The Cyber Security Review | Friday, March 12, 2021
Rogue, a new malware development package, was discovered by Check Point researchers which has the potential to enable the development of advanced malware for android.
Fremont, CA: Android smartphone has always been attractive targets for cybercriminals. Some cybercriminals put additional efforts to innovate unusual methods of attacking. Lately, a large and affordable network of android mobile malware development packages was located on the dark web, which is expected to transform the way malware is developed.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Rogue, the new danger
Researchers at Check Point discovered the package called Rogue, that is enabling the development of advanced android malware, that are proficient in gaining control over host android device and exfiltrate sensitive data. A threat actor dubbed Triangulum has been seen extending Rogue a collaboration with another player nicknamed HexaGoN Dev. The sale thread is offering the most advanced iteration on undercover forums for as low as $29.99, providing low-level cybercriminals, with insufficient technical skills, the capability to seize sensitive personal data.
Rogue’s inclinations
Rogue usually aims for android devices with keyloggers permitting felons to watch the use of websites and apps to steal login credentials and other delicate data. Rogue has been managing persistence with advanced capabilities such as GPS location monitoring, camouflage protection technique, and information exfiltration. The malware gets around by exploiting Google's Firebase service for apps to conceal its ill-disposed purposes and disguise as a legitimate app on the device.
Rogue's Origin
The Rogue not a completely distinct malware family. It is the mixed variant of two premature families of Android RATs - Cosmos and Hawkshaw. Moreover, Rogue resembles to be the latest alternative of an ancient malware called Dark Shades, which was acquired by Triangulum in August 2019.
Comparable to Triangulum, there are numerous menace actors actively practising their skills to produce high-level malware and making them commercially available on the dark web. Therefore, users must stay vigilant. Specialists advocate users keep their devices modernized with all security applications and download apps only from a trusted source.
More in News