s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.roaming_mantis

📛 Threat Title

Malware family: Roaming Mantis

Category: Roaming Mantis First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.roaming_mantis`. Printable name: Roaming Mantis.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:digitalterminal.in

    Kaspersky researchers reported on a new domain name system (DNS) changer functionality used in the Roaming Mantis campaign. Now cybercriminals can use compromised Wi-Fi routers in cafes, airports hotels and other public places to potentially infect more Android smartphones with the Wroba.o malware . At the moment, the new technique targets users in South Korea, but it can be soon implemented in ...

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the Roaming Mantis malware family including references, samples and yara signatures.

  • web:novatech.net

    In this spirit, let's look at a problem that started as Android malware and has since grown into an advanced persistent threat (APT). The ID Theft Ring of Roaming Mantis In 2018, Kaspersky researchers gave the name " Roaming Mantis " to both a Chinese cybercrime group and an APT campaign.

  • web:securityaffairs.com

    Roaming Mantis threat actors were observed using a new variant of their mobile malware Wroba to hijack DNS settings of Wi-Fi routers.

  • web:thehackernews.com

    Roaming Mantis , also known as Shaoye, is a long-running financially motivated operation that singles out Android smartphone users with malware capable of stealing bank account credentials as well as harvesting other kinds of sensitive information.

  • web:www.anomali.com

    In South Korea, Roaming Mantis implemented a new DNS changer function. XLoader-infected Android devices were targeting specific Wi-Fi routers used mostly in South Korea. The malware would compromise routers with default credentials and change the DNS settings to serve malicious landing pages from legitimate domains.

  • web:www.cyberaffairs.com

    About Roaming Mantis For your information, Roaming Mantis is a financially motivated, long-running cybercrime campaign in which attackers target Android smartphones and infect them with malware to steal banking credentials and sensitive data. The campaign was first observed in April 2018 by Kaspersky when it used DNS hijacking to infect Android smartphones and hijack data.

  • web:www.darkreading.com

    The name of the campaign is based on its propagation via smartphones roaming between Wi-Fi networks, potentially carrying and spreading the infection. New DNS changer functionality to attack more ...

  • web:www.kaspersky.com

    On January 19, Kaspersky researchers reported on a new domain name system (DNS) changer functionality used in the Roaming Mantis campaign. Now cybercriminals can use compromised Wi-Fi routers in cafes, airports hotels and other public places to potentially infect more Android smartphones with the Wroba.o malware . At the moment, the new technique targets users in South Korea, but it can be soon ...

  • web:www.msspalert.com

    The Roaming Mantis cyber threat crew (aka Shaoye) are attacking Wi-Fi routers in public locations to spread Android malware known as Wroba.o.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.