Slashdot Mirror


Malware Targets All Android Phones — Except Those In Russia (csoonline.com)

itwbennett writes: MazarBOT, a malware program that can take full control of Android phones, appears to be targeting online bank accounts. The malware has been seen advertised on Russian underground forums in the last few months and surfaced over the weekend. '[On] Friday, a swarm of SMSs were sent to random phone numbers in Denmark and likely elsewhere. The content of the SMS had the purpose of luring the recipient into clicking the provided link, which would serve up a malicious APK,' wrote Peter Kruse, an IT security expert and founder of CSIS Security Group. One interesting feature: 'MazarBOT will stop installing itself if it detects an Android device that is running within Russia,' writes Jeremy Kirk.

4 of 78 comments (clear)

  1. Russia refuses to police their country by Anonymous Coward · · Score: 4, Insightful

    Why is it that so much malware and online crime comes from Russia? The country simply refuses to police themselves, even when things are obviously illegal. The overall effects are pretty severe to other countries. I'd support sanctioning Putin directly to prevent him from entering the EU. Then I'd also effectively cut them off from the internet by terminating any wired links between them and the EU while dropping all connections coming from IPs assigned to entities in Russia. Cutting Russia off from the internet to the best of our ability is really the only way to stop the excessive crime from that country.

    1. Re:Russia refuses to police their country by Anonymous Coward · · Score: 4, Insightful

      Why is it that so much malware and online crime comes from Russia?

      It isn't Russia specifically. I see enough malware coming from the US too.
      The thing that is new here is that the criminals have realized that neither country gives a shit about what happens to people in other countries. Russia isn't going to bother with criminals that doesn't hurt their own population and they aren't going to let foreign police dick around. This means that by only targeting population in other countries the criminals know that there won't be an investigation.

  2. How is this even a thing? by Gumbercules!! · · Score: 4, Insightful

    Firstly, the link in the article above takes you to a site which has nothing at all in it about Android malware. It's completely about Linux malware that's injected via Windows machines. So what the hell is it doing in the article as the primary link?

    Then, if I understand correctly (based on the summary alone - because, you know, the primary linked article is clearly completely wrong), you'd need to:

    1. Get an SMS with a link in it.
    2. Click the link.
    3. Get redirected to a website (which Chrome doesn't block).
    4. Download an APK from that site.
    5. Attempt to sideload it.
    6. Realise you can't sideload it without disabling default security options (because the second link does indeed say that the user needs to manually install the APK).
    7. Go disable default security options.
    8. Sideload the APK.

    WHO THE FUCK FALLS FOR THIS SHIT?!?!

    Seriously? How the hell do people successfully find idiots who will do that kind of thing?

  3. Pot meet kettle by sjbe · · Score: 3, Insightful

    Why is it that so much malware and online crime comes from Russia?

    You could ask the same question about any large country including the United States. Russia in particular has a bit of the wild west going on and I think the authorities there might turn a blind eye if it negatively impacts rival countries.

    The country simply refuses to police themselves, even when things are obviously illegal.

    You mean like how in the US we have police straight up murdering black people without repercussions? Or how the NSA blatantly violates the constitution? Or how we imprison people in Cuba indefinitely without any trial? Yeah, Russia has some problems but it's not like our poop lacks odor...

    I'd support sanctioning Putin directly to prevent him from entering the EU.

    Umm, are you aware that Russia supplies much of the EU with huge amounts of oil and gas that cannot be gotten elsewhere quickly? All Putin has to do is shut off a key pipeline or two (which he has done a few times) and it gets awfully cold really fast in some parts of the EU. Furthermore actions like what you suggest are frankly kind of a juvenile response. Putin might be behind all of it (he isn't) but keeping the head of state of Russia arbitrarily out would accomplish very little and would actually do more harm than good in all likelihood.

    Cutting Russia off from the internet to the best of our ability is really the only way to stop the excessive crime from that country.

    No it really wouldn't.