Security Architecture, Endpoint/Device Security, Endpoint/Device Security, Threat Management, Threat Management, Malware, Phishing, Endpoint/Device Security, Endpoint/Device Security, Endpoint/Device Security

Return to sender: Smishing attack delivers fake Czech postal service texts

A newly discovered SMS-based mobile phishing campaign is faking texts from the Czech Republic's postal service, hoping to trick Czech device owners into downloading a malicious app containing a trojan horse designed to steal credit card information and commit other malicious activities.

According to a Thursday blog post by Check Point Software Technologies, the smishing texts alert recipients of a shipment that's been rushed to a collecting depot, and contain a link leading to a phony Czech Post web page that immediately downloads the bad app. The scheme uses social engineering to trick users into approving the installation by labeling the app as a Flash Player update or Czech Post app.

After infection, victims who try to open any app will automatically receive a request for their credit card details and other personally identifying information, which is communicated back to the attackers' command-and-control server. The malware also can intercept SMS texts (allowing the bad actors to pass two-factor authentication), send SMS messages to contacts or specific numbers to spread the infection, and lock devices for a ransomware-style attack.

Bradley Barth

As director of multimedia content strategy at CyberRisk Alliance, Bradley Barth develops content for online conferences, webcasts, podcasts video/multimedia projects — often serving as moderator or host. For nearly six years, he wrote and reported for SC Media as deputy editor and, before that, senior reporter. He was previously a program executive with the tech-focused PR firm Voxus. Past journalistic experience includes stints as business editor at Executive Technology, a staff writer at New York Sportscene and a freelance journalist covering travel and entertainment. In his spare time, Bradley also writes screenplays.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms and Conditions and Privacy Policy.