惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 三生石上(FineUI控件)
D
DataBreaches.Net
博客园_首页
J
Java Code Geeks
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
罗磊的独立博客
腾讯CDC
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
B
Blog
D
Docker
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
A
About on SuperTechFans
博客园 - 聂微东
Stack Overflow Blog
Stack Overflow Blog
WordPress大学
WordPress大学
MyScale Blog
MyScale Blog
G
Google Developers Blog
博客园 - 司徒正美
aimingoo的专栏
aimingoo的专栏
小众软件
小众软件
Apple Machine Learning Research
Apple Machine Learning Research
博客园 - 叶小钗
M
MIT News - Artificial intelligence
Recent Announcements
Recent Announcements

Threat Walkthroughs – ThreatDown by Malwarebytes

Fake Booking.com emails target hotels Phishers go “interplanetary” to get company login credentials “Enhanced Bonus” QR code phish steals Microsoft credentials USB worms: Still wriggling on to under-protected computers after all these years Analyzing a Mispadu Trojan’s attack chain How a clipboard hijacker delivers Lumma Stealer - ThreatDown by Malwarebytes Web shop spreads SocGolish malware and steals credit cards Clipboard hijacker tries to install a Trojan A visit to a print shop put a password stealer on a co-worker’s laptop
Watch out! Mobidash Android adware spread through phishin...
Pieter Arntz · 2024-09-30 · via Threat Walkthroughs – ThreatDown by Malwarebytes
Android

ThreatDown has uncovered a new campaign spreading the MobiDash adware for Android.

Someone is trying very hard to infect your Android device with malicious adware.

ThreatDown’s Android experts recently became aware of a campaign spreading MobiDash adware for Android using phishing emails, links on social media posted by people or bots, and at least one pornography website (xnxxvideosporn[.]net).

Android/Adware.MobiDash is Malwarebytes’ detection name for an adware that targets mobile devices running the Android OS, which became prevalent in 2015 and continues to be spread via hundreds of variants. It comes in the form of a Software Development Kit (SDK), a pre-packaged set of tools that can be added easily onto any Android Application Package (APK), the format used to distribute Android apps.

It is common for nefarious actors to take legitimate APKs and repackage them with adware SDKs so that besides the game, mod, movie, or whatever app they were promised, unsuspecting users are also infected with the MobiDash adware, and any other malware that MobiDash is used to install.

A unique characteristic of MobiDash is that it can wait up to three days after being installed before it starts to display ads. From then on, infected devices will display ads until the app is uninstalled. Since the MobiDash SDK is attached to a legitimate APK that will continue to work as expected, the victim may be left wondering where the advertisements are coming from, and won’t know which app to uninstall.

Mobidash link on Facebook
Link as posted on Facebook

In the recent campaign, users who clicked the Facebook link in the screenshot above were sent through a chain of redirects (lookebonyhill.com > apkretro.com > 3-dl-app.com) that ends in the automatic download of an APK file, although some users will have to use the Download button.

download of another apk than expected
Download of the APK

ThreatDown and Malwarebytes block the start of the redirect chain and can detect and remove MobiDash from your device.

Malwarebytes blocks lookebonyhill[.]com
Malwarebytes blocks lookebonyhill[.]com

IOCs

lookebonyhill[.]com

cinepornogratis[.]com

mobileoffers-ek-download[.]com

apkdw[.]online

mobileoffers-et-download[.]com