When Voice Phishing met Malicious Android App

No ratings

Presented at CODEBLUE2018@TOKYO 2018 by

The traditional voice phishing we know is that the attacker makes a call to the victim and then fraud with social engineering techniques. However, there are not many users who are deceived in such an old-fashioned attack.Imagine that what happens if attackers intercept the call when we make a call to the primary number of a government agency or financial company? We may trust this number because we made a call ourselves.We firstly discovered malicious apps with the feature to intercept outgoing calls last year. Unfortunately, we couldn’t acquire an alive malicious app distribution server. Because the server was already closed when we have received a report about victims.Fortunately, one day we had received a report from a victim without delay, and we finally could collect alive malware distribution server. We made an automation script for real-time malicious app collection based on the strings of webpage source code discovered from the first distribution server. We have been able to find malicious app distribution servers and variants of the malicious app.In this talk, we will disclose the fascinating findings of the actual voice phishing criminal which have been traced over the last few months.