ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Malware

Large scale Android Mobile Botnet Hijacking Discovered

Paul by Paul
December 17, 2013 - Updated on May 17, 2022
in Malware, Mobile Security, Public
Reading Time: 1 min read
android mobile botnet
Share on FacebookShare on Twitter

Researchers at FireEye revealed the menace today, describing MisoSMS as “one of the largest advanced mobile botnets to date” and warning that it is being utilized in more than 60 malware campaigns.

FireEye monitored the infections to Android units in Korea and noted that the operaters are logging into command-and-control servers (C&C) from Korea and China, amongst other areas, to occasionally browse the stolen SMS messages.

You might also like

How Hackers Still Manage to Compromise MFA

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

FireEye’s research team identified a total of 64 mobile botnet campaigns within the MisoSMS malware family and a command-and-control that consists of over 450 unique malicious e-mail accounts.

FireEye security researchers Vinay Pidathala stated that MisoSMS infects Android systems by deploying a malicious Android app called “Google Vx” that acts as an Android settings app used for administrative tasks.

The app uses a bit of trickery to install and hide itself from the user. Once it’s installed, the app secretly steals the user’s personal SMS messages and emails them to a webmail command-and-control server.

Pidathala went on to explain the SMS ex-filtration technique:

“This application exfiltrates the SMS messages in a unique way. Some SMS-stealing malware sends the contents of users SMS messages by forwarding the messages over SMS to phone numbers under the attacker’s control. Others send the stolen SMS messages to a CnC server over TCP connections. This malicious app, by contrast, sends the stolen SMS messages to the attacker’s email address over an SMTP connection. ”

Pidathala reported all of the malicious e-mail accounts have already been banned as part of a mitigation strategy with law enforcement and security response officials in Korea and China

Tags: androidbotnetFireEyemalware
Previous Post

Botnet utilizes the infected to hack the sites they visit

Next Post

AV program signed with 12 stolen digital certificates

Paul

Paul

Editor and chief at ZeroSecurity. Expertise includes programming, malware analysis, and penetration testing. If you would like to write for ZeroSecurity, please click "Contact us" at the bottom of the page.

Recommended For You

How Hackers Still Manage to Compromise MFA

How Hackers Still Manage to Compromise MFA

March 6, 2026
Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

February 6, 2026

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

January 1, 2025

BadBox Botnet Infects Over 190,000 Android Devices Worldwide

December 20, 2024

FBI Warns of HiatusRAT Targeting Network Devices Worldwide

December 18, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.