Big Android Botnet Sends SMS Messages To China

One of the biggest Android botnets ever has been stealing text messages and sending them to servers in China, according to security company FireEye.

Researchers uncovered 64 Android botnet campaigns belonging to the MisoSMS malware family, which appeared to victims to be a genuine Android settings application called “Google Vx”.

Most victims were in South Korea, with the attackers picking up messages within the country and in China. The attackers have used more than 450 unique malicious email accounts for the attacks.

Android botnet attacks

FireEye said it had worked with law enforcement and a Chinese email provider to take those email accounts offline, disrupting the botnet. Before the botnet took a hit, it was showing some interesting behaviour, the researchers said in a blog post.

“This application exfiltrates the SMS messages in a unique way. Some SMS-stealing malware sends the contents of users’ SMS messages by forwarding the messages over SMS to phone numbers under the attacker’s control,” read the post, from FireEye researchers Vinay Pidathala, Hitesh Dharmdasani, Jinjian Zhai and Zheng Bu.

“Others send the stolen SMS messages to a CnC server over TCP connections. This malicious app, by contrast, sends the stolen SMS messages to the attacker’s email address over an SMTP connection.

“MisoSMS is one of the largest mobile botnets that leverages modern botnet techniques and infrastructure. This discovery, coupled with the other discoveries from FireEye, highlights the importance of mobile security and the quickly changing threat landscape.”

This is the second time in a month a unique piece of Android malware has been spotted in the wild. Lookout said for the first time it spied Android malware calling premium rate numbers.

What do you know about Internet security? Find out with our quiz!

Thomas Brewster

Tom Brewster is TechWeek Europe's Security Correspondent. He has also been named BT Information Security Journalist of the Year in 2012 and 2013.

Recent Posts

Ericsson To Cut 1,200 Jobs in Sweden Amid ‘Challenging’ Market

Swedish telecoms giant Ericsson blamed “challenging mobile networks market” and “further volume contraction” for job…

1 hour ago

FTX’s Sam Bankman-Fried Sentenced To 25 Years In Prison For $8bn Fraud

Dramatic downfall. Sam Bankman-Fried sentenced to 25 years in prison for masterminding $8bn fraud that…

2 hours ago

Elon Musk Orders FSD Demo For Every Tesla US Sale

Fallout avoidance? Tesla buyers in the US must be shown how to use the FSD…

3 hours ago

Amazon Pumps Another $2.75 Billion Into Anthropic

Amazon completes its $4bn investment into AI firm Anthropic, after providing an additional $2.75bn in…

5 hours ago

The Sustainability of AI

While AI promises unparalleled efficiency, productivity, and innovation, questions regarding its environmental impact loom large.…

8 hours ago

Trump’s Truth Social Makes Successful Market Debut

Shares in Donald Trump’s social media company rose about 16 percent after first day of…

8 hours ago