New Android Malware Surge Hits Devices via Overlays Virtualization Fraud and NFC Theft
The inner workings of AntiDot, an Android malware that has penetrated over 3,775 devices as part of 273 distinct attacks, have been made public by cybersecurity researchers.
In a report sent to The Hacker News, PRODAFT stated that AntiDot, which is run by the financially driven threat actor LARVA-398, is regularly offered for sale as a Malware-as-a-Service (MaaS) on underground forums and has been connected to numerous mobile campaigns.
AntiDot is marketed as a "three-in-one" solution that can intercept SMS messages, record the device's screen by abusing Android's accessibility services, and get private information from third-party apps.
Based on activity that suggests selective victim targeting by language and location, it is assumed that the Android botnet was distributed using...

