<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>This topic</title>
    <link>https://community.bt.com/t5/Archive-Staging/Scam-Alert-Scam-missed-delivery-texts-and-Flubot-Malware/m-p/2157535#M1193222</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Flubot malware is malicious software that is installed when a victim receives a text message and follows a link, asking them to install a tracking app. This could be informing them of a "new voicemail" received or a ‘missed package delivery’. The tracking app is in fact spyware that steals passwords and other sensitive data and then also sends out multiple text messages to further pass on the malware.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;We will be sending text messages to customers that we have identified as being impacted by this scam, the text messages will link to this community article and we have including the contents of the text below so that you know it is genuine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Flubot.png" style="width: 400px;"&gt;&lt;img src="https://community.bt.com/t5/image/serverpage/image-id/72889i76A866B624D119CE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Flubot.png" alt="Flubot.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;How can I spot this particular scam&lt;/H2&gt;
&lt;P&gt;&lt;SPAN&gt;Victims receive a text message with a link asking them to install an app either for a new voicemail or a ‘missed package delivery’. See examples below for each of these, however, the message and app/link may vary and reference any company.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="ScamDHL.png" style="width: 344px;"&gt;&lt;img src="https://community.bt.com/t5/image/serverpage/image-id/72858iDBCED2BD26AE6CF5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ScamDHL.png" alt="ScamDHL.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="flubot voicemail.png" style="width: 544px;"&gt;&lt;img src="https://community.bt.com/t5/image/serverpage/image-id/73830i85D5DA64C6AB013B/image-size/large?v=v2&amp;amp;px=999" role="button" title="flubot voicemail.png" alt="flubot voicemail.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;What happens to my phone if I install Flubot Malware?&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Flubot malware impersonates other apps on a victim’s phone to steal their banking credentials and other private information. It will also access contact details and send out additional text messages – further spreading the spyware. It can eavesdrop on incoming notifications, read and write SMS’, make calls, and transmit the victims’ entire contact list back to its control centre.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you receive a scam text message:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Do &lt;STRONG&gt;NOT&lt;/STRONG&gt; click the link in the message, and do not install any apps if prompted.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Forward the message to &lt;STRONG&gt;7726&lt;/STRONG&gt;, a free spam-reporting service provided by phone operators.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Delete the message.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have already clicked the link to download the [Flubot] application:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;The &lt;STRONG&gt;NCSC&lt;/STRONG&gt; (&lt;STRONG&gt;National Cyber Security Centre&lt;/STRONG&gt;) have released guidance on what to do if you receive a Flubot SMS. You can find out more &lt;A title="Opens the NCSC website in another tab" href="https://www.ncsc.gov.uk/guidance/flubot-guidance-for-text-message-scam" target="_blank" rel="noopener"&gt;from the NCSC HERE&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;How to protect yourself&lt;/H2&gt;
&lt;P&gt;&lt;BR /&gt;You must clean your device, as your passwords and online accounts are now at risk from hackers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;DO NOT enter your password, or log into any accounts until you have followed the below steps.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;To remove any Malware from your device you should&lt;BR /&gt;&lt;BR /&gt;Perform a factory reset as soon as possible. The process for doing this will vary based on the device manufacturer, and guidance &lt;A title="Opens the NCSC.GOV page with advice on deleting data from your device, in another page." href="https://www.ncsc.gov.uk/guidance/buying-selling-second-hand-devices#section_2" target="_blank" rel="noopener"&gt;can be found here&lt;/A&gt;.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Note that if you don't have backups enabled, &lt;STRONG&gt;you will lose data.&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Protect any online accounts&lt;BR /&gt;&lt;BR /&gt;If you have logged in to any accounts or apps using a password since downloading the app, that account password needs to be changed.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;If you have used these same passwords for any other accounts, then these also need to be changed.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;To protect yourself from future scams like this, you should&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Back up your device to ensure that you don't lose important information like photos and documents. The &lt;A title="Opens the CyberAware campaign page in another tab" href="https://www.ncsc.gov.uk/cyberaware/home#action-6" target="_blank" rel="noopener"&gt;CyberAware campaign explains how to do this.&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Only install new apps onto your device from the app store that your manufacturer recommends. For example, most Android devices use Google's Play Store. Some manufacturers, such as Huawei, provide their own app store.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;For Android devices, make sure that &lt;A title="Opens the Google Play Protect service page in another tab" href="https://support.google.com/android/answer/2812853" target="_blank" rel="noopener"&gt;Google's Play Protect service&lt;/A&gt; is enabled if your device supports it. Some Huawei devices &lt;A title="Opens the Huawei virus scanner page in another tab" href="https://consumer.huawei.com/en/support/content/en-us00317497/" target="_blank" rel="noopener"&gt;provide a similar tool&lt;/A&gt; to scan devices for viruses. This will ensure that any malware on your device can be detected and removed.&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you are using a different SMS client to Google messages which does not include spam protection you might want to switch to one with integrated spam protection or install a third-party security solution from Google Play that can filter incoming spam SMS before it hits.&lt;/P&gt;
&lt;P&gt;Users on Google Chrome, Firefox, and certain other web browsers are protected by Google’s Safebrowsing technology that shows a warning when a user browses to a known Flubot distribution site. If you are not using one of these you might want to consider using a browser with Safebrowsing or similar website scanning technologies from other vendors.&lt;/P&gt;
&lt;P&gt;More about Google Safebrowsing can be found &lt;A href="https://safebrowsing.google.com/" target="_self"&gt;Google Safe browsing&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 14 Jul 2021 09:28:23 GMT</pubDate>
    <dc:creator>SeanD</dc:creator>
    <dc:date>2021-07-14T09:28:23Z</dc:date>
    <item>
      <title>Scam Alert! Scam missed delivery texts and Flubot Malware</title>
      <link>https://community.bt.com/t5/Archive-Staging/Scam-Alert-Scam-missed-delivery-texts-and-Flubot-Malware/m-p/2157535#M1193222</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Flubot malware is malicious software that is installed when a victim receives a text message and follows a link, asking them to install a tracking app. This could be informing them of a "new voicemail" received or a ‘missed package delivery’. The tracking app is in fact spyware that steals passwords and other sensitive data and then also sends out multiple text messages to further pass on the malware.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;We will be sending text messages to customers that we have identified as being impacted by this scam, the text messages will link to this community article and we have including the contents of the text below so that you know it is genuine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Flubot.png" style="width: 400px;"&gt;&lt;img src="https://community.bt.com/t5/image/serverpage/image-id/72889i76A866B624D119CE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Flubot.png" alt="Flubot.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;How can I spot this particular scam&lt;/H2&gt;
&lt;P&gt;&lt;SPAN&gt;Victims receive a text message with a link asking them to install an app either for a new voicemail or a ‘missed package delivery’. See examples below for each of these, however, the message and app/link may vary and reference any company.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="ScamDHL.png" style="width: 344px;"&gt;&lt;img src="https://community.bt.com/t5/image/serverpage/image-id/72858iDBCED2BD26AE6CF5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ScamDHL.png" alt="ScamDHL.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="flubot voicemail.png" style="width: 544px;"&gt;&lt;img src="https://community.bt.com/t5/image/serverpage/image-id/73830i85D5DA64C6AB013B/image-size/large?v=v2&amp;amp;px=999" role="button" title="flubot voicemail.png" alt="flubot voicemail.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;What happens to my phone if I install Flubot Malware?&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Flubot malware impersonates other apps on a victim’s phone to steal their banking credentials and other private information. It will also access contact details and send out additional text messages – further spreading the spyware. It can eavesdrop on incoming notifications, read and write SMS’, make calls, and transmit the victims’ entire contact list back to its control centre.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you receive a scam text message:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Do &lt;STRONG&gt;NOT&lt;/STRONG&gt; click the link in the message, and do not install any apps if prompted.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Forward the message to &lt;STRONG&gt;7726&lt;/STRONG&gt;, a free spam-reporting service provided by phone operators.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Delete the message.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have already clicked the link to download the [Flubot] application:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;The &lt;STRONG&gt;NCSC&lt;/STRONG&gt; (&lt;STRONG&gt;National Cyber Security Centre&lt;/STRONG&gt;) have released guidance on what to do if you receive a Flubot SMS. You can find out more &lt;A title="Opens the NCSC website in another tab" href="https://www.ncsc.gov.uk/guidance/flubot-guidance-for-text-message-scam" target="_blank" rel="noopener"&gt;from the NCSC HERE&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;How to protect yourself&lt;/H2&gt;
&lt;P&gt;&lt;BR /&gt;You must clean your device, as your passwords and online accounts are now at risk from hackers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;DO NOT enter your password, or log into any accounts until you have followed the below steps.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;To remove any Malware from your device you should&lt;BR /&gt;&lt;BR /&gt;Perform a factory reset as soon as possible. The process for doing this will vary based on the device manufacturer, and guidance &lt;A title="Opens the NCSC.GOV page with advice on deleting data from your device, in another page." href="https://www.ncsc.gov.uk/guidance/buying-selling-second-hand-devices#section_2" target="_blank" rel="noopener"&gt;can be found here&lt;/A&gt;.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Note that if you don't have backups enabled, &lt;STRONG&gt;you will lose data.&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Protect any online accounts&lt;BR /&gt;&lt;BR /&gt;If you have logged in to any accounts or apps using a password since downloading the app, that account password needs to be changed.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;If you have used these same passwords for any other accounts, then these also need to be changed.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;To protect yourself from future scams like this, you should&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Back up your device to ensure that you don't lose important information like photos and documents. The &lt;A title="Opens the CyberAware campaign page in another tab" href="https://www.ncsc.gov.uk/cyberaware/home#action-6" target="_blank" rel="noopener"&gt;CyberAware campaign explains how to do this.&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Only install new apps onto your device from the app store that your manufacturer recommends. For example, most Android devices use Google's Play Store. Some manufacturers, such as Huawei, provide their own app store.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;For Android devices, make sure that &lt;A title="Opens the Google Play Protect service page in another tab" href="https://support.google.com/android/answer/2812853" target="_blank" rel="noopener"&gt;Google's Play Protect service&lt;/A&gt; is enabled if your device supports it. Some Huawei devices &lt;A title="Opens the Huawei virus scanner page in another tab" href="https://consumer.huawei.com/en/support/content/en-us00317497/" target="_blank" rel="noopener"&gt;provide a similar tool&lt;/A&gt; to scan devices for viruses. This will ensure that any malware on your device can be detected and removed.&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you are using a different SMS client to Google messages which does not include spam protection you might want to switch to one with integrated spam protection or install a third-party security solution from Google Play that can filter incoming spam SMS before it hits.&lt;/P&gt;
&lt;P&gt;Users on Google Chrome, Firefox, and certain other web browsers are protected by Google’s Safebrowsing technology that shows a warning when a user browses to a known Flubot distribution site. If you are not using one of these you might want to consider using a browser with Safebrowsing or similar website scanning technologies from other vendors.&lt;/P&gt;
&lt;P&gt;More about Google Safebrowsing can be found &lt;A href="https://safebrowsing.google.com/" target="_self"&gt;Google Safe browsing&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2021 09:28:23 GMT</pubDate>
      <guid>https://community.bt.com/t5/Archive-Staging/Scam-Alert-Scam-missed-delivery-texts-and-Flubot-Malware/m-p/2157535#M1193222</guid>
      <dc:creator>SeanD</dc:creator>
      <dc:date>2021-07-14T09:28:23Z</dc:date>
    </item>
  </channel>
</rss>

