RiSec.n0tst3 8 January 2022
The widely distributed FluBot malware continues to evolve, with new campaigns distributing the malware as Flash Player and the developers adding new features. FluBot is an Android banking trojan that steals credentials by displaying overlay login forms against many banks worldwide. The smishing (SMS phishing) lures for its distribution include fake security updates, fake Adobe Flash Players, voicemail memos, and impersonating parcel delivery notices. Once in the device, FluBot can steal online banking credentials, send or intercept SMS messages (and one-time passwords), and capture screenshots. Because the malware uses the victim’s device...