TF-MAL-apk.roaming_mantis
📛 Threat Title
Malware family: Roaming Mantis
Description
ThreatFox malware family `apk.roaming_mantis`. Printable name: Roaming Mantis.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:digitalterminal.in
Kaspersky researchers reported on a new domain name system (DNS) changer functionality used in the Roaming Mantis campaign. Now cybercriminals can use compromised Wi-Fi routers in cafes, airports hotels and other public places to potentially infect more Android smartphones with the Wroba.o malware . At the moment, the new technique targets users in South Korea, but it can be soon implemented in ...
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the Roaming Mantis malware family including references, samples and yara signatures.
-
web:novatech.net
In this spirit, let's look at a problem that started as Android malware and has since grown into an advanced persistent threat (APT). The ID Theft Ring of Roaming Mantis In 2018, Kaspersky researchers gave the name " Roaming Mantis " to both a Chinese cybercrime group and an APT campaign.
-
web:securityaffairs.com
Roaming Mantis threat actors were observed using a new variant of their mobile malware Wroba to hijack DNS settings of Wi-Fi routers.
-
web:thehackernews.com
Roaming Mantis , also known as Shaoye, is a long-running financially motivated operation that singles out Android smartphone users with malware capable of stealing bank account credentials as well as harvesting other kinds of sensitive information.
-
web:www.anomali.com
In South Korea, Roaming Mantis implemented a new DNS changer function. XLoader-infected Android devices were targeting specific Wi-Fi routers used mostly in South Korea. The malware would compromise routers with default credentials and change the DNS settings to serve malicious landing pages from legitimate domains.
-
web:www.cyberaffairs.com
About Roaming Mantis For your information, Roaming Mantis is a financially motivated, long-running cybercrime campaign in which attackers target Android smartphones and infect them with malware to steal banking credentials and sensitive data. The campaign was first observed in April 2018 by Kaspersky when it used DNS hijacking to infect Android smartphones and hijack data.
-
web:www.darkreading.com
The name of the campaign is based on its propagation via smartphones roaming between Wi-Fi networks, potentially carrying and spreading the infection. New DNS changer functionality to attack more ...
-
web:www.kaspersky.com
On January 19, Kaspersky researchers reported on a new domain name system (DNS) changer functionality used in the Roaming Mantis campaign. Now cybercriminals can use compromised Wi-Fi routers in cafes, airports hotels and other public places to potentially infect more Android smartphones with the Wroba.o malware . At the moment, the new technique targets users in South Korea, but it can be soon ...
-
web:www.msspalert.com
The Roaming Mantis cyber threat crew (aka Shaoye) are attacking Wi-Fi routers in public locations to spread Android malware known as Wroba.o.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.