalism and enhance media literacy in the country.<\/em><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>On October 21, 2021, the Nigeria Computer Emergency Response Team (ngCERT), announced and warned online users about the emergence of a new malware that \u201ctargets Androids with fake security updates and app installations.\u201d\u00a0 The malware called \u2018Flubot\u2019 is said to \u201cimpersonate Android mobile banking applications to draw fake web views on targeted applications.\u201d&nbsp; It also steals the personal data and financial information of unsuspecting persons. Although multiple reports show it uses different schemes found in older malware families, Flubot has caused a lot of damage within the few months of its emergence.&nbsp; What is Flubot? A malware is a generic word used to describe a virus or a malicious software, designed specially to disrupt damage or gain unauthorised access to a computer system. As such, flubot is a malware-like computer virus that can be installed on an android device via a malicious link that is sent through an SMS.\u00a0 This malware can take over a user\u2019s phone and send text messages to other people from the device without the user\u2019s knowledge, potentially infecting them as well. Flubot malware was first identified on Australian shores in August 2021. It was characterised by a text sent from an Australian phone number that enticed users to click on a link that would then infect their android device with malware. How Flubots works The malware targets different mobile apps based on the device\u2019s language setting. So far, there have been detections of the malware targeting bank apps mainly in Spain, but evidence suggests it may move on to other markets, such as Poland, Germany, Hungary and the UK. Aside from targeting mobile banking apps, flubot also operates on cryptocurrency-related mobile apps as well, regardless of the device\u2019s language setting. Flubot is crafted to deceive intended targets.&nbsp; First, the victim receives a text message informing them about the delivery of a package. These delivery messages usually contain a link to a website that serves as a host for the malware (disguised as the delivery company\u2019s application).&nbsp; In recent times, flubot has used the DHL, UPS and FedEx brands to lure unsuspecting members of the public. When the victim downloads and installs the application, the malware uploads the victim&#8217;s contacts to its C&amp;C (Command &amp; Control server) and from there, the scheme is launched.\u00a0 Once the malware application has been installed and opened, it asks the victim to enable its accompanying accessibility service. After the rights are granted, the malware agent grants itself several permissions by abusing the access.&nbsp; Nonetheless, the questions users usually ask is: How do I know I have Flubot? When you start to receive text messages and calls from unknown numbers inquiring about messages you sent their way,&nbsp; your device is most likely infected already.&nbsp; Also, your device is definitely under the control of flubots if it carries an application that looks like a blue cassette wrapped in a yellow envelope tagged \u2018voicemail\u2019. How do I remove Flubot from my phone? Although it actively protects itself from deletion, you can manually remove Flubot from your device by using android\u2019s safe boot.&nbsp; Hold down the power button and restart your phone, confirming that you wish to reboot the device in safe mode. In the system settings, look for the malware app and uninstall it. Users can also restore the factory setting of their device.&nbsp; Conclusion Flubots are designed to target the financial credentials of a user. While the malware is only a functional android device, experts are warning all mobile users to be wary of unusual activities on their devices.&nbsp; This article was produced per 2021 Kwame Karikari&nbsp; fact &#8211; checking fellowship in partnership with National Orientation Agency (NOA) to facilitate the ethos of truth in journalism and enhance media literacy in the country.<\/p>\n","protected":false},"author":1,"featured_media":10182,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"hannibal_claim_source":"","hannibal_source_label":"","hannibal_card_color":"blue","_jetpack_memberships_contains_paid_content":false,"footnotes":"","_wpscppro_dont_share_socialmedia":false,"_wpscppro_custom_social_share_image":0,"_facebook_share_type":"","_twitter_share_type":"","_linkedin_share_type":"","_pinterest_share_type":"","_linkedin_share_type_page":"","_instagram_share_type":"","_medium_share_type":"","_threads_share_type":"","_google_business_share_type":"","_bluesky_share_type":"","_mastodon_share_type":"","_selected_social_profile":[],"_wpsp_enable_custom_social_template":false,"_wpsp_social_scheduling":{"enabled":false,"datetime":null,"platforms":[],"status":"template_only","dateOption":"today","timeOption":"now","customDays":"","customHours":"","customDate":"","customTime":"","schedulingType":"absolute"},"_wpsp_active_default_template":true},"categories":[1572,4],"tags":[2845,2849,2854,2843,2851,347,2853,2841,2847,2842,2844,2846,1299,2848,2852,2855],"verdict":[],"ppma_author":[1983],"class_list":["post-10181","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-explainers","category-featured","tag-android","tag-application","tag-deceive","tag-deception","tag-dhl","tag-featured","tag-fedex","tag-flubot","tag-install","tag-malware","tag-phones","tag-playstore","tag-scam","tag-uninstall","tag-ups","tag-featured-2"],"jetpack_shortlink":"https:\/\/wp.me\/p8R6dE-2Ed","jetpack_likes_enabled":true,"jetpack_sharing_enabled":true,"authors":[{"term_id":1983,"user_id":0,"is_guest":1,"slug":"aisha-ali","display_name":"Aisha Ali","avatar_url":"https:\/\/secure.gravatar.com\/avatar\/03948b9cc5a10a76acf81e69ede9371002270641cc990320daeb1046cb98a4a9?s=96&r=g","author_category":"","user_url":"","last_name":"","first_name":"","job_title":"","description":""}],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/dubawa.org\/dir\/wp-content\/uploads\/2021\/11\/unnamed-10.png?fit=512%2C320&ssl=1","_links":{"self":[{"href":"https:\/\/dubawa.org\/dir\/wp-json\/wp\/v2\/posts\/10181","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dubawa.org\/dir\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dubawa.org\/dir\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dubawa.org\/dir\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dubawa.org\/dir\/wp-json\/wp\/v2\/comments?post=10181"}],"version-history":[{"count":0,"href":"https:\/\/dubawa.org\/dir\/wp-json\/wp\/v2\/posts\/10181\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dubawa.org\/dir\/wp-json\/wp\/v2\/media\/10182"}],"wp:attachment":[{"href":"https:\/\/dubawa.org\/dir\/wp-json\/wp\/v2\/media?parent=10181"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dubawa.org\/dir\/wp-json\/wp\/v2\/categories?post=10181"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dubawa.org\/dir\/wp-json\/wp\/v2\/tags?post=10181"},{"taxonomy":"verdict","embeddable":true,"href":"https:\/\/dubawa.org\/dir\/wp-json\/wp\/v2\/verdict?post=10181"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/dubawa.org\/dir\/wp-json\/wp\/v2\/ppma_author?post=10181"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}