Comments on: Roaming Mantis implements new DNS changer in its malicious mobile app in 2022 https://securelist.com/roaming-mantis-dns-changer-in-malicious-mobile-app/108464/ Fri, 03 Feb 2023 08:54:27 +0000 hourly 1 https://wordpress.org/?v=6.2.2 By: Securelist https://securelist.com/roaming-mantis-dns-changer-in-malicious-mobile-app/108464/#comment-3533071 Fri, 03 Feb 2023 08:54:27 +0000 https://kasperskycontenthub.com/securelist/?p=108464#comment-3533071 In reply to Tyler Nash.

Hi Tyler!

This investigation is ongoing, and we withhold such details, so as not to provoke the actor.

]]>
By: Tyler Nash https://securelist.com/roaming-mantis-dns-changer-in-malicious-mobile-app/108464/#comment-3533045 Wed, 01 Feb 2023 23:35:54 +0000 https://kasperskycontenthub.com/securelist/?p=108464#comment-3533045 How did you determine the amount of downloaded APKs?

]]>
By: Securelist https://securelist.com/roaming-mantis-dns-changer-in-malicious-mobile-app/108464/#comment-3533013 Mon, 30 Jan 2023 17:52:50 +0000 https://kasperskycontenthub.com/securelist/?p=108464#comment-3533013 In reply to AAA.

Hi AAA!

We don’t share malicious packages, because we are a cybersecurity company. However, we provide file hashes in the IoC section, so if you want, you can try to find APKs by hash on the internet.

]]>
By: AAA https://securelist.com/roaming-mantis-dns-changer-in-malicious-mobile-app/108464/#comment-3532882 Thu, 26 Jan 2023 01:54:57 +0000 https://kasperskycontenthub.com/securelist/?p=108464#comment-3532882 Can I get related APK files?

]]>
By: Securelist https://securelist.com/roaming-mantis-dns-changer-in-malicious-mobile-app/108464/#comment-3532853 Tue, 24 Jan 2023 16:09:03 +0000 https://kasperskycontenthub.com/securelist/?p=108464#comment-3532853 In reply to Alex.

Hi Alex!

They do not install valid certificates. We have observed two types of landing pages: those using HTTP, and those using invalid certificates. In both cases the browser shows a warning in the address bar when the landing page is opened.

]]>
By: Alex https://securelist.com/roaming-mantis-dns-changer-in-malicious-mobile-app/108464/#comment-3532844 Tue, 24 Jan 2023 09:42:28 +0000 https://kasperskycontenthub.com/securelist/?p=108464#comment-3532844 Given that most of today’s traffic is TLS encrypted, manipulating hostname resolution is not sufficient for an attack. Does Roaming Mantis also install a rogue root certificate into the device’s trust store?

]]>