MOSCOW, August 5 Kaspersky Lab has discovered a new malware, LianSpy, which targets owners of electronic devices in Russia running the Android operating system, the company said.
«
«Kaspersky Lab specialists have discovered a spyware Trojan and named it LianSpy. The malware is used in a cyberespionage campaign targeting specific Android device owners in Russia. It has been going on for several years now and is still a relevant cyber threat to users today. The attackers are actively hiding their tracks, which made it difficult to detect the malware,» the report says.
It is noted that LianSpy disguises itself as system applications and financial services. It collects and transmits to the attackers a list of contacts from the infected device, as well as call log data and a list of installed applications. The Trojan is capable of recording the smartphone screen when opening certain mobile applications, mainly instant messengers. The company added that the attackers are not interested in the financial information of the victims.
According to the company's experts, when launched, the malware «hides» its icon and works in the background so that it is not detected, after which it actively uses superuser rights. In this way, it gains full control over the device and the ability to hide its activity. For example, it can bypass Android notifications that clearly show that the camera or microphone is currently being used on the phone.
«LianSpy has unusual techniques for a mobile spy. For example, it uses a combination of symmetric and asymmetric encryption. In addition, the malware does not use any private infrastructure — only public services. This, in particular, complicates the process of attributing the campaign to any group of attackers,» the company explained.
Свежие комментарии