The method used in the attacks was leaked during the Hacking Team data breach.
It could look identical to the standard app but have extra functionality.
Only if the infected link is clicked by the user does the attack get activated.
All major operating systems like Android and iOS are affected by the method.
They are versions of the standard app with extra functionality to exfiltrate sensitive information to remote servers.
We have found these applications in use in the wild.
Currently, the number of undisclosed victims of the attacks are small.
Source: BusinessInsider
Read More
source: www.techworm.net