Tag

Lemon Group

All articles tagged with #lemon group

cybersecurity2 years ago

Guerilla Malware Infects Millions of Android Devices, Google Play Store Users Warned.

The Lemon Group has pre-infected over 8.9 million Android devices worldwide with Guerilla malware, including smartphones, watches, and televisions. The malware can infiltrate a number of Android tools, including swiping passwords, intercepting one-time passwords, and interrupting messaging as well as other apps. The Lemon Group is after massive amounts of data from shipments to advertising content. The malware can also infiltrate users’ social media accounts, including WhatsApp, as well as compromise the Splash Plugin with intrusive advertisements. Trend Micro is concerned it could even affect cars.

cybersecurity2 years ago

Millions of Android Devices Pre-Infected with Malware by Cybercrime Gang

The Lemon Group, a cybercrime gang, has pre-installed malware known as 'Guerilla' on almost 9 million Android-based devices, including smartphones, watches, TVs, and TV boxes. The malware is used to load additional payloads, intercept one-time passwords from SMS, set up a reverse proxy, hijack WhatsApp sessions, and more. The group's infrastructure overlaps with the Triada trojan operation from 2016. The malware is implanted through supply chain attacks, compromised third-party software, a compromised firmware update process, or enlisting insiders on the product manufacturing or distribution chain. The group has a diverse monetization strategy that includes selling compromised accounts, hijacking network resources, offering app-installation services, generating fraudulent ad impressions, offering proxy services, and SMS Phone Verified Accounts (PVA) services. The countries most significantly impacted include the United States, Mexico, Indonesia, Thailand, and Russia.

cybersecurity2 years ago

"Massive Cybercrime Scheme Pre-Installs Malware on Millions of Android Devices Worldwide"

Cybercrime syndicate Lemon Group has pre-infected over 8.9 million Android smartphones worldwide, turning them into mobile proxies for stealing and selling SMS messages, social media and online messaging accounts, and monetization via advertisements and click fraud. The majority of the infections were discovered in the US, Mexico, Indonesia, Thailand, Russia, South Africa, India, Angola, the Philippines, and Argentina. The malware strain called Guerilla has infected over 50 brands of mobile devices and is continuously evolving, with the threat actors branching out to other Android-based IoT devices.