SMS Delivery Malware Attack
Message Details
Sender: "USPS" (spoofed)
Time Received: February 10, 2024, 11:32 AM
Content: "USPS: Your package has a delivery exception. Update address: [malicious-link]"
Context: Was expecting multiple packages (made it credible)
Attack Analysis
Message Characteristics
- Sender ID: Spoofed to show "USPS" (not just number)
- Urgency: Delivery exception requires immediate action
- Personalization: Generic enough for mass sending
- Link: usps-tracking-update[.]com (looks legitimate)
Link Analysis
- Website: Professional USPS replica
- Request: Enter address and phone number
- Malware: Android APK download disguised as "tracking update"
- Permissions: Requested full device access
Technical Investigation
Malware Analysis
- Type: Trojan disguised as USPS tracking app
- Capabilities:
- SMS interception
- Keylogging
- Contact list theft
- Banking app credential theft
- Remote access
- Distribution: 5,000+ downloads before takedown
Infrastructure
- Domain: Registered 1 week before campaign
- Hosting: Compromised WordPress site
- C2: 194.233.164.12 (Germany)
- Targets: Primarily Android users in US
Protective Actions
Immediate Response
- Device:
- Did not click link
- Screenshot message
- Blocked sender
- Ran malware scan
- Reporting:
- Forwarded to 7726 (SPAM reporting)
- Reported to USPS Postal Inspection Service
- Filed with FTC
- Submitted Quiet-Report
Preventive Measures
- Device Security:
- Updated Android security patch
- Verified app installation sources
- Installed reputable security app
- Behavior Changes:
- Never click links in delivery texts
- Verify through official apps
- Use package tracking apps directly
Impact Assessment
Risk Factors
- High: Expecting actual deliveries
- Medium: Android device vulnerabilities
- Low: Security awareness prevented infection
Potential Damage (if installed)
- Financial loss from banking apps
- Identity theft from personal data
- Additional malware spreading to contacts
- Device compromise requiring factory reset
Detection Statistics
Campaign Scope
- Messages Sent: Estimated 500,000+
- Click Rate: ~5% (based on download counts)
- Infection Rate: ~60% of clicks
- Geographic: Primarily US, major cities
Takedown Actions
- Domain: Suspended by registrar
- Hosting: Site taken down
- C2: Investigated by authorities
- Warning: USPS issued official alert
Recommendations
- For Users:
- Use official carrier apps for tracking
- Never download APKs from links
- Verify delivery issues through official channels
- For Carriers:
- Official SMS sender IDs
- Public awareness campaigns
- Better fraud reporting systems