started · updated
Android malware campaigns target users via social media and phone scams
Security researchers have identified two distinct but highly effective Android malware campaigns targeting users through social media and social engineering.
One campaign involves the StreamRat malware, which spreads via paid advertisements on platforms such as Facebook, Instagram, and TikTok. These ads often promise free streaming services to lure users to malicious websites. Once a user installs the application and grants Accessibility Services permissions, the malware can monitor the screen, steal login credentials, and allow attackers to control the device remotely. One Meta-related campaign reportedly reached approximately 570,000 users.
A second threat involves the WindTapper group, which uses a combination of phone scams and the WindRelay malware. Attackers pose as bank employees to convince victims to install malicious software under the guise of a security check. This malware enables an NFC relay attack, allowing criminals to intercept communication between a victim's contactless payment card and their phone. This allows attackers to facilitate unauthorized payments in real-time without ever physically possessing the victim's card.
Entities
ComSource · Meta · ThreatFabric · WindRelay · WindTapper