MobileNews

Iranian hackers’ Android malware spies on dissidents by stealing 2FA codes

It’s no secret that some countries have spied on their citizens through innocuous-looking apps, but one effort is more extensive than usual. Check Point Research has discovered (via ZDNet) that Rampant Kitten, an Iranian hacker group that has targeted the country’s political opponents for years, has developed Android malware focused on stealing two-factor authentication codes. It isn’t just focused on any one service, either — it targets Google, Telegram, and other major internet or social services.

The attackers first use a phishing trojan to collect login details, and then try those with the real site. If the victim has two-factor authentication turned on, the newly-reported malware intercepts the incoming SMS messages and quietly sends copies to the intruders.

The code also has tools to grab contacts, text message logs and even microphone audio, but it’s unusually centered around two-factor data. It has so far been found in an app pretending to help Persian speakers in Sweden get driver’s licenses, but it might be available in other apps.

This is an important discovery. Although it’s no secret that likely state-backed groups can get around two-factor requests, it’s difficult to see how those systems work. It also stresses the importance of using two-authentication systems that avoid SMS, such as hardware security keys. SMS is better than nothing, but it’s no longer a deterrent for the most determined intruders — whether they’re pro-government spies or everyday criminals.

Check out the latest Samsung phones at great prices from Gizmofashion – our recommended retail partner.


Author: Jon Fingas, @jonfingas

Source: Engadget

Related posts
GamingNews

Professor Layton and the New World of Steam Adds PC and PS5 Release to 2026 Global Simultaneous Launch — but There’s No Xbox Version

GamingNews

The Lord of the Rings and The Boys Star Karl Urban Throws His Hat in the Ring for Potential Red Dead Redemption Movie — and He Knows Exactly Who He Wants to Play

GamingNews

'We Actually Didn't Nerf Tracer's Butt' — 10 Years On, Former Overwatch Boss is Still Being Asked About That Pose Change

CryptoNews

Crypto ETFs Turn Red: Bitcoin Loses $159 Million, Ether Drops $64 Million

Sign up for our Newsletter and
stay informed!