{"id":143,"date":"2020-11-18T13:24:43","date_gmt":"2020-11-18T13:24:43","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=143"},"modified":"2021-08-30T09:21:16","modified_gmt":"2021-08-30T09:21:16","slug":"spy-android-spynote-instagram","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2020\/11\/18\/spy-android-spynote-instagram\/","title":{"rendered":"Spy.Android.SpyNote.Instagram"},"content":{"rendered":"<h2>General Explanation<\/h2>\n<p><strong>Type<\/strong>: Spyware<\/p>\n<p><strong>Degree of destruction<\/strong>: average<\/p>\n<p><strong>Prevalence<\/strong>: average<\/p>\n<h3>What is spyware?<\/h3>\n<p>By installing Spyware on your phone, the user\u2019s data security is always under threat and each second, it is possible to be stolen and received by an unauthorized person. Usually, spyware is installed on the phone secretly and out of the user\u2019s sight and performs its actions in complete secrecy. This kinds of spyware collect the necessary data about the user\u2019s activity on the phone or any other data that is necessary and at the right time will send it to another person. Usually, spyware by deceiving users on the internet will be installed on their phone, as a useful and applicant application. The malware collects the information about the user\u2019s activity on the phone such as passwords, credit card information, and other security information such as compressed buttons by keyboard and user\u2019s call list, contact list, sending and receiving a text message, etc.<\/p>\n<h3>What is the SpyNote family?<\/h3>\n<p>This is a remote access Trojan (RAT). It means, it can remotely and by the server, access all devices that the malware is installed on. The destructive actions that are performed in the user\u2019s phone are items such as: stealing user\u2019s data like messages and contact list, listening to victims conversation, sound recording, controlling camera, attain admin access (Admin), and the possibility to initial calls in the user\u2019s phone.<\/p>\n<h2>Technical Explanation<\/h2>\n<p>The name of this application is \u201cFollowerInstagram\u201d which is a member of the Spyware family and names \u201cSpyNote\u201d. This application immediately gets control of the Device Admin to help its persistence; so, it does not help the user to delete the application easily. Also, by using AccessibilityServices permission which attains from the user for its application, will attempt to steal complete information from an installed application on the phone, user\u2019s personal information such as calls, send\/receive SMS, complete information of the phone, sound recording, taking a photo, receiving geographical situation, etc. after running the application, a service of the type AccessibilityServices, is recalled to attain settings related to accessibility services and the following image will appear to the user. If the user enables the accession for the application, malware will initiate its destructive action without any problem and still keeps its services in the above background (even if the user stops this service, it will restart again after few seconds, and then automatically the application will be closed and its icon will vanish). As surveys, after attaining accessibility services, malware will provide a file that includes a list of the installed application on the phone along with the installation date and package name and will add it in the data\/data path. I.e. the application updated will make a list of installed applications on the phone and collect its other desired information, will run once the A application service every 3 minutes, and checks the execution of this service.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-144 aligncenter\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2020\/11\/Service-a.png\" alt=\"\" width=\"332\" height=\"493\" \/><\/p>\n<p>\u201cA\u201d service:<\/p>\n<p>The following destruction operation will happen every 15 seconds:<\/p>\n<ol>\n<li>Will keep the device on in the background which is executed by running application services using the WakeLock method.<\/li>\n<li>Because in a special situation such as SafeMode, the WiFi connection will automatically shut down by using WifiLock to keep the device\u2019s wifi connection on.<\/li>\n<li>Checking the on\/off situation of the phone screen.<\/li>\n<li>Fetching complete information of the user\u2019s phone which includes the follows:\n<ul>\n<li>The device specification (host, ID, device model, system bootloader version number, a trading name of the device, name of the hardware, fingerprint, name of the manufacturer, hardware-software number, etc.)<\/li>\n<li>OS specification (Android version, SDK version, language, and the current time.<\/li>\n<li>SIM card specification (IMEI, SIM card serial number, network operator, operator\u2019s name, phone number, and the zip code of the provider country).<\/li>\n<li>A geographical situation or phone\u2019s locale by GSM (cell phone country code, cell phone network code, cell phone signature, area code of the residence)<\/li>\n<li>Battery (Battery power status, check how the device is charged (USB))<\/li>\n<li>WIFI ( service signature, MAC address, velocity, signal quality)<\/li>\n<li>The volume of the phone<\/li>\n<li>Checking Bluetooth connectivity status<\/li>\n<li>Specifies SIM cards with active internet.<\/li>\n<\/ul>\n<\/li>\n<li>Access to SD card and attain a list of all files in it.<\/li>\n<li>Access to internal storage and changing its contents (for instance changing name or the file storage paths, change in the size and the existing image frame, etc.)<\/li>\n<li>Access to call log and fetching its full data (name, number, etc.)<\/li>\n<li>Checking of being root or not being the root<\/li>\n<li>Access to the full information of user\u2019s phone SMSs (text of the message, sender\/receiver name, sender\/receiver number, date, etc.)<\/li>\n<li>Access to user\u2019s account information in the system (name and the type of user account)<\/li>\n<li>Access to complete information of phone contacts<\/li>\n<li>Access to complete information of call history and remove each item according to its specified signature<\/li>\n<li>Access to complete information of phone contacts and change\/remove each item according to its specified name<\/li>\n<li>Fetching camera settings<\/li>\n<li>Access to phone camera settings, because each time the rare or front camera is adjusted<\/li>\n<li>Opening the phone camera<\/li>\n<li>Creating a list of setScanMode, setFocusMode, setFlashMode, and setColorMode (different modes that adjusted for taking a photo, for instance, Flash, Color, and Scan)<\/li>\n<li>Taking a photo and checking if the photo is taken right or not.<\/li>\n<li>Change in device volume, for instance, increasing the voice, if the system\u2019s volume is low or off<\/li>\n<li>Adjusting the microphone as a sound resource to record voice, recording voice, and storing it in a path in the SD card.<\/li>\n<li>Possibility of turning the WIFI on or off<\/li>\n<li>Access to locale status information of the user by GPS and checking it every 5 seconds<\/li>\n<li>Checking the activation\/deactivation of GPS<\/li>\n<li>By getInstalledApplications it will receive a list of all applications that are already installed on the phone which involves complete information such as first installation date, last update date, application icon, application version, application path, application size, and whether the application is system-based or user-based.<\/li>\n<li>Checking the special application being installed and open it, if it is installed.<\/li>\n<li>Attain system policy (principles and rules set for the device) and then initiate the factory reset which deletes all user\u2019s information.<\/li>\n<li>Initiating a phone call by specific phone number and attain certificate \u201candroid.permission.CALL_PHONE\u201d.<\/li>\n<li>By using send text message() and assign the receiver phone number and the message text, sends an SMS and then checks its send\/failed status<\/li>\n<li>Stealing pressed key information from the user\u2019s keyboard and saving them<\/li>\n<li>By attaining the \u201candroid.intent.action.DELETE\u201d permission and adjust the package name of the desired application, will delete applications.<\/li>\n<\/ol>\n<p>Finally, this spyware after collecting all its desired information about the victim, will encrypt them and send them to its command and control server \u201cimages. myvnc[.]com\u201d.<\/p>\n<h2>How to deal with it and disinfect the system<\/h2>\n<p>To make sure that the system is safe, install <a href=\"https:\/\/padvish.com\/en-us\/Main\" target=\"_blank\" rel=\"noopener\">Padvish antivirus<\/a> and keep its database file and scan it.<\/p>\n<p><strong>Methods of preventing phone infection:<\/strong><\/p>\n<ol>\n<li style=\"min-height: 1.5em\">Avoid downloading and installing any application from unauthorized resources\/markets.<\/li>\n<li style=\"min-height: 1.5em\">Note the requested permissions, when installing the mobile application.<\/li>\n<li style=\"min-height: 1.5em\">Continuously back up your saved data and files.<\/li>\n<li style=\"min-height: 1.5em\">Do not use an unofficial version of applications. Applications such as Telegram, Instagram have many unofficial versions and most of them release through Telegram channels.<\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>General Explanation Type: Spyware Degree of destruction: average Prevalence: average What is spyware? By installing Spyware on your phone, the user\u2019s data security is always under threat and each second, it is possible to be stolen and received by an unauthorized person. Usually, spyware is installed on the phone secretly and out of the user\u2019s&hellip;<\/p>\n","protected":false},"author":16,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[],"class_list":["post-143","post","type-post","status-publish","format-standard","hentry","category-spyware"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/143","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/16"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=143"}],"version-history":[{"count":8,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/143\/revisions"}],"predecessor-version":[{"id":816,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/143\/revisions\/816"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=143"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=143"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=143"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}