AIRLINK 167.01 Decreased By ▼ -1.50 (-0.89%)
BOP 9.75 Decreased By ▼ -0.04 (-0.41%)
CNERGY 7.78 Decreased By ▼ -0.21 (-2.63%)
CPHL 88.70 Increased By ▲ 0.73 (0.83%)
FCCL 44.99 Increased By ▲ 1.06 (2.41%)
FFL 15.25 Decreased By ▼ -0.27 (-1.74%)
FLYNG 28.10 Increased By ▲ 0.16 (0.57%)
HUBC 140.20 Increased By ▲ 2.23 (1.62%)
HUMNL 12.56 Increased By ▲ 0.19 (1.54%)
KEL 4.22 Decreased By ▼ -0.02 (-0.47%)
KOSM 5.50 Decreased By ▼ -0.06 (-1.08%)
MLCF 67.40 Increased By ▲ 2.61 (4.03%)
OGDC 213.50 Increased By ▲ 1.81 (0.86%)
PACE 5.54 Decreased By ▼ -0.19 (-3.32%)
PAEL 44.45 Decreased By ▼ -0.57 (-1.27%)
PIAHCLA 16.85 Decreased By ▼ -0.24 (-1.4%)
PIBTL 9.36 Increased By ▲ 0.13 (1.41%)
POWER 14.31 Decreased By ▼ -0.14 (-0.97%)
PPL 163.99 Decreased By ▼ -2.41 (-1.45%)
PRL 29.29 Decreased By ▼ -1.36 (-4.44%)
PTC 21.51 Increased By ▲ 0.31 (1.46%)
SEARL 88.51 Decreased By ▼ -1.96 (-2.17%)
SSGC 40.50 Decreased By ▼ -0.55 (-1.34%)
SYM 14.79 Increased By ▲ 0.31 (2.14%)
TELE 7.17 Decreased By ▼ -0.22 (-2.98%)
TPLP 9.19 Decreased By ▼ -0.18 (-1.92%)
TRG 64.35 Decreased By ▼ -0.65 (-1%)
WAVESAPP 9.42 Decreased By ▼ -0.09 (-0.95%)
WTL 1.29 Decreased By ▼ -0.02 (-1.53%)
YOUW 3.65 Decreased By ▼ -0.07 (-1.88%)
AIRLINK 167.01 Decreased By ▼ -1.50 (-0.89%)
BOP 9.75 Decreased By ▼ -0.04 (-0.41%)
CNERGY 7.78 Decreased By ▼ -0.21 (-2.63%)
CPHL 88.70 Increased By ▲ 0.73 (0.83%)
FCCL 44.99 Increased By ▲ 1.06 (2.41%)
FFL 15.25 Decreased By ▼ -0.27 (-1.74%)
FLYNG 28.10 Increased By ▲ 0.16 (0.57%)
HUBC 140.20 Increased By ▲ 2.23 (1.62%)
HUMNL 12.56 Increased By ▲ 0.19 (1.54%)
KEL 4.22 Decreased By ▼ -0.02 (-0.47%)
KOSM 5.50 Decreased By ▼ -0.06 (-1.08%)
MLCF 67.40 Increased By ▲ 2.61 (4.03%)
OGDC 213.50 Increased By ▲ 1.81 (0.86%)
PACE 5.54 Decreased By ▼ -0.19 (-3.32%)
PAEL 44.45 Decreased By ▼ -0.57 (-1.27%)
PIAHCLA 16.85 Decreased By ▼ -0.24 (-1.4%)
PIBTL 9.36 Increased By ▲ 0.13 (1.41%)
POWER 14.31 Decreased By ▼ -0.14 (-0.97%)
PPL 163.99 Decreased By ▼ -2.41 (-1.45%)
PRL 29.29 Decreased By ▼ -1.36 (-4.44%)
PTC 21.51 Increased By ▲ 0.31 (1.46%)
SEARL 88.51 Decreased By ▼ -1.96 (-2.17%)
SSGC 40.50 Decreased By ▼ -0.55 (-1.34%)
SYM 14.79 Increased By ▲ 0.31 (2.14%)
TELE 7.17 Decreased By ▼ -0.22 (-2.98%)
TPLP 9.19 Decreased By ▼ -0.18 (-1.92%)
TRG 64.35 Decreased By ▼ -0.65 (-1%)
WAVESAPP 9.42 Decreased By ▼ -0.09 (-0.95%)
WTL 1.29 Decreased By ▼ -0.02 (-1.53%)
YOUW 3.65 Decreased By ▼ -0.07 (-1.88%)
BR100 12,327 Increased By 71.3 (0.58%)
BR30 36,803 Increased By 80.1 (0.22%)
KSE100 115,469 Increased By 449.5 (0.39%)
KSE30 35,563 Increased By 234.3 (0.66%)

ISLAMABAD: The National Telecommunication & Information Security Board (NTISB) has warned that Konfety Group targets Android users with “Evil Twin” malicious Play Store apps.

The board issued an advisory which stated that Google Play Store identified and thwarted an active malicious campaign targeting Android users globally. Collectively named as Konfety Apps; this campaign used 250+ Decoy Evil Twin android applications.

The malicious activity is allegedly conducted by the Russian Konfety cybercrime group having ulterior motives primarily backed by monetary gains using advertisement fraud.

The advisory further noted that attackers use advertising campaigns to promote modified APK and redirects users to download malicious apps. Konfety malware involves a dropper APK that further loads an obfuscated stager and back door SDK, making it highly evasive hence difficult to detect. Further, the decoy twin apps used by attackers appear harmless while Evil Twin mimics them to commit ad fraud, install payloads, second stage malwares and code injection etc.

The Board recommended that although Google has removed Konfety apps from its Play Store, however, if any of the attached malicious Konfety apps found installed on smart phones, following remedial measures may be opted: a). Immediately uninstall specific Konfety app. b). Perform a factory reset. c). Take a backup of personal media files (excluding device/system apps). d. Restrict unnecessary apps permission and set to while using App only. e). Download and install software only from official app stores like Play Store or the IOS App Store. f. Keep your smart phone, OS and apps updated. g. Regularly check the smart devices/Wi-Fi data usage of apps installed on smart devices. h. Use a reputed anti-virus and internet security software package on your smart devices.

The board issued another advisory which stated that Google has released Chrome browser version 126 with security updates to address 10 vulnerabilities.

Majority of the vulnerabilities are high-severity memory issues potentially leading to Sandbox Escapes and Remote Code Execution. Fixes include flaws in V8’s Implementation, Type Confusion and Use-After-Free bugs in Screen Capture, Media Stream, Audio and Navigation. Google also addressed Race Condition in DevTools and an Out-of-Bound memory access in V8. No exploits in the wild are reported but users are urged to update promptly.

To safeguard against Chrome vulnerabilities, users are advised to ensure that Google Chrome browser is updated to following versions (by navigating to Setting>About Chrome and Re-launching the browser): a. Version 126.0.6478.182 or later on Windows/Linux b. Version 126.0.6478.183 or later on macOS c. Version 126.0.6478.186 or later on Android.

Copyright Business Recorder, 2024

Comments

Comments are closed.