Photo: Vladimir Astapkovich / RIA Novosti
The crooks attacked the users of the Internet service Avito using virus for Android. The potential damage from a Trojan, called FANTA, amounted to no less than 35 million rubles. About it reported in a press release of the company Group-IB, arrived in edition “Tapes.ru”.
Attackers find the contact details of the sellers in the network, and some time later, the victim gets a personal TEXT about the “translation” into his account the full value of the goods. The email contains a link that supposedly can arrange it for you.
On it the user goes to a fake page of the website Avito. When you click on the “Continue” button on the phone boots, the malware FANTA disguised as an app Avito.
Later, the Trojan gets credit card users: they enter this information into the Windows masquerading as legitimate mobile apps banks. Experts discovered that the malware is also able to read the text notifications about 70 applications of banks, systems of payment and electronic wallets.
In addition to Avito, the developers FANTA is able to create the conditions for hacking devices users around 30 different online services, such as AliExpress, Yula, Pandao, Aviasales, Booking, Trivago, as well as taxis and carcharhinoid services.
According to Group-IB, the last attack was aimed at Russian-speaking users, the majority of infected devices are in Russia, the smaller part — in Ukraine, Kazakhstan and Belarus.
Head of dynamic analysis of malicious code Group-IB Rustam Mirkasymov said that the campaign of Trajan was able to reveal empirically. Then one of the specialists of the company got suspicious SMS at the time of sale of the goods on Avito.
Video, photo All from Russia.