Flubot malware is malicious software that is installed when a victim receives a text message and follows a link, asking them to install a tracking app. This could be informing them of a "new voicemail" received or a ‘missed package delivery’. The tracking app is in fact spyware that steals passwords and other sensitive data and then also sends out multiple text messages to further pass on the malware.
We will be sending text messages to customers that we have identified as being impacted by this scam, the text messages will link to this community article and we have including the contents of the text below so that you know it is genuine.
Victims receive a text message with a link asking them to install an app either for a new voicemail or a ‘missed package delivery’. See examples below for each of these, however, the message and app/link may vary and reference any company.
The Flubot malware impersonates other apps on a victim’s phone to steal their banking credentials and other private information. It will also access contact details and send out additional text messages – further spreading the spyware. It can eavesdrop on incoming notifications, read and write SMS’, make calls, and transmit the victims’ entire contact list back to its control centre.
If you receive a scam text message:
If you have already clicked the link to download the [Flubot] application:
The NCSC (National Cyber Security Centre) have released guidance on what to do if you receive a Flubot SMS. You can find out more from the NCSC HERE.
You must clean your device, as your passwords and online accounts are now at risk from hackers.
If you are using a different SMS client to Google messages which does not include spam protection you might want to switch to one with integrated spam protection or install a third-party security solution from Google Play that can filter incoming spam SMS before it hits.
Users on Google Chrome, Firefox, and certain other web browsers are protected by Google’s Safebrowsing technology that shows a warning when a user browses to a known Flubot distribution site. If you are not using one of these you might want to consider using a browser with Safebrowsing or similar website scanning technologies from other vendors.
More about Google Safebrowsing can be found Google Safe browsing