Since the beginning of 2018, I and several others have been working on a network of malware called PushIran.DL, the results of which we recently published in a comprehensive report on the website Sartefa, which I founded. This relatively long report, about 20 pages, contains important points for Android users in Iran, which is why this article has been written. Therefore, I strongly recommend that you send this article to your friends and acquaintances, as their Android devices are likely also infected with one of the PushIran.DL malware. The structure of PushIran.DL consists of various malware that introduce themselves to users under different names, such as "Which Actor Are You Like?", "Mushroom Eater", "18+ Collection", etc.; you can view a list of about 220 examples of these malware presented in various Android applications here. Additionally, we believe that at least 10 million Android devices in Iran are infected with this malware. The main developers and designers of PushIran.DL are two companies, Raman and Raz, which operate in mobile application development, online advertising, and online marketing in the country. According to what has been registered in the official newspaper of the country, these two companies began their official activities in the spring and summer of 2017. The goal of the developers of PushIran.DL is to earn money through various methods, such as exploiting telecommunications value-added schemes or illegally increasing the download rates of various applications in various Android application stores like Cafe Bazaar. The first and perhaps most important function of PushIran.DL malware relates to the use of telecommunications value-added services (VAS), which allows the designers of this malware to earn direct income from infected devices. For this purpose, the designers of PushIran.DL contract with VAS service providers and then receive a percentage as a commission from these companies. For example, the table below shows the daily income of 118 million tomans for VAS providers through 10 PushIran.DL applications, assuming a 1% commission, the developers of this malware family would earn a daily income of 1 million and 200 thousand tomans! The remarkable income of VAS companies also stems from the fact that PushIran.DL developers add the capability to activate VAS services via SMS as a commercial feature to their infected apps, and then start charging users daily. This daily charge, which is deducted from the victim's SIM card balance or added to their monthly bill, ranges from 200 to 400 tomans per day. In addition to this method, the developers of PushIran.DL use their malware network to forcibly install various applications on victims' devices, increase views of Telegram and Instagram posts, display advertising pop-ups, engage in click fraud to boost website views, and direct users to various pages and websites, such as value-added service websites. For example, the image below shows two examples of advertising pop-ups that PushIran.DL forcibly displays on users' devices. I must point out that if you see such messages on your Android device for any reason, know that your smartphone or tablet is infected with one of the PushIran.DL malware. The first step to countering PushIran.DL malware is to install an antivirus on your mobile phone or tablet. According to our research, the following antivirus programs can identify malware produced by PushIran.DL: Dr.Web, Avira, ESET NOD32, Kaspersky, Trend Micro. Make sure to download these antivirus programs from Google Play or Cafe Bazaar and never download APK files from other sources or Telegram channels. Additionally, always keep the installed antivirus updated. Besides installing and updating antivirus software, always check the comments section of a new application before installing it to read other users' opinions and ensure the authenticity of the application. This recommendation is due to the fact that in many cases, it has been observed that PushIran.DL designers have released an application under a name while that application does not have such functionality. Furthermore, be cautious when receiving various notifications and do not click on a notification without checking it, nor grant various permissions to different applications. Finally, strongly avoid installing applications like fortune-telling apps, "Who Do You Resemble?", "When Is Your Future Love?", etc., and do not install them under any circumstances. You can read the full report "The PushIran.DL Malware Family, A Fraudulent Advertising Botnet in Iran" here.
How Cyber Saboteurs Inflate Your Mobile Bill?
A report reveals that a network of malware called PushIran.DL is infecting Android devices in Iran, potentially affecting over 10 million devices. The malware exploits telecommunications value-added services to generate income for its developers through unauthorized charges to users' mobile bills. This situation highlights significant cybersecurity risks for Android users in Iran.
👥 Key Players
📰 What Happened
A report reveals that a network of malware called PushIran.DL is infecting Android devices in Iran, potentially affecting over 10 million devices. This malware exploits telecommunications value-added services to generate income for its developers through unauthorized charges to users' mobile bills.
- PushIran.DL malware is believed to infect at least 10 million Android devices in Iran.
- The malware generates income by exploiting telecommunications services, leading to unauthorized charges on users' mobile bills.
💡 Why It Matters
📚 Background
Cybersecurity threats are a growing concern globally, and malware targeting mobile devices can lead to significant financial and privacy risks for users. In Iran, where mobile technology is widely used, such threats are particularly alarming.
🏷️ Entities Mentioned
Translated from the original and edited for English readers. View original source →
Translation confidence: 85%