The Lemon Group, a prominent cybercrime organization, has planted the ‘Guerilla’ malware on nearly 9 million Android devices, enabling them to execute various malicious activities.
While among all the illicit activities here, we have mentioned the key ones:-
A recent Trend Micro report revealed that certain elements of the attackers’ infrastructure exhibit similarities with the Triada trojan operation in 2016, suggesting a potential connection between the two incidents.
Triada was discovered pre-installed in 42 Android smartphone models manufactured by budget-friendly Chinese brands with a global market presence, posing a significant security risk to users.
Cybersecurity researchers at Trend Micro identified over 50 infected ROMs used by the Lemon Group to load initial malware loaders onto devices. However, the specific method of infecting devices with malicious firmware remains undisclosed.
Trend Micro suggests that the compromise of devices by the Lemon Group could occur through various means such as:-
While beside this, the maliciously modified firmware of Lemon Group was identified by purchasing an Android phone and extracting its “ROM image.”
The modified system library ‘libandroid_runtime.so’ on the device decrypts and executes a DEX file, which activates the attackers’ main plugin, “Sloth,” and establishes communication using a Lemon Group domain specified in its configuration.
The Guerrilla malware’s primary plugin is responsible for loading specialized plugins designed for specific functions, encompassing a range of capabilities.
So, here below, we have mentioned all the additional plugins that are used by the Guerilla and also mentioned their capabilities as well:-
The threat actor, who has control over devices in over 180 countries, has spread the infection globally, as revealed through tracking indicators.
Here below, we have mentioned the top 10 countries that are affected:-
The true number of Android devices affected by the Guerrilla malware is potentially more significant than the reported count, indicating a broader scope of infection than initially estimated.
While apart from this, it has been identified that for generating OTP requests for SMS PVA services across various platforms, more than 490,000 mobile numbers were used.
This cybercrime syndicate’s single service has identified over 500,000 compromised devices, highlighting their extensive global presence.
Their malicious operations demonstrate a significant reach, impacting numerous locations worldwide.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…