New malware creates chaos among users of old Android phones

0
15

Users of old Android phones know that, unlike those who have recently released a terminal, they are exposed to a series of possible problems. And now a new malware that is in circulation confirms this in the worst of ways: infecting devices in bulk. The latest data published suggests that there are more than 120 active attacks that are using the same malware to do their thing.

Cybercriminals who are resorting to using this malware known as Rafel RAT are putting their boots on the ground and do not stop exploiting it with the intention of causing users a lot of headaches. In some cases, according to comments from security experts that come from the network, it is suggested that the malware activates a ransomware system that blocks the victims’ mobile phones until they make a release payment through Telegram.

How infection occurs?

As usual, this is a threat that is hidden in certain applications or that is distributed through them with malicious links. In many cases, according to the security firm Check Point, this threat hides camouflaged as an antivirus in which users end up giving permissions that they should not. Other times it comes through links from Telegram, WhatsApp, Instagram and many other apps that can be installed on mobile phones.

Android Rafel RAT malware infection process

Once the Rafel RAT malware enters a victim’s mobile phone, depending on the cybercriminal’s intentions, it can generate different effects. Hackers who take advantage of this can use a wide series of malicious commands, although they say that the five most common are the following: ransomware (to encrypt and lock the mobile), wipe (to delete files remotely), LockTheScreen ( blocks the mobile and makes it useless), sms_oku (sends all SMS and 2FA codes to the cybercriminal’s control center) and location_tracker (filters the location of the mobile, with all that that entails). However, there are more commands that cybercriminals can use, so this is a really dangerous infection.

Who is at risk?

As we said, they are old Android phones. But how old exactly? As they say from Check Point, these are terminals that use a version of Android that has been categorized as obsolete. According to their figures, 87.5% of those affected by these malware attacks have Android 11 or an earlier version, while 12.5% ​​have Android version 12 or 13. If we talk about brands, there is practically no manufacturer let it be saved. This shows that the problem is not with the brand, but with using an Android mobile that has become obsolete, something that is never recommended because it can expose you to this type of problems.

Different versions affected by the Rafel RAT malware

Regarding whether it is a significant risk at the user level or not, Check Point mentions that many of those affected are members of the government, the military sector or even people from large companies. This should lessen a bit of seriousness for users, but it does not mean that they can feel safe if they have one of these mobile phones in their possession. What is said to relax us a little is knowing that most of the victims are physically in China, the United States or Indonesia.

One of the situations that has been given as an example by Check Point has been the attack suffered by a user whose call logs have been deleted by cybercriminals, their screen has been blocked, their image background has been changed and they have activated the vibration. They have also sent him an SMS message with a comment telling him to contact them on Telegram to resolve the problem he is having with his mobile. From that moment on, they ask him to pay a ransom for the cell phone and, if he does not do so, he knows that he could face worse consequences.

Map of Rafel RAT infections in the world

The advice given by Check Point so that this does not happen to you is the usual advice that you have surely heard. Above all, do not download APK files from dubious applications because you never know what they may have inside. Second, do not click on URLs that you receive in messages or SMS and, finally, always check everything you are going to install using Play Protect. This will reduce your level of risk, although it is obvious that, above all, you should think about abandoning the use of mobile phones that are no longer protected.

Previous articleThis is how you can create the Europass curriculum that more and more companies and institutions are requesting
Next articleThis is what we miss most about Windows XP after 10 years of its end