This research from ThreatFabric discusses some really interesting mobile malware. Maybe it’s my bias, but it seems like a good chunk of our industry would rather forget about the mobile attack surface. Perhaps because it’s annoying to research? Anyway, check this out.
Two interesting things about this: the Accessibility persistence mechanism allows this to overlay the numpad-style keyboard on Android devices, meaning it captures PINs and unlock passcodes across the OS—yes, even from the lock screen. So that’s gnarly. Additionally, it has a fallback C2 mechanism that beacons over BLE and WiFi to find other nearby infected devices and create a multi-hop C2/exfiltration chain when necessary. That’s wild.
This is in Cyber News because there is not a lot actionable here, especially because the research does not discuss delivery methods. But the nature of the malware suggests, at least to me, specific targeting of high-level individuals. The geographic targeting is notable as well.
How would you defend against this, short of iOS in Lockdown Mode? If Android is, for whatever reason, a requirement, the options for true defense seem rather limited.