[ << ALL_FEED ]

A sucker is not a mammoth, an APK is not a video.

More in General

A fool and his money are soon parted, APK is not a video 🦣

In late 2024 — early 2025, information about the spread of the Mamont virus in Telegram was actively discussed online. This banking trojan, a malicious .apk file, was encountered by us under names such as CBO-Information.apk, Фoтoгpaф.apk, Google Video.apk, Video.apk, Видео.apk, Фото.apk, Photo.apk, Докyмент <Количество штук>.apk, and the like.

When installed on a phone, it requests permission to set itself as the default SMS app. Upon closing, it hides its presence on the system from the user by removing its icon from the home screen menu. Meanwhile, in the background, it collects information about installed apps, SIM cards, SMS messages, calls, and other user data, and sends it to a command-and-control server.

🔑 How it can infiltrate your Android

An unknown person sends you a file with the .apk extension in a messenger and asks if you are the one pictured in a photo or video. Sometimes they urgently demand you open an archive with documents, which is actually an .apk file.

The virus can also get onto your device:

• via phishing websites;
• via QR codes for joining closed groups, channels, etc.;
• disguised as legitimate apps (.apk files not from official stores);
• if an attacker has physical access.

🔐 How to avoid being tricked

1️⃣ Be more vigilant:
• do not click links in messages without checking where they lead;
• do not enter account credentials on suspicious resources;
• avoid scanning QR codes in public places (they may lead to phishing sites);
• do not open files from untrusted sources.

2️⃣ Adjust your privacy settings in the messenger. You can disable being added to groups and turn off receiving SMS messages from strangers (Settings → Privacy).

3️⃣ If you receive voice, SMS, or video messages from an acquaintance with unusual requests, contact them through alternative channels (attackers often use deepfakes).

4️⃣ Do not store passwords and banking details in saved messages or chats.

5️⃣ Only install apps from official stores and developer websites. Check the permissions requested: if an app requires access to data unrelated to its functionality, this may indicate malware.

6️⃣ Regularly check the list of installed apps — the Apps section (Installed Files, etc.) in your device settings. Some malware hides itself from the user. You can also use activity monitoring tools that will notify you of suspicious actions.

7️⃣ Pay attention to notifications and device behavior. If you receive many unusual notifications or the device heats up significantly while idle, this could be a sign of infection.

8️⃣ Regularly update your OS and apps. Updates often contain security fixes.

9️⃣ Use trusted antivirus software.

1️⃣0️⃣ Use a strong password to protect against physical access to your device.

1️⃣1️⃣ Regularly back up your data and store it in a safe place.

1️⃣2️⃣ To assess the damage if your mobile device is infected, conduct a forensic investigation.

1️⃣3️⃣ Continuously educate yourself and stay informed about new threats. For general awareness, you can take free courses from Positive Technologies — “Personal Cybersecurity” and “Basic Cybersecurity: First Dive.”

💡 Remember that APK (Android Package Kit) is a format used in the context of applications, not for photo or video files.

🎁 Bonus: we published IoCs for 2025 on Telegraph.

#news #tips #malware
@ptescalator

More from global_author

More from global_author

More in General