<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cybersecurity Archives - Evina</title>
	<atom:link href="https://www.evina.com/tag/cybersecurity/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.evina.com/tag/cybersecurity/</link>
	<description>The most advanced cybersecurity for mobile payments and digital regulation</description>
	<lastBuildDate>Fri, 06 Jan 2023 14:35:01 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>

<image>
	<url>https://www.evina.com/wp-content/uploads/2020/12/cropped-evina-ico-1-32x32.png</url>
	<title>Cybersecurity Archives - Evina</title>
	<link>https://www.evina.com/tag/cybersecurity/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>DCB Index 2022: Insights into the Direct Carrier Billing Market in the Middle East and Africa</title>
		<link>https://www.evina.com/dcb-index-2022-insights-into-the-direct-carrier-billing-market-in-the-middle-east-and-africa/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=dcb-index-2022-insights-into-the-direct-carrier-billing-market-in-the-middle-east-and-africa</link>
					<comments>https://www.evina.com/dcb-index-2022-insights-into-the-direct-carrier-billing-market-in-the-middle-east-and-africa/#respond</comments>
		
		<dc:creator><![CDATA[Evina]]></dc:creator>
		<pubDate>Wed, 28 Dec 2022 10:35:58 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Business growth]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<guid isPermaLink="false">https://www.evina.com/?p=6913</guid>

					<description><![CDATA[<p>We are pleased to announce the release of the 2022 edition of the Direct Carrier Billing (DCB) Index, a collaboration between Evina and Telecoming. This initiative is part of our strategic alliance to place direct carrier billing (DCB) at the forefront of the payments industry and reinforce our commitment to developing a transparent, secure, and stable mobile economy.</p>
<p>The post <a href="https://www.evina.com/dcb-index-2022-insights-into-the-direct-carrier-billing-market-in-the-middle-east-and-africa/">DCB Index 2022: Insights into the Direct Carrier Billing Market in the Middle East and Africa</a> appeared first on <a href="https://www.evina.com">Evina</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">The DCB Index provides insights into the direct carrier billing market of countries in the Middle East and Africa region (MEA), ranking them according to their current DCB status and potential to further develop this growth-boosting mobile payment method. The classification ranges from 1 to 5, with 1 being the lowest and 5 the highest DCB potential. The ranking is based on four main factors: mobile players&#8217; actions to prevent fraud on DCB, their bent to innovate in DCB, the country&#8217;s overall DCB penetration, and the DCB growth potential.</p>



<p class="wp-block-paragraph">According to the results of the DCB Index, South Africa is the leading country in the ranking, with the highest score (3.4 out of 5). In the Middle East and North Africa, Morocco and the UAE stand out, surpassing last year&#8217;s leader, Bahrain. Nigeria and the Democratic Republic of Congo also rank highly, with 3.1 and 3.0 respectively.</p>



<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="1024" height="512" src="https://www.evina.com/wp-content/uploads/2022/12/MapIndex-1024x512.png" alt="" class="wp-image-6919" srcset="https://www.evina.com/wp-content/uploads/2022/12/MapIndex-1024x512.png 1024w, https://www.evina.com/wp-content/uploads/2022/12/MapIndex-300x150.png 300w, https://www.evina.com/wp-content/uploads/2022/12/MapIndex-768x384.png 768w, https://www.evina.com/wp-content/uploads/2022/12/MapIndex-1536x768.png 1536w, https://www.evina.com/wp-content/uploads/2022/12/MapIndex-2048x1024.png 2048w, https://www.evina.com/wp-content/uploads/2022/12/MapIndex-464x232.png 464w, https://www.evina.com/wp-content/uploads/2022/12/MapIndex-928x464.png 928w, https://www.evina.com/wp-content/uploads/2022/12/MapIndex-500x250.png 500w, https://www.evina.com/wp-content/uploads/2022/12/MapIndex-1000x500.png 1000w, https://www.evina.com/wp-content/uploads/2022/12/MapIndex-1320x660.png 1320w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption>Overview of the countries included in the DCB Index 2022 and their ranking in the index. </figcaption></figure>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">DCB has proven to be a powerful payment tool in the MEA region, and the overall fraud prevention of mobile players has increased by 0.2 compared to 2021, showing a collective willingness to safeguard this technology. DCB has the potential to become even more powerful than credit cards, and mobile operators have all the advantages to elevate DCB and become major fintech companies. However, it is important that businesses protect DCB with the right cybersecurity solutions.</p>



<p class="wp-block-paragraph">The DCB Index is intended to provide mobile players with an overview of the development of DCB in the MEA region, helping them to better understand how to improve their business in their own country or what conditions to consider when deploying in other countries.&nbsp;</p>



<div class="btn-group">
																														<a href="https://www.evina.com/wp-content/uploads/2022/12/INFOGRAPHIC-2022-DCB-INDEX-EVINA-TELECOMING.pdf" class="btn btn-strong scrollTo">View the complete DCB Index here</a>
											
																	</div>
<p>The post <a href="https://www.evina.com/dcb-index-2022-insights-into-the-direct-carrier-billing-market-in-the-middle-east-and-africa/">DCB Index 2022: Insights into the Direct Carrier Billing Market in the Middle East and Africa</a> appeared first on <a href="https://www.evina.com">Evina</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.evina.com/dcb-index-2022-insights-into-the-direct-carrier-billing-market-in-the-middle-east-and-africa/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>How a malware-infected messaging app is impersonating millions of users worldwide</title>
		<link>https://www.evina.com/how-a-malware-infected-messaging-app-is-impersonating-millions-of-users-worldwide/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=how-a-malware-infected-messaging-app-is-impersonating-millions-of-users-worldwide</link>
					<comments>https://www.evina.com/how-a-malware-infected-messaging-app-is-impersonating-millions-of-users-worldwide/#respond</comments>
		
		<dc:creator><![CDATA[Evina]]></dc:creator>
		<pubDate>Mon, 05 Dec 2022 16:56:10 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<guid isPermaLink="false">https://www.evina.com/?p=6752</guid>

					<description><![CDATA[<p>At Evina, we are equipped with the most advanced cybersecurity technology developed over 15 years of research and development, and experienced malware hunters who discover the most sophisticated malware hidden in app stores. The new malware that impersonates users by stealing their phone numbers is the latest addition to the series of malware our team uncovers each year. </p>
<p>The post <a href="https://www.evina.com/how-a-malware-infected-messaging-app-is-impersonating-millions-of-users-worldwide/">How a malware-infected messaging app is impersonating millions of users worldwide</a> appeared first on <a href="https://www.evina.com">Evina</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">We asked one of Evina’s top malware hunters how this newly uncovered malware operates. Here’s what you should know.</p>



<div class="wp-block-image"><figure class="alignleft is-resized"><img decoding="async" src="https://lh5.googleusercontent.com/f-HJSaQfBbVnEwyiHmfKLXI6zfR8aV7fU-VelaR4_ZVtC-bSWwxsUNyzPHIP1CASBITRiNcKoiNGwhR1NKdSzqfE5v5b8LYSvmQm4GRinnCV2H0Nr-T5EUShtbGvm8XVqURzXj4tVizl05dI_sCgGjyx8DFvR7lq7sIY0s6bVT9mqlyoS6Wsat5IdQLb8Q" alt="" width="189" height="397"/></figure></div>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"><strong>Can you tell us more about where the malware hides?</strong></p>



<p class="wp-block-paragraph">The malware is hidden in a messaging app named Symoo on the Google Play Store.</p>



<p class="wp-block-paragraph">It’s available worldwide, but the app has been downloaded the most by users in India, Bangladesh, Pakistan, Algeria and Nepal. </p>



<p class="wp-block-paragraph">You won’t find the app anymore on the Google Play Store however, as it’s been removed following our press release.</p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"><strong>The malware steals phone numbers from users, how exactly does it do that?&nbsp;&nbsp;</strong></p>



<p class="wp-block-paragraph">So the first thing to understand is that the infected app Symoo masquerades as a legitimate messaging app to impersonate users and create fake social media accounts.</p>



<p class="wp-block-paragraph">It starts out with a user that finds the app on the app store, downloads it, and when it opens the infected app, the first thing that pops up is the app’s request to get the user’s phone number.&nbsp;</p>



<p class="wp-block-paragraph">When the user launchers the app, a loading screen appears and in the meantime, the app has launched a malicious program in the background that sends the user’s phone number to an external server and intercepts all SMS messages.&nbsp;</p>



<p class="wp-block-paragraph">This external server is used by a marketplace that collects the stolen phone number and reads the SMS messages linked to this number to obtain one-time codes that allow to create fake social media accounts. Millions of fake accounts on popular social networks like Facebook or Telegram are created this way and individuals can purchase these fake account directly from this platform to remain anonymous while potentially perpetrating criminal actions.&nbsp;</p>



<p class="wp-block-paragraph"><strong>What has been the malware’s impact up to now?</strong></p>



<p class="wp-block-paragraph">All users that have downloaded the infected app and entered their phone number are victims of the malware. These users now have fake social media profiles linked to their phone number and they aren’t aware. In India, there are 100K victims, in Pakistan 9K, in Algeria 3K and in Morocco 1K.</p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.evina.com/wp-content/uploads/2022/12/Iphones.png" alt="" class="wp-image-6753" width="494" height="466" srcset="https://www.evina.com/wp-content/uploads/2022/12/Iphones.png 1019w, https://www.evina.com/wp-content/uploads/2022/12/Iphones-300x283.png 300w, https://www.evina.com/wp-content/uploads/2022/12/Iphones-768x725.png 768w, https://www.evina.com/wp-content/uploads/2022/12/Iphones-246x232.png 246w, https://www.evina.com/wp-content/uploads/2022/12/Iphones-491x464.png 491w, https://www.evina.com/wp-content/uploads/2022/12/Iphones-429x405.png 429w, https://www.evina.com/wp-content/uploads/2022/12/Iphones-858x810.png 858w" sizes="(max-width: 494px) 100vw, 494px" /><figcaption>&nbsp;These images show (1) the countries where the malware has stolen from users and (2) the number of fake accounts per social media platforms available on the marketplace.<br></figcaption></figure>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">For more information, <a href="https://www.evina.com/press-releases/cybercriminals-attack-india-pakistan-morocco-and-algeria-via-malware-infected-app/">read the full press release</a>.</p>
<p>The post <a href="https://www.evina.com/how-a-malware-infected-messaging-app-is-impersonating-millions-of-users-worldwide/">How a malware-infected messaging app is impersonating millions of users worldwide</a> appeared first on <a href="https://www.evina.com">Evina</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.evina.com/how-a-malware-infected-messaging-app-is-impersonating-millions-of-users-worldwide/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The return of the Facebook thieves</title>
		<link>https://www.evina.com/the-return-of-the-facebook-thieves/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=the-return-of-the-facebook-thieves</link>
					<comments>https://www.evina.com/the-return-of-the-facebook-thieves/#respond</comments>
		
		<dc:creator><![CDATA[Evina]]></dc:creator>
		<pubDate>Thu, 21 Oct 2021 08:18:32 +0000</pubDate>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<guid isPermaLink="false">https://www.evina.com/?p=4974</guid>

					<description><![CDATA[<p>About a year ago, our cybersecurity team's discovery of hidden in-app malware that was stealing Facebook credentials caught the attention of the press and the entire mobile ecosystem. This secret malware was stealing one of the most popular digital IDs of the decade, and it was going unnoticed.</p>
<p>The post <a href="https://www.evina.com/the-return-of-the-facebook-thieves/">The return of the Facebook thieves</a> appeared first on <a href="https://www.evina.com">Evina</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Today, Evina’s team of malware hunters have once again identified apps embedded with this kind of malware, which have persistently infected the most popular new free apps in the Play Store.&nbsp;</p>



<p class="wp-block-paragraph">They work in exactly the same way. Their objective is to steal mobile users’ Facebook login credentials and data.</p>



<p class="wp-block-paragraph">These apps require users to log in to their Facebook account to allow them to access the app&#8217;s content and, therefore, collect the credentials.</p>



<p class="wp-block-paragraph">Below is one of the apps that featured malware, and was downloaded over +500K times.</p>



<div class="wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex">
<div class="wp-block-column is-layout-flow wp-block-column-is-layout-flow" style="flex-basis:100%">
<figure class="wp-block-image size-large is-resized"><img loading="lazy" decoding="async" src="https://www.evina.com/wp-content/uploads/2021/10/Malware1-512x1024.jpeg" alt="" class="wp-image-4975" width="239" height="477" srcset="https://www.evina.com/wp-content/uploads/2021/10/Malware1-512x1024.jpeg 512w, https://www.evina.com/wp-content/uploads/2021/10/Malware1-150x300.jpeg 150w, https://www.evina.com/wp-content/uploads/2021/10/Malware1-768x1536.jpeg 768w, https://www.evina.com/wp-content/uploads/2021/10/Malware1-1024x2048.jpeg 1024w, https://www.evina.com/wp-content/uploads/2021/10/Malware1-116x232.jpeg 116w, https://www.evina.com/wp-content/uploads/2021/10/Malware1-232x464.jpeg 232w, https://www.evina.com/wp-content/uploads/2021/10/Malware1-203x405.jpeg 203w, https://www.evina.com/wp-content/uploads/2021/10/Malware1-405x810.jpeg 405w, https://www.evina.com/wp-content/uploads/2021/10/Malware1-1320x2640.jpeg 1320w, https://www.evina.com/wp-content/uploads/2021/10/Malware1-scaled.jpeg 1280w" sizes="auto, (max-width: 239px) 100vw, 239px" /><figcaption>Photo Motion &#8211; one of the infected apps</figcaption></figure>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"></p>
</div>
</div>



<figure class="wp-block-image size-large is-resized"><img loading="lazy" decoding="async" src="https://www.evina.com/wp-content/uploads/2021/10/Malware2-512x1024.jpeg" alt="" class="wp-image-4976" width="248" height="496" srcset="https://www.evina.com/wp-content/uploads/2021/10/Malware2-512x1024.jpeg 512w, https://www.evina.com/wp-content/uploads/2021/10/Malware2-150x300.jpeg 150w, https://www.evina.com/wp-content/uploads/2021/10/Malware2-768x1536.jpeg 768w, https://www.evina.com/wp-content/uploads/2021/10/Malware2-1024x2048.jpeg 1024w, https://www.evina.com/wp-content/uploads/2021/10/Malware2-116x232.jpeg 116w, https://www.evina.com/wp-content/uploads/2021/10/Malware2-232x464.jpeg 232w, https://www.evina.com/wp-content/uploads/2021/10/Malware2-203x405.jpeg 203w, https://www.evina.com/wp-content/uploads/2021/10/Malware2-405x810.jpeg 405w, https://www.evina.com/wp-content/uploads/2021/10/Malware2-1320x2640.jpeg 1320w, https://www.evina.com/wp-content/uploads/2021/10/Malware2-scaled.jpeg 1280w" sizes="auto, (max-width: 248px) 100vw, 248px" /><figcaption>The app requires the mobile user to log in to their Facebook account</figcaption></figure>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"></p>



<figure class="wp-block-image size-full is-resized"><img loading="lazy" decoding="async" src="https://www.evina.com/wp-content/uploads/2021/10/Malware3.png" alt="" class="wp-image-4977" width="473" height="410" srcset="https://www.evina.com/wp-content/uploads/2021/10/Malware3.png 640w, https://www.evina.com/wp-content/uploads/2021/10/Malware3-300x260.png 300w, https://www.evina.com/wp-content/uploads/2021/10/Malware3-268x232.png 268w, https://www.evina.com/wp-content/uploads/2021/10/Malware3-535x464.png 535w, https://www.evina.com/wp-content/uploads/2021/10/Malware3-467x405.png 467w" sizes="auto, (max-width: 473px) 100vw, 473px" /><figcaption>The app is ranked among the most popular free apps in many countries</figcaption></figure>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"><strong>How it works</strong></p>



<p class="wp-block-paragraph">To steal login credentials, the malware launches a webview and runs a javascript command to retrieve the values typed by the user.</p>



<p class="wp-block-paragraph">The next step is to use the API graph to get the account information.</p>



<p class="wp-block-paragraph"></p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="287" src="https://www.evina.com/wp-content/uploads/2021/10/Malware4-1-1024x287.png" alt="" class="wp-image-4979" srcset="https://www.evina.com/wp-content/uploads/2021/10/Malware4-1-1024x287.png 1024w, https://www.evina.com/wp-content/uploads/2021/10/Malware4-1-300x84.png 300w, https://www.evina.com/wp-content/uploads/2021/10/Malware4-1-768x215.png 768w, https://www.evina.com/wp-content/uploads/2021/10/Malware4-1-827x232.png 827w, https://www.evina.com/wp-content/uploads/2021/10/Malware4-1-500x140.png 500w, https://www.evina.com/wp-content/uploads/2021/10/Malware4-1-1000x280.png 1000w, https://www.evina.com/wp-content/uploads/2021/10/Malware4-1.png 1077w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption>Javascript commands to retrieve Facebook users&#8217; credentials</figcaption></figure>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="930" height="159" src="https://www.evina.com/wp-content/uploads/2021/10/Malware5.png" alt="" class="wp-image-4980" srcset="https://www.evina.com/wp-content/uploads/2021/10/Malware5.png 930w, https://www.evina.com/wp-content/uploads/2021/10/Malware5-300x51.png 300w, https://www.evina.com/wp-content/uploads/2021/10/Malware5-768x131.png 768w, https://www.evina.com/wp-content/uploads/2021/10/Malware5-500x85.png 500w" sizes="auto, (max-width: 930px) 100vw, 930px" /><figcaption>Request to the Facebook Graph API to obtain information about the Facebook profile</figcaption></figure>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"><strong>The interesting malware feature</strong></p>



<p class="wp-block-paragraph">The malware is interested in the advertising campaigns that mobile users might have launched, and it’s also interested in the credit card they have registered to do so.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">This allows the malware to create its own advertising campaigns with the mobile user’s account, and thus their credit card.</p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="856" height="245" src="https://www.evina.com/wp-content/uploads/2021/10/Malware6.png" alt="" class="wp-image-4981" srcset="https://www.evina.com/wp-content/uploads/2021/10/Malware6.png 856w, https://www.evina.com/wp-content/uploads/2021/10/Malware6-300x86.png 300w, https://www.evina.com/wp-content/uploads/2021/10/Malware6-768x220.png 768w, https://www.evina.com/wp-content/uploads/2021/10/Malware6-811x232.png 811w, https://www.evina.com/wp-content/uploads/2021/10/Malware6-500x143.png 500w" sizes="auto, (max-width: 856px) 100vw, 856px" /><figcaption>Obtains information on user ad campaigns</figcaption></figure>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">Here is a list of other identified malware-infected apps &#8211; in the top new apps of the Play Store:</p>



<p class="wp-block-paragraph"><a href="https://play.google.com/store/apps/details?id=com.cutestudio.neonphotoeffect&amp;gl=FR" target="_blank" rel="noreferrer noopener">https://play.google.com/store/apps/details?id=com.cutestudio.neonphotoeffect&amp;gl=FR</a></p>



<p class="wp-block-paragraph"><a href="https://t.co/nH6lgcGKBF?amp=1">https://play.google.com/store/apps/details?id=com.meicalhowell.motion.pixmotion…</a></p>



<p class="wp-block-paragraph"><a href="https://t.co/TCFOBfRo5e?amp=1">https://play.google.com/store/apps/details?id=com.Blodwen.Gower.photoeditlab…</a> </p>



<p class="wp-block-paragraph">Note: At the moment, most of these apps have been deleted.</p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"><strong>Credits: Maxime Ingrao</strong></p>



<p class="wp-block-paragraph"><br>To never miss a cybersecurity update, <a href="https://www.evina.com/the-fraud-observer/">subscribe to our newsletter.</a></p>
<p>The post <a href="https://www.evina.com/the-return-of-the-facebook-thieves/">The return of the Facebook thieves</a> appeared first on <a href="https://www.evina.com">Evina</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.evina.com/the-return-of-the-facebook-thieves/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>What is the future of cybersecurity? Philippe Vannier answers our questions.</title>
		<link>https://www.evina.com/what-is-the-future-of-cybersecurity-philippe-vannier-answers-our-questions/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=what-is-the-future-of-cybersecurity-philippe-vannier-answers-our-questions</link>
					<comments>https://www.evina.com/what-is-the-future-of-cybersecurity-philippe-vannier-answers-our-questions/#respond</comments>
		
		<dc:creator><![CDATA[Vanessa Palladino]]></dc:creator>
		<pubDate>Tue, 08 Sep 2020 17:54:00 +0000</pubDate>
				<category><![CDATA[Interviews]]></category>
		<category><![CDATA[Business growth]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<guid isPermaLink="false">https://www.evina.com/?p=1740</guid>

					<description><![CDATA[<p>Philippe Vannier has been founding Chairman of the Crescendo Industries fund since 2004. He has led numerous investments made by Crescendo in technology companies in the fields of Big Data and Security. </p>
<p>The post <a href="https://www.evina.com/what-is-the-future-of-cybersecurity-philippe-vannier-answers-our-questions/">What is the future of cybersecurity? Philippe Vannier answers our questions.</a> appeared first on <a href="https://www.evina.com">Evina</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">In this capacity, he was the largest shareholder and CEO of the Bull Group (€1.3 billion) until the friendly takeover bid by Atos at the end of 2014. Within Atos, he was Chief Technology Officer and Executive Vice President of Big Data &amp; Security until 2019, while remaining Chief Executive Officer of the Bull Group.&nbsp;</p>



<p class="wp-block-paragraph">He is also President of the European CyberSecurity Organisation (ECSO) in Brussels.</p>



<p class="wp-block-paragraph">As an expert in this field, we asked him about the cybersecurity challenges on the rise in the mobile era.</p>



<div class="wp-block-image"><figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" src="https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.55.32.png" alt="" class="wp-image-1742" width="412" height="274" srcset="https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.55.32.png 587w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.55.32-300x200.png 300w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.55.32-348x232.png 348w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.55.32-500x333.png 500w" sizes="auto, (max-width: 412px) 100vw, 412px" /><figcaption>Philippe Vannier</figcaption></figure></div>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"><strong>Evina has just published a case study that traces the origins and outcomes of its collaboration with the Belgian mobile phone operator Proximus. What are your thoughts on this case study?</strong></p>



<p class="wp-block-paragraph">This type of case study is very exciting as it clearly demonstrates the power of cybersecurity when it aligns with business objectives.</p>



<p class="wp-block-paragraph">My understanding is that Proximus was on the verge of closing down a large part of its mobile payment business simply because it had become too complex to manage. This unnecessary complexity was due to massive and repeated attacks by fraudsters. This would have been a reaction that we have often seen with other operators. However, Proximus decided to keep its wits about it, not panic and today it is reaping the rewards of not giving in to fraudsters.</p>



<p class="wp-block-paragraph">This decision to face and manage fraud proved to be more than worthwhile. Thanks to Evina’s technology, Proximus contained and then eliminated fraud and thus breathed new life into its mobile payment activities.</p>



<p class="wp-block-paragraph">This is a textbook case: not only does the operator now better protect its customers, but thanks to this newfound confidence, interactions are more fluid, more numerous and consequently revenues increase.</p>



<p class="wp-block-paragraph">Evina embodies this new era of cybersecurity, where we are moving from a defensive to an offensive expenditure that allows access to promising new markets.</p>



<p class="wp-block-paragraph"><strong>You talk about a new era in cybersecurity, what are the specifics?</strong></p>



<p class="wp-block-paragraph">The players in the Internet world are gradually becoming aware of the true potential of cybersecurity. It’s not just a question of avoiding tragedies, but of having a daily facilitator and accelerator of business.</p>



<p class="wp-block-paragraph">In this new era of cybersecurity, being a specialist in good protection practices is no longer enough. The crucial challenge today is to develop advanced technologies based on an in-depth knowledge of the global economic ecosystem.</p>



<p class="wp-block-paragraph">This knowledge of the ecosystem allows to intervene at multiple levels where fraudsters attack and therefore to not only protect each player but also to open up business opportunities by protecting and streamlining the entire chain.</p>



<p class="wp-block-paragraph">For example, in the world of mobile monetization where operators are at risk as well as advertisers, advertising agencies, merchants or payment aggregators, companies like Evina manage to intervene at all stages of interactions and with all players. This creates a beneficial chain reaction for everyone involved.</p>



<p class="wp-block-paragraph">Better protected networks mean fewer barriers and manual checks, so more simplicity, more speed, more transactions and more revenue for everyone.</p>



<p class="wp-block-paragraph"><strong>Does Evina have a unique market positioning?</strong></p>



<p class="wp-block-paragraph">While Evina’s positioning is perhaps not unique, it is nevertheless rare in the market for two reasons.</p>



<p class="wp-block-paragraph">Very often, cybersecurity companies are outside the ecosystem they intend to protect and therefore have a poor understanding of the issues at stake. In such cases, they can only protect to the detriment of turnover.</p>



<p class="wp-block-paragraph">In the case of cybersecurity companies that are part of the ecosystem, they often have links to certain actors which creates conflicts of interest and prevents the establishment of healthy relationships based on trust.</p>



<p class="wp-block-paragraph">This is why companies like Evina, who combine technical expertise, neutrality and knowledge of sectoral issues, are rare, yet essential for the long-term growth of the market. This makes them all the more valuable.</p>



<p class="wp-block-paragraph"><strong>How do you see the market evolving in the coming years?</strong></p>



<p class="wp-block-paragraph">Today more than ever, the Internet has the potential to be a formidable tool for prosperity.</p>



<p class="wp-block-paragraph">The increase in fraud, however, limits the full realization of this potential: barriers have been erected that were supposed to protect but which have above all prevented free trade.</p>



<p class="wp-block-paragraph">To gain a little more flexibility while avoiding the criminals, many have taken refuge in secure environments run by giants, all American. This strategy, though comfortable, is not without consequences. Aside from the Cloud Act, which is a pass on your data that the American authorities claim as their own, it always comes at a higher cost than expected.</p>



<p class="wp-block-paragraph">It’s a sub-optimal situation that makes too many losers to last forever.</p>



<p class="wp-block-paragraph">So we already see companies like Fortnite questioning Apple’s hegemony by leaving its closed environment.</p>



<p class="wp-block-paragraph">All companies that wish to escape the pincers between the taxation of GAFAM and the theft of criminals are in dire need of protection. This is why I believe in the emergence of these new high-tech companies that know how to align mastery of cybersecurity and business challenges.</p>



<p class="wp-block-paragraph">They will be crucial architects of the development of a safer and more prosperous Internet, and will undoubtedly be very richly rewarded for doing so.</p>
<p>The post <a href="https://www.evina.com/what-is-the-future-of-cybersecurity-philippe-vannier-answers-our-questions/">What is the future of cybersecurity? Philippe Vannier answers our questions.</a> appeared first on <a href="https://www.evina.com">Evina</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.evina.com/what-is-the-future-of-cybersecurity-philippe-vannier-answers-our-questions/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Donations for Lebanon: beware of scams, make sure your money reaches the right people.</title>
		<link>https://www.evina.com/donations-for-lebanon-beware-of-scams-make-sure-your-money-reaches-the-right-people/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=donations-for-lebanon-beware-of-scams-make-sure-your-money-reaches-the-right-people</link>
					<comments>https://www.evina.com/donations-for-lebanon-beware-of-scams-make-sure-your-money-reaches-the-right-people/#respond</comments>
		
		<dc:creator><![CDATA[Vanessa Palladino]]></dc:creator>
		<pubDate>Mon, 17 Aug 2020 13:01:00 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<guid isPermaLink="false">https://www.evina.com/?p=1940</guid>

					<description><![CDATA[<p>Whenever a catastrophe occurs, some people will always try to make a profit out of it. This is currently happening with the recent explosion in Lebanon. While donations pour in to help the victims, a lot of fraudulent websites have popped up to try and divert some of the money.</p>
<p>The post <a href="https://www.evina.com/donations-for-lebanon-beware-of-scams-make-sure-your-money-reaches-the-right-people/">Donations for Lebanon: beware of scams, make sure your money reaches the right people.</a> appeared first on <a href="https://www.evina.com">Evina</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">On the 4<sup>th</sup>&nbsp;of August 2020, Lebanon experienced an unprecedented tragedy. In the heart of Beirut, the country’s capital, a stock of ammonium nitrate exploded causing 171 deaths, and leaving thousands injured. Because of the substantial damage in the surrounding area, more than 300.000 people are currently homeless. The images were seen around the world, prompting an international show of solidarity. Donations are pouring in to help those affected, attracting the attention of scammers trying to pass themselves off as charities.</p>



<p class="wp-block-paragraph">In order to help, Evina used its knowledge in cybersecurity to check out numerous websites calling for donations for Lebanon, and identified which were legitimate websites and which ones were scams. Before sending money to a website, be certain to check the following points to make sure your donation will actually be of use to Lebanon.</p>



<p class="wp-block-paragraph">Each site must clearly display the name of the organisation as well as its address, and the mandatory terms and conditions. A simple Google search using the website’s name or URL generally unearths any negative existing feedback on the internet. Also check if there are any links to an external website or social network. Finally, do a search using any identifiable information given on the site, like the name of the PayPal account or the e-mail address. If it’s a scam, they will often appear on other fake websites.</p>



<h2 class="wp-block-heading">Websites to avoid</h2>



<p class="wp-block-paragraph">When analyzing these websites, Evina found enough elements to officially call them out as scams. <br><br>https://beyrouthshima.com<br></p>



<p class="wp-block-paragraph">This site doesn’t display either its name, address or the terms and conditions. Their PayPal account PIXER doesn’t belong to any known organisation. However, this account is used by another suspicious website, https://www.8cups.online, which again doesn’t include an address, and their social network links don’t work.</p>



<figure class="wp-block-image"><img decoding="async" src="https://www.evina.com/wp-content/uploads/2020/08/Beirut-1.jpg" alt=""/></figure>



<p class="wp-block-paragraph"><a href="https://savelebanonlives.com">https://savelebanonlives.com</a><br><br>This website doesn’t provide an address or the terms and conditions, and is completely unknown on Google or social networking platforms. Additionally, when you subscribe to their newsletter, you’ll receive an e-mail from givepalestine123@gmail.com. </p>



<figure class="wp-block-image"><img decoding="async" src="https://www.evina.com/wp-content/uploads/2020/08/Beirut-2-1024x383.jpg" alt=""/></figure>



<div style="height:40px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph"><a href="https://www.impactlebanon.org">https://www.impactlebanon.org</a><br><br>Aside from the missing address and terms and conditions, this is a phishing site asking for donations in cryptocurrency. It is impersonating another site (https://impactbeirutlebanon.com) by using the same logo and a similar URL.<br><br><a href="https://www.cryptofundlebanon.com">https://www.cryptofundlebanon.com</a><br><br>Yet again, the first clue with this website is the missing terms and conditions. However, this one is more easily spotted thanks to a link to a completely unrelated Instagram account. Additionally, the webmaster tried to promote his site on&nbsp;<a href="https://www.reddit.com/r/Bitcoin/comments/i6l5ts/bitcoin_disaster_relief_fund_for_the_blast_that/">Reddit</a> but ended up deleting his post when several comments called it out as a scam.</p>



<figure class="wp-block-image"><img decoding="async" src="https://www.evina.com/wp-content/uploads/2020/08/Beirut-3.jpg" alt=""/></figure>



<div style="height:40px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph"><a href="https://loveforlebanon.com">https://loveforlebanon.com</a><br><br>This website includes broken links to social networks, but what really helped identify this website as a scam was the contact e-mail contact@naturelove.org. The same address is used by numerous other websites that always ask for donations. This includes websites about&nbsp;<a href="https://androidgram.com/contact-us/">surf</a>ing,&nbsp;<a href="https://wearesurfer.com/contact-us/">weddings</a>,&nbsp;or&nbsp;<a href="https://androidgram.com/contact-us/">Android</a>&nbsp;news.</p>



<div class="wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex">
<div class="wp-block-column is-layout-flow wp-block-column-is-layout-flow" style="flex-basis:100%">
<figure class="wp-block-gallery columns-1 is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex"><ul class="blocks-gallery-grid"><li class="blocks-gallery-item"><figure><img loading="lazy" decoding="async" width="1024" height="845" src="https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-18-at-15.00.13-1024x845.png" alt="" data-id="1943" class="wp-image-1943" srcset="https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-18-at-15.00.13-1024x845.png 1024w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-18-at-15.00.13-300x247.png 300w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-18-at-15.00.13-768x633.png 768w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-18-at-15.00.13-281x232.png 281w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-18-at-15.00.13-563x464.png 563w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-18-at-15.00.13-491x405.png 491w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-18-at-15.00.13-982x810.png 982w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-18-at-15.00.13.png 1096w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure></li></ul></figure>
</div>
</div>



<figure class="wp-block-image is-resized"><img loading="lazy" decoding="async" src="https://www.evina.com/wp-content/uploads/2020/08/Beirut-6.jpg" alt="" width="268" height="215"/></figure>



<figure class="wp-block-image is-resized"><img loading="lazy" decoding="async" src="https://www.evina.com/wp-content/uploads/2020/08/Beirut-5.jpg" alt="" width="268" height="220"/></figure>



<h2 class="wp-block-heading">Websites to safely donate</h2>



<p class="wp-block-paragraph">The fact that these scams exist shouldn’t discourage you to help out the Lebanese population. Evina has compiled the following list of recommended websites, checked by us, so you can safely donate.</p>



<p class="wp-block-paragraph"><strong>ASHRAFIEH 2020:</strong>&nbsp;<a href="https://www.just-help.org/c/relieffund">https://www.just-help.org/c/relieffund</a></p>



<p class="wp-block-paragraph"><strong>BEIT EL BARAKA:</strong>&nbsp;<a href="https://www.beitelbaraka.org">https://www.beitelbaraka.org</a></p>



<p class="wp-block-paragraph"><strong>RIFAK el DARB:</strong>&nbsp;<a href="https://www.just-help.org/c/rifaqeldarb">https://www.just-help.org/c/rifaqeldarb</a></p>



<p class="wp-block-paragraph"><strong>BAYTNA BAYTAK:</strong>&nbsp;<a href="https://www.gofundme.com/f/help-beirut-explosion">https://www.gofundme.com/f/help-beirut-explosion</a></p>



<p class="wp-block-paragraph"><strong>IMPACT LEBANON:</strong>&nbsp;<a href="https://www.justgiving.com/crowdfunding/lebanon-relief">https://www.justgiving.com/crowdfunding/lebanon-relief</a></p>



<p class="wp-block-paragraph"><strong>OFFRE JOIE:</strong>&nbsp;<a href="https://www.givingloop.org/offrejoie">https://www.givingloop.org/offrejoie</a></p>



<p class="wp-block-paragraph"><strong>LEBANESE RED CROSS:</strong>&nbsp;<a href="https://www.supportlrc.app/donate/">https://www.supportlrc.app/donate/</a></p>



<p class="wp-block-paragraph"><strong>LEBANESE FOOD BANKS:</strong>&nbsp;<a href="https://donate.lebanesefoodbank.org/">https://lebanesefoodbank.org/donate/</a></p>
<p>The post <a href="https://www.evina.com/donations-for-lebanon-beware-of-scams-make-sure-your-money-reaches-the-right-people/">Donations for Lebanon: beware of scams, make sure your money reaches the right people.</a> appeared first on <a href="https://www.evina.com">Evina</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.evina.com/donations-for-lebanon-beware-of-scams-make-sure-your-money-reaches-the-right-people/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>They steal your Facebook</title>
		<link>https://www.evina.com/they-steal-your-facebook/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=they-steal-your-facebook</link>
					<comments>https://www.evina.com/they-steal-your-facebook/#respond</comments>
		
		<dc:creator><![CDATA[Vanessa Palladino]]></dc:creator>
		<pubDate>Tue, 09 Jun 2020 17:12:00 +0000</pubDate>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<guid isPermaLink="false">https://www.evina.com/?p=1656</guid>

					<description><![CDATA[<p>Evina blocks fraudulent traffic, but we don’t stop there.</p>
<p>The post <a href="https://www.evina.com/they-steal-your-facebook/">They steal your Facebook</a> appeared first on <a href="https://www.evina.com">Evina</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">New ways of perpetrating fraud are regularly brought to the attention of our cybersecurity experts and we recently discovered a new malware that steals Facebook logins. This malware could devastate your online and offline life by making off with the credentials of one of your most valued pieces of digital real estate. The malware was embedded in a large number of popular apps:</p>



<figure class="wp-block-image size-large is-resized"><img loading="lazy" decoding="async" src="https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-18.55.53.png" alt="" class="wp-image-1662" width="398" height="156" srcset="https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-18.55.53.png 940w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-18.55.53-300x118.png 300w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-18.55.53-768x303.png 768w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-18.55.53-588x232.png 588w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-18.55.53-500x197.png 500w" sizes="auto, (max-width: 398px) 100vw, 398px" /><figcaption>Example of infected apps</figcaption></figure>



<div style="height:40px" aria-hidden="true" class="wp-block-spacer"></div>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="668" height="852" src="https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-18.57.22.png" alt="" class="wp-image-1665" srcset="https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-18.57.22.png 668w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-18.57.22-235x300.png 235w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-18.57.22-182x232.png 182w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-18.57.22-364x464.png 364w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-18.57.22-318x405.png 318w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-18.57.22-635x810.png 635w" sizes="auto, (max-width: 668px) 100vw, 668px" /><figcaption>And it is no surprise that there were numerous unfortunate victims.</figcaption></figure>



<div style="height:40px" aria-hidden="true" class="wp-block-spacer"></div>



<figure class="wp-block-image size-large is-resized"><img loading="lazy" decoding="async" src="https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-18.58.36.png" alt="" class="wp-image-1667" width="280" height="143" srcset="https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-18.58.36.png 773w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-18.58.36-300x154.png 300w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-18.58.36-768x394.png 768w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-18.58.36-452x232.png 452w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-18.58.36-500x257.png 500w" sizes="auto, (max-width: 280px) 100vw, 280px" /><figcaption>Comments on the infected applications</figcaption></figure>



<div style="height:40px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph">We had Google shut down those applications. Evina managed to successfully reverse-engineer the malware which enabled us to protect end users against it. This is critical for our customers:</p>



<h3 class="wp-block-heading">Brigitte De Ducla, Orange France</h3>



<figure class="wp-block-image size-large is-resized"><img loading="lazy" decoding="async" src="https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.02.16.png" alt="" class="wp-image-1669" width="105" height="105" srcset="https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.02.16.png 372w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.02.16-300x300.png 300w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.02.16-150x150.png 150w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.02.16-232x232.png 232w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.02.16-80x80.png 80w" sizes="auto, (max-width: 105px) 100vw, 105px" /></figure>



<p class="wp-block-paragraph">&#8220;We have successful results with Evina; in addition to providing us with premium protection on our carrier billing, they also help us create a safer customer journey, therefore preserving the global experience of our clients&#8221;.</p>



<p class="wp-block-paragraph"><strong>Here’s how they steal your Facebook</strong></p>



<figure class="wp-block-image size-large is-resized"><img loading="lazy" decoding="async" src="https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.03.00.png" alt="" class="wp-image-1671" width="183" height="327" srcset="https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.03.00.png 420w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.03.00-168x300.png 168w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.03.00-130x232.png 130w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.03.00-259x464.png 259w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.03.00-226x405.png 226w" sizes="auto, (max-width: 183px) 100vw, 183px" /><figcaption>In the foreground is the malware browser, in the background the real application</figcaption></figure>



<div style="height:40px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph">When an application is launched on your phone, the malware queries the application name. If it is a Facebook application, the malware will launch a browser that loads Facebook at the same time. The browser is displayed in the foreground which makes you think that the application launched it. When you enter your credentials into this browser, the malware executes java script to retrieve them. The malware then sends your account information to a server.</p>



<figure class="wp-block-image size-large is-resized"><img loading="lazy" decoding="async" src="https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.04.22.png" alt="" class="wp-image-1677" width="483" height="45" srcset="https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.04.22.png 834w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.04.22-300x28.png 300w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.04.22-768x72.png 768w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.04.22-500x47.png 500w" sizes="auto, (max-width: 483px) 100vw, 483px" /><figcaption>Check if the Facebook app is running in the foreground</figcaption></figure>



<div style="height:40px" aria-hidden="true" class="wp-block-spacer"></div>



<figure class="wp-block-image size-large is-resized"><img loading="lazy" decoding="async" src="https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.05.06.png" alt="" class="wp-image-1681" width="348" height="93" srcset="https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.05.06.png 812w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.05.06-300x80.png 300w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.05.06-768x205.png 768w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.05.06-500x134.png 500w" sizes="auto, (max-width: 348px) 100vw, 348px" /><figcaption>Run the activity that contains the WebView</figcaption></figure>



<div style="height:40px" aria-hidden="true" class="wp-block-spacer"></div>



<figure class="wp-block-image size-large is-resized"><img loading="lazy" decoding="async" src="https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.06.31-1024x242.png" alt="" class="wp-image-1685" width="305" height="72" srcset="https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.06.31-1024x242.png 1024w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.06.31-300x71.png 300w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.06.31-768x182.png 768w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.06.31-980x232.png 980w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.06.31-500x118.png 500w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.06.31-1000x237.png 1000w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.06.31.png 1039w" sizes="auto, (max-width: 305px) 100vw, 305px" /><figcaption>The WebView loads the login page</figcaption></figure>



<div style="height:40px" aria-hidden="true" class="wp-block-spacer"></div>



<figure class="wp-block-image size-large is-resized"><img loading="lazy" decoding="async" src="https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.07.32-1024x158.png" alt="" class="wp-image-1690" width="417" height="64" srcset="https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.07.32-1024x158.png 1024w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.07.32-300x46.png 300w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.07.32-768x118.png 768w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.07.32-500x77.png 500w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.07.32-1000x154.png 1000w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.07.32.png 1053w" sizes="auto, (max-width: 417px) 100vw, 417px" /><figcaption>It executes javascript to get the credentials</figcaption></figure>



<div style="height:40px" aria-hidden="true" class="wp-block-spacer"></div>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="243" src="https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.08.27-1024x243.png" alt="" class="wp-image-1691" srcset="https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.08.27-1024x243.png 1024w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.08.27-300x71.png 300w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.08.27-768x182.png 768w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.08.27-977x232.png 977w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.08.27-500x119.png 500w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.08.27-1000x237.png 1000w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.08.27.png 1188w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption>And sends the data to airshop.pw<br></figcaption></figure>



<div style="height:40px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph">Lionel Ferri, Evina CTO: “It’s a fraudulent technique that points out the danger and reflects how important it is to protect yourself. It cannot be identified by Facebook as the malware displays in front of the legit app when it is launched”.</p>



<p class="wp-block-paragraph"><strong>Why are you always targeted? Because everyone is targeted.</strong></p>



<p class="wp-block-paragraph">Internet-based fraud has become so pervasive that sometimes it seems as if everyone you meet has, at some point or another, been a victim of digital fraud. Often when one is targeted by online fraudsters, the first reaction is ‘why me?’.</p>



<p class="wp-block-paragraph">Rest assured that we are all in the same boat and while it is normal for the victim to think they have been specifically targeted, we are all targets. Furthermore, we must highlight that victims should never be blamed for the criminal actions of others.</p>



<p class="wp-block-paragraph">Fraudsters are everywhere and they are not confined to the DCB sector. They lurk in every nook and cranny of the web and it is the job of experts like Evina to flush them out. Our clients are very helpful in this regard. They regularly provide us with valuable information that helps us lift the lid on what you could call the “digital fraud of the day”.</p>



<p class="wp-block-paragraph">In conclusion, keep in mind once that the victims are not the culprits: the app developer, the app store and all other legitimate players involved are simply innocent victims of fraudsters and their malware. </p>
<p>The post <a href="https://www.evina.com/they-steal-your-facebook/">They steal your Facebook</a> appeared first on <a href="https://www.evina.com">Evina</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.evina.com/they-steal-your-facebook/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Evina protects end users from MobOk: an incessantly mutating malware family in Germany</title>
		<link>https://www.evina.com/evina-protects-end-users-from-mobok-an-incessantly-mutating-malware-family-in-germany/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=evina-protects-end-users-from-mobok-an-incessantly-mutating-malware-family-in-germany</link>
					<comments>https://www.evina.com/evina-protects-end-users-from-mobok-an-incessantly-mutating-malware-family-in-germany/#respond</comments>
		
		<dc:creator><![CDATA[Vanessa Palladino]]></dc:creator>
		<pubDate>Thu, 16 Apr 2020 09:51:00 +0000</pubDate>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<guid isPermaLink="false">https://www.evina.com/?p=2356</guid>

					<description><![CDATA[<p>Evina has detected the MobOk family of mobile malware in 49 Android applications.</p>
<p>The post <a href="https://www.evina.com/evina-protects-end-users-from-mobok-an-incessantly-mutating-malware-family-in-germany/">Evina protects end users from MobOk: an incessantly mutating malware family in Germany</a> appeared first on <a href="https://www.evina.com">Evina</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Several clues indicate a concentration of some of the malware in Germany. Even though it is unusual to see a whole family of malware victims in the same country, fraudsters always look for accessible targets and work on the weaknesses as long as it is lucrative. Germany is unfortunately not exempted. As typical for most malware, MobOk continues to evolve the way it hides its malicious code and fraud methods. In the world of mobile malware, this makes MobOk a particularly challenging opponent.</p>



<p class="wp-block-paragraph"><strong>All Evina customers: mobile operators, payment gateways and content editors are protected from MobOk and in doing so, so are all their customers.</strong></p>



<p class="wp-block-paragraph">How does it work? MobOk collects information that is useful for its fraudulent activities such as the relevant operator details and mobile device screen size. It then launches an invisible browser that aims to subscribe the user to premium-rate mobile services using the applicable billing operator. </p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="380" src="https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.42.35-1024x380.png" alt="" class="wp-image-2359" srcset="https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.42.35-1024x380.png 1024w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.42.35-300x111.png 300w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.42.35-768x285.png 768w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.42.35-625x232.png 625w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.42.35-500x186.png 500w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.42.35-1000x371.png 1000w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.42.35.png 1078w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption><em>Some MobOk malware applications</em></figcaption></figure>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">MobOk will ask for permission to read notifications and this is how the malware is able to retrieve the content of SMS messages. Consumers have to accept permissions manually.</p>



<figure class="wp-block-image size-large is-resized"><img loading="lazy" decoding="async" src="https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.41.14.png" alt="" class="wp-image-2357" width="218" height="462" srcset="https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.41.14.png 472w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.41.14-142x300.png 142w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.41.14-110x232.png 110w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.41.14-219x464.png 219w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.41.14-191x405.png 191w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.41.14-382x810.png 382w" sizes="auto, (max-width: 218px) 100vw, 218px" /></figure>



<figure class="wp-block-image size-large is-resized"><img loading="lazy" decoding="async" src="https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.41.47-486x1024.png" alt="" class="wp-image-2358" width="214" height="450" srcset="https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.41.47-486x1024.png 486w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.41.47-142x300.png 142w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.41.47-110x232.png 110w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.41.47-220x464.png 220w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.41.47-192x405.png 192w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.41.47-384x810.png 384w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.41.47.png 580w" sizes="auto, (max-width: 214px) 100vw, 214px" /><figcaption><em>Phone Booster, a MobOk malware that looks very pro</em><br><br></figcaption></figure>



<p class="wp-block-paragraph">There are several indications that this type of fraud initiated in Germany. First of all, the majority of negative comments are in German, furthermore the application communicates with the ium2.de domain and finally we have received attacks on German IPs. Other cases concern Asia, especially Thailand and Malaysia.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="645" src="https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.43.34-1024x645.png" alt="" class="wp-image-2360" srcset="https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.43.34-1024x645.png 1024w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.43.34-300x189.png 300w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.43.34-768x484.png 768w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.43.34-368x232.png 368w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.43.34-736x464.png 736w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.43.34-500x315.png 500w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.43.34-1000x630.png 1000w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.43.34.png 1082w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption><em>Google Play comments</em></figcaption></figure>



<div style="height:42px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph"><strong>DETECTION</strong></p>



<p class="wp-block-paragraph">Evina has created a honeypot that uses a network of 3G proxy SIM cards around the world to attract fraudulent activity. When we use SIMs in Germany, we have seen fraudulent subscriptions as a result of the MobOk application.</p>



<p class="wp-block-paragraph"><strong>MOBOK GENERATIONS</strong></p>



<p class="wp-block-paragraph">The malware family has evolved a way to load its fraudulent code to avoid detection by the Play Store. </p>



<p class="wp-block-paragraph"><strong><em>First generation</em></strong></p>



<p class="wp-block-paragraph">In the beginning, the malicious code was located directly in the application with only a simple obfuscation.</p>



<figure class="wp-block-image size-large is-resized"><img loading="lazy" decoding="async" src="https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.45.16.png" alt="" class="wp-image-2361" width="239" height="338" srcset="https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.45.16.png 470w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.45.16-212x300.png 212w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.45.16-164x232.png 164w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.45.16-327x464.png 327w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.45.16-286x405.png 286w" sizes="auto, (max-width: 239px) 100vw, 239px" /><figcaption><em>NService class contains the service to read SMS in notifications</em></figcaption></figure>



<div style="height:42px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph"><strong><em>Second generation</em></strong></p>



<p class="wp-block-paragraph">In the second generation of MobOk, the malware had an encrypted DEX file in the Assets folder that contained all the malicious code. The decrypted function was directly in the code.</p>



<div class="wp-block-image"><figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" src="https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.47.56.png" alt="" class="wp-image-2364" width="182" height="101"/><figcaption><em><em>Encrypted DEX file</em><br><br></em><br></figcaption></figure></div>



<div class="wp-block-image"><figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" src="https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.48.52.png" alt="" class="wp-image-2366" width="351" height="75" srcset="https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.48.52.png 542w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.48.52-300x64.png 300w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.48.52-500x107.png 500w" sizes="auto, (max-width: 351px) 100vw, 351px" /><figcaption><em>The filename after decrypted is renamed a22777.dex</em><br><br></figcaption></figure></div>



<p class="wp-block-paragraph"><strong><em>Third generation</em></strong></p>



<p class="wp-block-paragraph">Finally, MobOk uses the Bangcle packer, to hide all the files from the library and also has significant anti-reverse engineering protection.</p>



<div class="wp-block-image"><figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" src="https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.50.07.png" alt="" class="wp-image-2368" width="182" height="164" srcset="https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.50.07.png 398w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.50.07-300x270.png 300w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.50.07-258x232.png 258w" sizes="auto, (max-width: 182px) 100vw, 182px" /><figcaption><em>Phone Booster source is packed by Bangcle</em></figcaption></figure></div>



<div class="wp-block-image"><figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" src="https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.51.24.png" alt="" class="wp-image-2370" width="149" height="331" srcset="https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.51.24.png 320w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.51.24-135x300.png 135w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.51.24-105x232.png 105w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.51.24-209x464.png 209w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.51.24-183x405.png 183w" sizes="auto, (max-width: 149px) 100vw, 149px" /><figcaption><em>.. And then after we unpacked it</em><br><br></figcaption></figure></div>



<p class="wp-block-paragraph"><strong>FRAUD SCENARIO</strong></p>



<p class="wp-block-paragraph">During the attack, MobOk sends information from the affected phone to a C&amp;C (Command and Control) server whose domain is: <strong>ium2.de</strong>. The send request is encrypted by the application.</p>



<div class="wp-block-image"><figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" src="https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.52.21-1024x241.png" alt="" class="wp-image-2371" width="682" height="160" srcset="https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.52.21-1024x241.png 1024w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.52.21-300x70.png 300w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.52.21-768x180.png 768w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.52.21-988x232.png 988w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.52.21-500x117.png 500w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.52.21-1000x235.png 1000w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.52.21.png 1124w" sizes="auto, (max-width: 682px) 100vw, 682px" /><figcaption><em>Request to the command and control server ium2.de</em><br><br></figcaption></figure></div>



<p class="wp-block-paragraph">The server in response provides MobOk with the URLs and Javascript to execute in order to achieve this fraud. The response is also encrypted.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="916" height="788" src="https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.53.07.png" alt="" class="wp-image-2372" srcset="https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.53.07.png 916w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.53.07-300x258.png 300w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.53.07-768x661.png 768w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.53.07-270x232.png 270w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.53.07-539x464.png 539w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.53.07-471x405.png 471w" sizes="auto, (max-width: 916px) 100vw, 916px" /><figcaption><em>Server response decrypted</em></figcaption></figure>



<div style="height:42px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph">Then, MobOk turns off the WiFi to connect to the mobile network where it will be able to charge for the premium service.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="204" src="https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.54.04-1024x204.png" alt="" class="wp-image-2373" srcset="https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.54.04-1024x204.png 1024w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.54.04-300x60.png 300w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.54.04-768x153.png 768w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.54.04-500x99.png 500w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.54.04-1000x199.png 1000w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.54.04.png 1096w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption><em>Disable wifi network</em></figcaption></figure>



<div style="height:42px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph">Finally, the malware launches an invisible browser where it browses the URLs it has received and executes Javascript commands.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="511" src="https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.54.41-1024x511.png" alt="" class="wp-image-2374" srcset="https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.54.41-1024x511.png 1024w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.54.41-300x150.png 300w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.54.41-768x383.png 768w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.54.41-465x232.png 465w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.54.41-930x464.png 930w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.54.41-500x250.png 500w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.54.41-1000x499.png 1000w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.54.41.png 1110w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption><em>Load url and javascript in invisible webview</em></figcaption></figure>



<div style="height:42px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph"><strong>SUMMARY</strong></p>



<p class="wp-block-paragraph">MobOk is a family of malware that is constantly evolving to remain undetected by the Google Play Store. In its latest generation, and according to our sources, none of the malware in the family has been detected. It is quite likely that MobOk will spread to many other countries and, given the code, that it will extend its fraudulent activities.</p>



<p class="wp-block-paragraph"><strong>HOW TO PROTECT YOURSELF?</strong></p>



<p class="wp-block-paragraph">If you are an end-user, it is necessary to be careful with the applications you download. To limit the risk, we advise you:</p>



<ul class="wp-block-list"><li>To check the comments on the application page</li><li>To check the permissions (a wallpaper app does not need to have any specific phone permissions)</li><li>Avoid flashlight, scanner, wallpaper, SMS applications</li></ul>



<p class="wp-block-paragraph">If you are a service provider, such as a mobile carrier, payment gateway or content editor, you must use an independent anti-fraud solution expert in payment and mobile cybersecurity.&nbsp;</p>



<p class="wp-block-paragraph">Evina guarantees end-users safety and ensures a sustainable growth of the German mobile payment market, collaborating with local carriers such as Mobilcom-Debitel and T-Mobile.</p>



<p class="wp-block-paragraph"><strong>APPS</strong></p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="893" height="1024" src="https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.56.28-893x1024.png" alt="" class="wp-image-2375" srcset="https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.56.28-893x1024.png 893w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.56.28-262x300.png 262w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.56.28-768x881.png 768w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.56.28-202x232.png 202w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.56.28-405x464.png 405w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.56.28-353x405.png 353w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.56.28-706x810.png 706w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.56.28.png 1062w" sizes="auto, (max-width: 893px) 100vw, 893px" /></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="83" src="https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.56.50-1024x83.png" alt="" class="wp-image-2376" srcset="https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.56.50-1024x83.png 1024w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.56.50-300x24.png 300w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.56.50-768x62.png 768w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.56.50-500x40.png 500w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.56.50-1000x81.png 1000w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.56.50.png 1062w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="704" height="930" src="https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.57.16.png" alt="" class="wp-image-2377" srcset="https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.57.16.png 704w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.57.16-227x300.png 227w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.57.16-176x232.png 176w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.57.16-351x464.png 351w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.57.16-307x405.png 307w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.57.16-613x810.png 613w" sizes="auto, (max-width: 704px) 100vw, 704px" /></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="708" height="970" src="https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.58.51.png" alt="" class="wp-image-2380" srcset="https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.58.51.png 708w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.58.51-219x300.png 219w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.58.51-169x232.png 169w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.58.51-339x464.png 339w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.58.51-296x405.png 296w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.58.51-591x810.png 591w" sizes="auto, (max-width: 708px) 100vw, 708px" /></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="79" src="https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.59.19-1024x79.png" alt="" class="wp-image-2381" srcset="https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.59.19-1024x79.png 1024w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.59.19-300x23.png 300w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.59.19-768x59.png 768w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.59.19-500x39.png 500w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.59.19-1000x77.png 1000w, https://www.evina.com/wp-content/uploads/2021/01/Screenshot-2021-01-06-at-11.59.19.png 1062w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>
<p>The post <a href="https://www.evina.com/evina-protects-end-users-from-mobok-an-incessantly-mutating-malware-family-in-germany/">Evina protects end users from MobOk: an incessantly mutating malware family in Germany</a> appeared first on <a href="https://www.evina.com">Evina</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.evina.com/evina-protects-end-users-from-mobok-an-incessantly-mutating-malware-family-in-germany/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Google Recaptcha is not an anti-fraud solution.</title>
		<link>https://www.evina.com/google-recaptcha-is-not-an-anti-fraud-solution/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=google-recaptcha-is-not-an-anti-fraud-solution</link>
					<comments>https://www.evina.com/google-recaptcha-is-not-an-anti-fraud-solution/#respond</comments>
		
		<dc:creator><![CDATA[Vanessa Palladino]]></dc:creator>
		<pubDate>Tue, 10 Mar 2020 18:40:00 +0000</pubDate>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<guid isPermaLink="false">https://www.evina.com/?p=1715</guid>

					<description><![CDATA[<p>Google reCAPTCHA puts end users in double jeopardy: </p>
<p>The post <a href="https://www.evina.com/google-recaptcha-is-not-an-anti-fraud-solution/">Google Recaptcha is not an anti-fraud solution.</a> appeared first on <a href="https://www.evina.com">Evina</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<ol class="wp-block-list"><li>It exposes users to fraud</li><li>It prevents them from purchasing what they want</li></ol>



<p class="wp-block-paragraph">Google reCaptcha is the CAPTCHA solution offered by Google, which we have all already seen before:</p>



<figure class="wp-block-image size-large is-resized"><img loading="lazy" decoding="async" src="https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.38.11.png" alt="" class="wp-image-1718" width="160" height="233" srcset="https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.38.11.png 399w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.38.11-206x300.png 206w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.38.11-159x232.png 159w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.38.11-319x464.png 319w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.38.11-278x405.png 278w" sizes="auto, (max-width: 160px) 100vw, 160px" /></figure>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">Google recently created a third version, and it doesn’t work better.&nbsp;<br></p>



<p class="wp-block-paragraph">1- Google reCAPTCHA exposes end users to fraud</p>



<p class="wp-block-paragraph">Since 2012, hacking Google reCAPTCHA has become a national sport:&nbsp;</p>



<ul class="wp-block-list"><li><a href="https://arstechnica.com/information-technology/2012/05/google-recaptcha-brought-to-its-knees/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/information-technology/2012/05/google-recaptcha-brought-to-its-knees/</a></li><li><a href="https://threatpost.com/google-recaptcha-bypass-technique-uses-googles-own-tools/124006/" target="_blank" rel="noreferrer noopener">https://threatpost.com/google-recaptcha-bypass-technique-uses-googles-own-tools/124006/</a></li><li><a href="https://www.wired.co.uk/article/google-captcha-recaptcha" target="_blank" rel="noreferrer noopener">https://www.wired.co.uk/article/google-captcha-recaptcha&nbsp;</a></li></ul>



<p class="wp-block-paragraph">On the dark web, fraudsters resell kits to bypass Google reCAPTCHA industrially. On the web, it costs 1,5$ per 1000 Google reCAPTCHA hacked: <a href="https://anti-captcha.com/mainpage" target="_blank" rel="noreferrer noopener">https://anti-captcha.com/mainpage</a></p>



<p class="wp-block-paragraph">Abdelaziz Khaled, Cyber Security Analyst at EVINA: “These tools are easy to download and set up. We find them everywhere. When we reverse-engineer a malware, as we did with <a href="https://www.evina.com/evina-protects-end-users-mobok-a-malware-family-in-constant-evolution-that-perpetrates-mobile-fraud-in-germany/" target="_blank" rel="noreferrer noopener">MOBOK Malware,</a> it involves a part of coding dedicated to bypassing Google reCAPTCHA” (picture below).</p>



<figure class="wp-block-image size-large is-resized"><img loading="lazy" decoding="async" src="https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.39.16.png" alt="" class="wp-image-1719" width="400" height="111" srcset="https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.39.16.png 913w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.39.16-300x83.png 300w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.39.16-768x214.png 768w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.39.16-834x232.png 834w, https://www.evina.com/wp-content/uploads/2020/12/Screenshot-2020-12-17-at-19.39.16-500x139.png 500w" sizes="auto, (max-width: 400px) 100vw, 400px" /></figure>



<p class="wp-block-paragraph">2- It prevents customers from purchasing what they want</p>



<p class="wp-block-paragraph">Indeed, Google reCAPTCHA v3 generates false positives.</p>



<p class="wp-block-paragraph">Wesley Hendriks, Head of Data Team at Sam Media: “We have tested Google reCAPTCHA v3 and compared the results with other anti-fraud solutions.&nbsp; We noticed that around 50% of legitimate traffic, according to other anti-fraud solutions, received the lowest scores &#8211; ’10’ or ‘30’-&nbsp; from Google reCAPTCHA V3.”</p>



<p class="wp-block-paragraph">Since the product is free, Google offers very little support and understanding of the data collected. Google provides clients with a score between 0.0 and 1.0 for them to determine which transaction to block. Yet support and thorough analysis are key to fight fraud the right way.</p>



<p class="wp-block-paragraph">Fabienne Huygens, Product Owner at CM.com: “When it comes to an anti-fraud solution, support is essential. The team at Evina is proactive and supports our teams on a daily basis to fight against fraud.”</p>



<p class="wp-block-paragraph">Franck Semanne, Head of Carrier Billing at Bouygues Telecom: “In terms of anti-fraud solutions, we can’t rely on an average score to let us decide what we consider as a fraud. An anti-fraud solution must detect and precisely define a fraudulent attempt, and this is what we appreciate with Evina.”</p>



<p class="wp-block-paragraph">Our team is at your disposal to provide you with effective tools to combat fraud, and to help your partners understand that Google reCAPTCHA is not an optimal anti-fraud solution.</p>
<p>The post <a href="https://www.evina.com/google-recaptcha-is-not-an-anti-fraud-solution/">Google Recaptcha is not an anti-fraud solution.</a> appeared first on <a href="https://www.evina.com">Evina</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.evina.com/google-recaptcha-is-not-an-anti-fraud-solution/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Ad fraud: a troll lives in a one million install game</title>
		<link>https://www.evina.com/ad-fraud-a-troll-lives-in-a-one-million-install-game-eng/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=ad-fraud-a-troll-lives-in-a-one-million-install-game-eng</link>
					<comments>https://www.evina.com/ad-fraud-a-troll-lives-in-a-one-million-install-game-eng/#respond</comments>
		
		<dc:creator><![CDATA[Vanessa Palladino]]></dc:creator>
		<pubDate>Tue, 10 Mar 2020 15:54:00 +0000</pubDate>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<guid isPermaLink="false">https://www.evina.com/?p=4618</guid>

					<description><![CDATA[<p>Evina has been observing a new malicious SDK on Google Play Store. So far, we have detected it in 3 applications, displayed since December 2019,  including a game that has been installed more than a million times: Parkour Roller.</p>
<p>The post <a href="https://www.evina.com/ad-fraud-a-troll-lives-in-a-one-million-install-game-eng/">Ad fraud: a troll lives in a one million install game</a> appeared first on <a href="https://www.evina.com">Evina</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">The malicious SDK — going by the name Troll (the class name which execute the fraud) —&nbsp; simulates the interaction with advertisements, collects information and subscribes to premium services without the user noticing: the browser is invisible during the fraud.</p>



<p class="wp-block-paragraph">Our customers are safe from this malware thanks to Evina’s protection.&nbsp;</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="220" height="445" src="https://www.evina.com/wp-content/uploads/2021/07/AdFraudTroll1.png" alt="" class="wp-image-4619" srcset="https://www.evina.com/wp-content/uploads/2021/07/AdFraudTroll1.png 220w, https://www.evina.com/wp-content/uploads/2021/07/AdFraudTroll1-148x300.png 148w, https://www.evina.com/wp-content/uploads/2021/07/AdFraudTroll1-115x232.png 115w, https://www.evina.com/wp-content/uploads/2021/07/AdFraudTroll1-200x405.png 200w" sizes="auto, (max-width: 220px) 100vw, 220px" /><figcaption>Parkour Roller Screenshots</figcaption></figure>



<p class="wp-block-paragraph">In order to charge for services the Troll SDK disables the WIFI, which draw user’s attention and bring them to give a bad rate on Google Play Store. To get around the problem, bots located in Thailand raise the average rating posting numerous 5-stars comments.</p>



<p class="wp-block-paragraph">It seems the fraud is global with comments in Asia (Indian and Thai). Regarding Europe, the app is well-ranked in Austria, Italy and Spain.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="491" height="256" src="https://www.evina.com/wp-content/uploads/2021/07/AdFraudTroll2.png" alt="" class="wp-image-4620" srcset="https://www.evina.com/wp-content/uploads/2021/07/AdFraudTroll2.png 491w, https://www.evina.com/wp-content/uploads/2021/07/AdFraudTroll2-300x156.png 300w, https://www.evina.com/wp-content/uploads/2021/07/AdFraudTroll2-445x232.png 445w" sizes="auto, (max-width: 491px) 100vw, 491px" /><figcaption>Google Play global rating history of the app</figcaption></figure>



<p class="wp-block-paragraph">FUNCTIONALITY</p>



<p class="wp-block-paragraph">After installation, the Troll SDK waits several launches of the app before being executed and sending information to register to the Command &amp; Control server hihotdog.com.</p>



<p class="wp-block-paragraph">In return, the server responds with parameters including the phone_id which is used to query the server that will retrieve fraudulent offers. We also find information to execute the frauds like the time interval between each fraud.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="339" height="341" src="https://www.evina.com/wp-content/uploads/2021/07/AdFraudTroll3.png" alt="" class="wp-image-4621" srcset="https://www.evina.com/wp-content/uploads/2021/07/AdFraudTroll3.png 339w, https://www.evina.com/wp-content/uploads/2021/07/AdFraudTroll3-298x300.png 298w, https://www.evina.com/wp-content/uploads/2021/07/AdFraudTroll3-150x150.png 150w, https://www.evina.com/wp-content/uploads/2021/07/AdFraudTroll3-231x232.png 231w, https://www.evina.com/wp-content/uploads/2021/07/AdFraudTroll3-80x80.png 80w" sizes="auto, (max-width: 339px) 100vw, 339px" /><figcaption>Server response</figcaption></figure>



<p class="wp-block-paragraph">Then, the Troll SDK executes the function doBiz, and next it queries the server to retrieve the fraudulent offers and disables the WIFI to go to the operator’s network.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="906" height="439" src="https://www.evina.com/wp-content/uploads/2021/07/AdFraudTroll4.png" alt="" class="wp-image-4622" srcset="https://www.evina.com/wp-content/uploads/2021/07/AdFraudTroll4.png 906w, https://www.evina.com/wp-content/uploads/2021/07/AdFraudTroll4-300x145.png 300w, https://www.evina.com/wp-content/uploads/2021/07/AdFraudTroll4-768x372.png 768w, https://www.evina.com/wp-content/uploads/2021/07/AdFraudTroll4-479x232.png 479w, https://www.evina.com/wp-content/uploads/2021/07/AdFraudTroll4-500x242.png 500w" sizes="auto, (max-width: 906px) 100vw, 906px" /><figcaption>Troll SDK gets fraudulent jobs</figcaption></figure>



<p class="wp-block-paragraph">Finally, the Troll SDK executes the urls and javascript contained in the server response.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="847" height="535" src="https://www.evina.com/wp-content/uploads/2021/07/AdFraudTroll5.png" alt="" class="wp-image-4624" srcset="https://www.evina.com/wp-content/uploads/2021/07/AdFraudTroll5.png 847w, https://www.evina.com/wp-content/uploads/2021/07/AdFraudTroll5-300x189.png 300w, https://www.evina.com/wp-content/uploads/2021/07/AdFraudTroll5-768x485.png 768w, https://www.evina.com/wp-content/uploads/2021/07/AdFraudTroll5-367x232.png 367w, https://www.evina.com/wp-content/uploads/2021/07/AdFraudTroll5-735x464.png 735w, https://www.evina.com/wp-content/uploads/2021/07/AdFraudTroll5-500x316.png 500w" sizes="auto, (max-width: 847px) 100vw, 847px" /><figcaption>Troll SDK executes javascript</figcaption></figure>



<p class="wp-block-paragraph">It is common to find offended code or fraudulent files that are downloaded after installation in frauds to fool users. But this new fraudulent SDK does not hide, it uses a rather explicit name “Troll” and method names like “doBiz” …</p>



<p class="wp-block-paragraph">It is surprising to see that the application has not been removed yet while there is no will to hide the fraud, especially since it has been installed a million times.</p>



<p class="wp-block-paragraph">It is therefore necessary to be careful with the applications you download, to limit the risk we advise you:</p>



<p class="wp-block-paragraph">To check the comments on the application page</p>



<p class="wp-block-paragraph">To check the permissions (a wallpaper app don’t need to have phone permissions)</p>



<p class="wp-block-paragraph">Avoid flashlight, scanner, wallpaper applications</p>



<p class="wp-block-paragraph">We have reported the concerned apps to Google.&nbsp;</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="737" height="160" src="https://www.evina.com/wp-content/uploads/2021/07/AdFraudTroll6.png" alt="" class="wp-image-4623" srcset="https://www.evina.com/wp-content/uploads/2021/07/AdFraudTroll6.png 737w, https://www.evina.com/wp-content/uploads/2021/07/AdFraudTroll6-300x65.png 300w, https://www.evina.com/wp-content/uploads/2021/07/AdFraudTroll6-500x109.png 500w" sizes="auto, (max-width: 737px) 100vw, 737px" /><figcaption>Applications</figcaption></figure>
<p>The post <a href="https://www.evina.com/ad-fraud-a-troll-lives-in-a-one-million-install-game-eng/">Ad fraud: a troll lives in a one million install game</a> appeared first on <a href="https://www.evina.com">Evina</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.evina.com/ad-fraud-a-troll-lives-in-a-one-million-install-game-eng/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Malware rises to the top applications in the Google Play store</title>
		<link>https://www.evina.com/malware-rises-to-the-top-applications-in-the-google-play-store/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=malware-rises-to-the-top-applications-in-the-google-play-store</link>
					<comments>https://www.evina.com/malware-rises-to-the-top-applications-in-the-google-play-store/#respond</comments>
		
		<dc:creator><![CDATA[Vanessa Palladino]]></dc:creator>
		<pubDate>Thu, 09 Jan 2020 17:09:00 +0000</pubDate>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<guid isPermaLink="false">https://www.evina.com/?p=4629</guid>

					<description><![CDATA[<p>Evina found malware in the Google Play Store’s top application rankings called “Stars Wallpapers.”</p>
<p>The post <a href="https://www.evina.com/malware-rises-to-the-top-applications-in-the-google-play-store/">Malware rises to the top applications in the Google Play store</a> appeared first on <a href="https://www.evina.com">Evina</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">This malware is able to simulate real human behavior and take several actions like clicking on ad banners or subscribing to paying services. It is also able to activate/deactivate wifi and send/read SMS on the device.</p>



<p class="wp-block-paragraph">Users complaint on the app Play Store page: content was disappointing, and some users have been subscribed to paid services without their consent. We also were able to confirm that EVINA DCBprotect blocked this malware since its very beginning. Companies protected by our solution have not been impacted by this fraud.</p>



<p class="wp-block-paragraph">Since last weekend the application is ranked in the top free applications in France, Germany, Italy, Spain and in the Netherlands.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="322" height="540" src="https://www.evina.com/wp-content/uploads/2021/07/TopMalware1.png" alt="" class="wp-image-4630" srcset="https://www.evina.com/wp-content/uploads/2021/07/TopMalware1.png 322w, https://www.evina.com/wp-content/uploads/2021/07/TopMalware1-179x300.png 179w, https://www.evina.com/wp-content/uploads/2021/07/TopMalware1-138x232.png 138w, https://www.evina.com/wp-content/uploads/2021/07/TopMalware1-277x464.png 277w, https://www.evina.com/wp-content/uploads/2021/07/TopMalware1-242x405.png 242w" sizes="auto, (max-width: 322px) 100vw, 322px" /></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="768" height="678" src="https://www.evina.com/wp-content/uploads/2021/07/TopMalware2-Google-Play-Store-Ranking-Source-AppBrain.png" alt="" class="wp-image-4631" srcset="https://www.evina.com/wp-content/uploads/2021/07/TopMalware2-Google-Play-Store-Ranking-Source-AppBrain.png 768w, https://www.evina.com/wp-content/uploads/2021/07/TopMalware2-Google-Play-Store-Ranking-Source-AppBrain-300x265.png 300w, https://www.evina.com/wp-content/uploads/2021/07/TopMalware2-Google-Play-Store-Ranking-Source-AppBrain-263x232.png 263w, https://www.evina.com/wp-content/uploads/2021/07/TopMalware2-Google-Play-Store-Ranking-Source-AppBrain-526x464.png 526w, https://www.evina.com/wp-content/uploads/2021/07/TopMalware2-Google-Play-Store-Ranking-Source-AppBrain-459x405.png 459w" sizes="auto, (max-width: 768px) 100vw, 768px" /><figcaption>Google Play Store Ranking (Source AppBrain)</figcaption></figure>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">“Stars Wallpapers” has been downloaded more than 100,000 times in three days between January 2nd and January 5th.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="647" height="281" src="https://www.evina.com/wp-content/uploads/2021/07/Topmalware3.png" alt="" class="wp-image-4632" srcset="https://www.evina.com/wp-content/uploads/2021/07/Topmalware3.png 647w, https://www.evina.com/wp-content/uploads/2021/07/Topmalware3-300x130.png 300w, https://www.evina.com/wp-content/uploads/2021/07/Topmalware3-534x232.png 534w, https://www.evina.com/wp-content/uploads/2021/07/Topmalware3-500x217.png 500w" sizes="auto, (max-width: 647px) 100vw, 647px" /><figcaption>Number of installations (Source AppBrain)</figcaption></figure>



<p class="wp-block-paragraph">How did we find it?</p>



<p class="wp-block-paragraph">Evina uses its own global proxies network to catch frauds. We noticed an unusual behavior of few of them (data consumption higher than expected, bill invoiced for premium service). When noticing this kind of behavior, we dug on history and found where it came from: an application called “Stars Wallpapers.”</p>



<p class="wp-block-paragraph">During the application’s analysis, we spotted that a piece of code of the application was missing even though it was declared.</p>



<p class="wp-block-paragraph">We quickly realized that a library inside the application loads the fraudulent code. It creates two encrypted Dex files and deletes one of them as soon as it has been created and then loads it into the memory.</p>



<p class="wp-block-paragraph">This method prevents detection by Google Play Store because the malicious code is not directly in the application.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="487" height="150" src="https://www.evina.com/wp-content/uploads/2021/07/Topmalware4.png" alt="" class="wp-image-4633" srcset="https://www.evina.com/wp-content/uploads/2021/07/Topmalware4.png 487w, https://www.evina.com/wp-content/uploads/2021/07/Topmalware4-300x92.png 300w" sizes="auto, (max-width: 487px) 100vw, 487px" /><figcaption>The application loads the library at start</figcaption></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="939" height="264" src="https://www.evina.com/wp-content/uploads/2021/07/Topmalware5.png" alt="" class="wp-image-4634" srcset="https://www.evina.com/wp-content/uploads/2021/07/Topmalware5.png 939w, https://www.evina.com/wp-content/uploads/2021/07/Topmalware5-300x84.png 300w, https://www.evina.com/wp-content/uploads/2021/07/Topmalware5-768x216.png 768w, https://www.evina.com/wp-content/uploads/2021/07/Topmalware5-825x232.png 825w, https://www.evina.com/wp-content/uploads/2021/07/Topmalware5-500x141.png 500w" sizes="auto, (max-width: 939px) 100vw, 939px" /><figcaption>Stack view of libkf.so library</figcaption></figure>



<p class="wp-block-paragraph">First of all, the malware creates an invisible window to track the user’s behavior and trigger the fraud at the right time.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="939" height="420" src="https://www.evina.com/wp-content/uploads/2021/07/Topmalware6.png" alt="" class="wp-image-4635" srcset="https://www.evina.com/wp-content/uploads/2021/07/Topmalware6.png 939w, https://www.evina.com/wp-content/uploads/2021/07/Topmalware6-300x134.png 300w, https://www.evina.com/wp-content/uploads/2021/07/Topmalware6-768x344.png 768w, https://www.evina.com/wp-content/uploads/2021/07/Topmalware6-519x232.png 519w, https://www.evina.com/wp-content/uploads/2021/07/Topmalware6-500x224.png 500w" sizes="auto, (max-width: 939px) 100vw, 939px" /><figcaption>Sample code of Stars Wallpapers malware</figcaption></figure>



<p class="wp-block-paragraph">During this time, the application receives and writes instructions in streaming with a server on the faymobi.com domain on port 9091 (which helps to hide these exchanges).</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="939" height="91" src="https://www.evina.com/wp-content/uploads/2021/07/Topmalware7.png" alt="" class="wp-image-4636" srcset="https://www.evina.com/wp-content/uploads/2021/07/Topmalware7.png 939w, https://www.evina.com/wp-content/uploads/2021/07/Topmalware7-300x29.png 300w, https://www.evina.com/wp-content/uploads/2021/07/Topmalware7-768x74.png 768w, https://www.evina.com/wp-content/uploads/2021/07/Topmalware7-500x48.png 500w" sizes="auto, (max-width: 939px) 100vw, 939px" /></figure>



<p class="wp-block-paragraph">Fraud instructions are stored in the application’s shared preferences. It contains encrypted information about the javascript actions to execute but also the information whether you have to send a sms or if you have to pass a captcha during the journey.</p>



<p class="wp-block-paragraph">It also includes the time interval between each attack and the maximum number of attacks per day.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="831" height="245" src="https://www.evina.com/wp-content/uploads/2021/07/Topmalware8.png" alt="" class="wp-image-4637" srcset="https://www.evina.com/wp-content/uploads/2021/07/Topmalware8.png 831w, https://www.evina.com/wp-content/uploads/2021/07/Topmalware8-300x88.png 300w, https://www.evina.com/wp-content/uploads/2021/07/Topmalware8-768x226.png 768w, https://www.evina.com/wp-content/uploads/2021/07/Topmalware8-787x232.png 787w, https://www.evina.com/wp-content/uploads/2021/07/Topmalware8-500x147.png 500w" sizes="auto, (max-width: 831px) 100vw, 831px" /><figcaption>Encrypted fraud instructions in shared_prefs folder</figcaption></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="666" height="437" src="https://www.evina.com/wp-content/uploads/2021/07/Topmalware9.png" alt="" class="wp-image-4638" srcset="https://www.evina.com/wp-content/uploads/2021/07/Topmalware9.png 666w, https://www.evina.com/wp-content/uploads/2021/07/Topmalware9-300x197.png 300w, https://www.evina.com/wp-content/uploads/2021/07/Topmalware9-354x232.png 354w, https://www.evina.com/wp-content/uploads/2021/07/Topmalware9-500x328.png 500w" sizes="auto, (max-width: 666px) 100vw, 666px" /><figcaption>Scan the captcha and send to an API to get the result</figcaption></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="989" height="414" src="https://www.evina.com/wp-content/uploads/2021/07/Topmalware10.png" alt="" class="wp-image-4639" srcset="https://www.evina.com/wp-content/uploads/2021/07/Topmalware10.png 989w, https://www.evina.com/wp-content/uploads/2021/07/Topmalware10-300x126.png 300w, https://www.evina.com/wp-content/uploads/2021/07/Topmalware10-768x321.png 768w, https://www.evina.com/wp-content/uploads/2021/07/Topmalware10-554x232.png 554w, https://www.evina.com/wp-content/uploads/2021/07/Topmalware10-500x209.png 500w" sizes="auto, (max-width: 989px) 100vw, 989px" /><figcaption>Check to see if a new SMS is received</figcaption></figure>



<p class="wp-block-paragraph">At the right time, the malware disables the wifi to be on the mobile network and launches an invisible browser, it executes all the actions of the file in the shared_prefs which thus subscribes to a premium service.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="939" height="281" src="https://www.evina.com/wp-content/uploads/2021/07/Topmalware11.png" alt="" class="wp-image-4640" srcset="https://www.evina.com/wp-content/uploads/2021/07/Topmalware11.png 939w, https://www.evina.com/wp-content/uploads/2021/07/Topmalware11-300x90.png 300w, https://www.evina.com/wp-content/uploads/2021/07/Topmalware11-768x230.png 768w, https://www.evina.com/wp-content/uploads/2021/07/Topmalware11-775x232.png 775w, https://www.evina.com/wp-content/uploads/2021/07/Topmalware11-500x150.png 500w" sizes="auto, (max-width: 939px) 100vw, 939px" /><figcaption>Disable wifi</figcaption></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="924" height="662" src="https://www.evina.com/wp-content/uploads/2021/07/Topmalware12.png" alt="" class="wp-image-4641" srcset="https://www.evina.com/wp-content/uploads/2021/07/Topmalware12.png 924w, https://www.evina.com/wp-content/uploads/2021/07/Topmalware12-300x215.png 300w, https://www.evina.com/wp-content/uploads/2021/07/Topmalware12-768x550.png 768w, https://www.evina.com/wp-content/uploads/2021/07/Topmalware12-324x232.png 324w, https://www.evina.com/wp-content/uploads/2021/07/Topmalware12-648x464.png 648w, https://www.evina.com/wp-content/uploads/2021/07/Topmalware12-500x358.png 500w" sizes="auto, (max-width: 924px) 100vw, 924px" /><figcaption>Launch Webview</figcaption></figure>



<p class="wp-block-paragraph">It is common to say that malware hides in unofficial store or is not very visible and contains suspicious permissions.</p>



<p class="wp-block-paragraph">That’s why Stars Wallpapers is dangerous because it doesn’t ask for any suspicious permissions, the content of the application looks professional and above all it is very well-ranked on Google Play Store.</p>



<p class="wp-block-paragraph">Fortunately, victims of this malware were able to comment or rate this application to warn of its dangerousness, which stopped its number of installations but not its ranking.</p>



<p class="wp-block-paragraph">It is therefore necessary to be careful with the applications you download, to limit the risk we advise you:</p>



<p class="wp-block-paragraph">To check the comments on the application page</p>



<p class="wp-block-paragraph">To check the permissions (a wallpaper app don’t need to have phone permissions)</p>
<p>The post <a href="https://www.evina.com/malware-rises-to-the-top-applications-in-the-google-play-store/">Malware rises to the top applications in the Google Play store</a> appeared first on <a href="https://www.evina.com">Evina</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.evina.com/malware-rises-to-the-top-applications-in-the-google-play-store/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
