Telecom

[Phishing ①] The target is a 'zombie phone'... Calls and URLs used to induce malicious app installs

IT DAILY ·

AI-generated image

✦ AI Summary

Voice phishing is evolving from transfer-inducement scams to schemes that take over mobile phones.

Scams that steal personal information and money through impersonation of institutions or acquaintances and inducement to install malicious apps are spreading, and voice tampering and profile image manipulation are also being added.

The government and the three major mobile carriers are responding with AI-based detection and blocking technologies.

Voice phishing crimes are evolving from transfer-inducement scams to schemes that take over mobile phones. After deceiving victims with calls impersonating institutions or acquaintances, criminals are spreading tactics that induce malicious app installation and use it to steal personal information and money. More recently, the methods have become more sophisticated with voice tampering and manipulated profile images.

This article is part of a two-part series. It explains that voice phishing has expanded beyond simply tricking victims into sending money and has evolved into a method of controlling their mobile phones.

As an example, the article presents the chain of events in a case involving a woman in her 60s identified as A. She received a call claiming to be from a bank about issuing a new check card, but replied that she had never applied for one. The caller, impersonating the bank, then said someone had stolen her identity and demanded that she install a security app.

A downloaded the app as instructed. She then called the bank's official number to verify the facts. However, the person on the line reassured her and told her to put the existing check card linked to her account in the mailbox.

But that counselor was not a real bank employee; he was a member of a voice phishing ring. The call A made to verify the facts had been routed to an overseas voice phishing call center because of the malicious app. In this way, the group lured victims into installing a malicious app through calls impersonating card issuance, then kept the flow going by making sure that even when victims called the official number to verify, the organization answered and issued further instructions.

The actors responding to this change are the government and the country's three major mobile carriers. They are focusing their response on AI-based detection and blocking technologies.

This reconstruction of a voice phishing case is based on the methods used by a China-based voice phishing ring that police busted in August.

Under Article 2, Paragraph 1 of the Basic Telecommunications Act, telecommunications financial fraud refers to acts of obtaining property gains or benefiting a third party through deception using telecommunications. Representative methods include voice phishing and smishing. Voice phishing is a method of impersonating another person or a government agency by phone and then extorting money. Smishing is a method of sending a text URL(link) to induce app installation or clicks and then extorting personal information and money.

The main bases of these voice phishing rings are overseas, centered in places such as China and Cambodia. They use SIM box as a tool to manipulate caller IDs. A SIM box is a spoofing repeater equipped with multiple illegal SIMs. This device routes internet calls from overseas call centers and the like through domestic mobile networks, causing the victim's phone to display the call as if it came from a 010 number.

As the center of criminal methods has shifted from PC-based operations to smartphone-targeting tactics, the approach has also changed. In the past, the main method was 'pharming' using malware, which redirected victims to fake financial websites. More recently, criminals have been using calls and text messages to induce victims to install malicious apps on their phones.

Once a malicious app is installed, the criminal group takes over the victim's smartphone through a control server, and the compromised phone becomes a 'zombie phone.' In this state, remote control is possible without the user's consent, and the criminal group can intercept calls received on the victim's smartphone or place calls from a number in the victim's name. This interception of incoming calls and placement of outgoing calls using the victim's number is known as forced call reception and forced call origination, or 'gangsu gangbal,' and it can be manipulated so that when victims make a verification call, they are connected to the criminal organization instead of the real investigative agency or financial institution. At that point, the group's calls can be made to appear as if they are coming from the actual agency's phone number.

One of the main methods used by voice phishing rings is to induce malicious app installation through URLs and other means outside the official app market. App downloads from external routes that do not go through official app markets such as Play Store and App Store are called sideloading.

Whether sideloading is possible varies depending on whether the device OS is Google Android or Apple's iOS. Voice phishing rings are said to attempt to identify the model of the victim's phone.

On Google Android devices, installing apps from external routes outside the official app market is possible. Android was designed as an open operating system intended to guarantee user freedom, and criminal groups are exploiting that openness.

By contrast, Apple iOS basically has an app distribution structure centered on the App Store, and external app installation on iOS is only permitted under limited conditions depending on region and requirements. For that reason, in domestic voice phishing crimes, when the victim uses an iPhone, there have been cases in which the criminals ask them to prepare a separate Android-based spare phone for installing the malicious app.

Samsung Electronics' Galaxy smartphones are based on Android and display a warning that says 'unknown app' when an APK is downloaded from an external route. To install an external APK, the user must manually disable the relevant security feature in the device settings.

In addition, Google has introduced 'Advanced Flow' to prevent crimes. When installing an unverified app, a 24-hour waiting period is mandatory, and the process is structured so that installation is only possible after 24 hours have passed, following activation of developer options, enabling the setting to allow unverified packages, identity verification, confirmation of whether there is fraudulent coercion, and device restart. This is intended to respond to situations in which voice phishing criminals pressure victims to install malicious apps immediately.

This policy took effect first on September 30 in places such as Brazil and Indonesia. Google plans to expand it to Android devices worldwide in 2027.

With the recent advancement of AI, scam methods using voice tampering, text message drafting, and image manipulation are being detected. Beyond simple voice phishing, a wide range of scam tactics is spreading.

In particular, voice AI has advanced to the point where it can synthesize speech with regional dialects. As a result, the risk that victims may mistake the voice for that of an acquaintance is also growing.

Industry experts warned that tactics targeting vulnerabilities by age group and situation, such as investment-leading scams, team mission scams, romance scams, and no-show scams, are becoming more diversified. They stressed the need to remain vigilant against these trends.

Among them, investment-leading scams approach people interested in investing, wealth management, or side jobs, build trust, and deceive them into handing over money by promising high returns. The main targets are people looking to manage a lump sum such as severance pay and people seeking side jobs.

Online and impersonation-based scam types include team mission scams, romance scams, and no-show scams. These types each approach victims in different ways, but all blur the judgment of participants or victims for the purpose of stealing money and induce transfers or payments.

A team mission scam is a method of recruiting multiple participants online and then inducing them to carry out specific tasks. In the process, scammers provide small initial rewards to build trust and then gradually raise the amount participants are asked to contribute. They also foster competition among team members and use psychological pressure to induce victims to keep sending money.

A romance scam is a method of forming romantic interest online and then asking for money. Recently, there have also been cases using AI. In such cases, AI is used to create profile photos that look like real people and to generate synthetic voices to approach victims.

The perpetrators continue talking with the victim for a long time to build an intimate relationship and then request money. The pretext for the request is often investment or an urgent situation. A defining feature is that the relationship is established first and the transfer request comes afterward.

A no-show scam is a new type of scam aimed at stealing money by impersonating a public official or someone from a public institution and asking victims or companies to buy goods on their behalf. They approach victims as if they are calling from a procurement department at a specific institution and deceive them into participating in a nonexistent public-sector purchasing process.

They claim to be supplying safety-related items such as fire extinguishers and AEDs to institutions. The request typically takes the form of asking the victim to buy the items on their behalf or to send money in advance. In one real case, someone impersonating a firefighter asked a temple to arrange the purchase of fire extinguishers on the grounds that they were needed there and demanded a transfer of funds.

Investigators and telecommunications industry experts stress that when a person receives a call or text suspected to be voice phishing, it is important to end the contact immediately and report quickly to the relevant authorities.

If voice phishing damage has already occurred, follow-up measures such as criminal investigation and suspension of financial accounts are needed. In that case, the reporting channels are 112 or the relevant financial institution.

Even before damage occurs, if you receive a suspicious call or text, you can seek counseling and file a report through the National Police Agency's Telecommunications Financial Fraud Integrated Response Team at 1394. If you receive a call or text suspected to be voice phishing or smishing, counseling and reporting are also available through each telecom carrier's customer service center. If you receive a notice such as an alert about malicious app infection, you should visit the nearest telecom store or police station.

Among the three major mobile carriers, there is also a way to prevent voice phishing by using a call app. Among them, SK Telecom users can use the 'A.Dot Call' app.

In the 'A.Dot Call' app, related features are available through the path Settings → 'AI Security' tab. 'Family Care' is a feature that shares alerts with guardians when a suspicious phishing call is received. 'AI Safe Block' automatically blocks spam and phishing calls, and 'Risk Call Warning' issues a warning when dialing a number suspected of spam or phishing.

KT offers the free safety call app 'Whowho' through its subsidiary KT cs. 'Whowho' can be installed for free from official app stores, and it allows users to check caller information in real time. It also automatically filters malicious spam calls and malicious spam texts. KT also supports reporting voice phishing and smishing-suspected calls and texts, with reporting channels through customer service and Whowho.

LG Uplus offers the call app 'ixi-O.' 'ixi-O' can distinguish fake voices with AI and blocks suspected voice phishing numbers in advance. It also supports pre-detection and blocking before a URL is opened and shares the blocking result with the user. The real-time voice phishing detection service can be used by entering the ixi-O app settings, going through 'Safe Call Settings,' and enabling the 'Real-Time Voice Phishing Detection' feature.

Source: IT DAILY · Seong Won-young
Original: https://www.itdaily.kr/news/articleView.html?idxno=241887

References

This article was produced with the help of an automated content generation algorithm.


Source: IT DAILY

View original

This article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.