Over the past month, many articles have been published recommending that we keep our mobile phones clean to reduce the risk of Coronavirus infection. While there’s still some debate over whether it’s necessary to clean your phone case and screen to get rid of possible germs, it’s a good idea to watch out for internal infections that your phone could pick up. Skilled threat actors are exploiting peoples’ concerns about Coronavirus to spread mobile malware, including Mobile Remote Access Trojans (MRATs), Banker Trojans, and Premium Dialers, via apps which claim to offer Coronavirus-related information and help for users.
Check Point’s researchers discovered 16 different malicious apps, all masquerading as legitimate Coronavirus apps, which contained a range of malware aimed at stealing users’ sensitive information or generating fraudulent revenues from premium-rate services.
It’s important to note that none of the malicious apps were available on an official app store. They were offered from new Coronavirus-related domains, which researchers believe had been created specifically with the aim of deceiving users. As we reported recently, more than 30,103 new coronavirus-related domains were registered in the past two weeks, of which 0.4% (131) were malicious and 9% (2,777) were suspicious and under investigation. Over 51,000 of coronavirus-related domains in total have been registered since January 2020.
How to protect yourself?
It is important that users only download apps from legitimate app stores such as Google Play and Apple’s AppStore.
If you suspect you may have one of these infected apps on your device, here’s what you should do:
- Uninstall the infected application from the device
- Update your device Operation System and Applications to the latest version
- For your personal device, we recommend using a mobile-specific security solution such as ZoneAlarm Mobile Security to check that all the apps on your phone are legitimate and not malicious.
Some tips to keep your mobile devices healthy and prevent data breaches
- Don’t Connect to Public Wi-Fi networks
- Enable remote lock and data wipe for mobile devices
- Avoid answering unsolicited calls, or even block them
- When you surf the web, make sure you only use websites secured with SSL, also on mobile
- Download applications only from the official app stores
Enterprises need to protect all their employees’ corporate devices against sophisticated mobile cyberattacks with solutions such as Check Point SandBlast Mobile. For a more in-depth technical analysis of the research you can click here.