New malware steals users’ money through mobile phones: Report


Team Udayavani, Sep 10, 2017, 5:20 PM IST

New Delhi : A new malware Xafecopy Trojan has been detected in India which steals money through victims’ mobile phones, cyber security firm Kaspersky said in a report. Around 40 per cent of target of the malware has been detected in India.

“Kaspersky Lab experts have uncovered a mobile malware targeting the WAP billing payment method, stealing money through victims’ mobile accounts without their knowledge,” the report said. Xafecopy Trojan is disguised as useful apps like BatteryMaster, and operates normally. The trojan secretly loads malicious code onto the device.

Once the app is activated, the Xafecopy malware clicks on web pages with Wireless Application Protocol (WAP) billing – a form of mobile payment that charges costs directly to the user’s mobile phone bill. After this the malware silently subscribes the phone to a number of services, the report said.

The process also does not require user to register a debit or credit card or set up a user-name and password. The malware uses technology to bypass ‘captcha’ systems designed to protect users by confirming the action is being performed by a human. In the captcha system, websites show a set of some letter or numbers which are required to be manually filled by the user.

“Xafecopy hit more than 4,800 users in 47 countries within the space of a month, with 37.5 per cent of the attacks detected and blocked by Kaspersky Lab products targeting India, followed by Russia, Turkey and Mexico,” the report said. Experts at Kaspersky Lab have found traces showing that cyber criminals gang promulgating other trojans are sharing malware code among themselves.

“Our research suggests WAP billing attacks are on the rise. Xafecopy’s attacks targeted countries where this payment method is popular. The malware has also been detected with different modifications, such as the ability to text messages from a mobile device to premium-rate phone numbers, and to delete incoming text messages to hide alerts from mobile network operators about stolen money,” Kaspersky Lab Senior Malware Analyst Roman Unuchek said.

Kaspersky Lab, Managing Director- South Asia, Altaf Halde said that Android users need to be extremely cautious in how they download apps. “It is best not to trust third-party apps, and whatever apps users do download should be scanned locally with the Verify Apps utility. But beyond that, Android users should be running a mobile security suite on their devices.

Udayavani is now on Telegram. Click here to join our channel and stay updated with the latest news.

Top News

Assembly clears Mysuru Development Authority Bill

Congress claims party worker ‘died due to tear gas smoke’ during protest in Assam

BJP using legislature for ‘politics’ instead of discussing real issues: CM Siddaramaiah

Congress twisted facts, distorted my statement on Ambedkar: Amit Shah

Govt will not remove temples built on Waqf properties, CM Siddaramaiah tells Assembly

Not God, but Constitution that saves oppressed people: Karnataka Minister Mahadevappa

One dead, 66 rescued after ferry capsizes off Mumbai coast

Related Articles More

Blocked 18 OTT platforms for publishing obscene, vulgar content: Govt

Congress claims party worker ‘died due to tear gas smoke’ during protest in Assam

Rajasthan govt to replace Urdu terms in policing with Hindi words

Congress twisted facts, distorted my statement on Ambedkar: Amit Shah

One dead, 66 rescued after ferry capsizes off Mumbai coast

MUST WATCH

Feeding Birds with Creative Paddy Art!

Areca Nut

HOTEL SRI DURGA BHAVANA

Harish Poonja

Heartwarming Miracle!


Latest Additions

Assembly clears Mysuru Development Authority Bill

Blocked 18 OTT platforms for publishing obscene, vulgar content: Govt

Boy critically injured after tree branch falls on him in Bengaluru

Congress claims party worker ‘died due to tear gas smoke’ during protest in Assam

Four dead in road accident in Kolar

Thanks for visiting Udayavani

You seem to have an Ad Blocker on.
To continue reading, please turn it off or whitelist Udayavani.