create account

HIGHRISE | Wikileaks Reveals Android Malware That Steals And Redirects Data Via SMS by fortified

View this thread on: hive.blogpeakd.comecency.com
· @fortified ·
$50.67
HIGHRISE | Wikileaks Reveals Android Malware That Steals And Redirects Data Via SMS
### <center> An SMS Proxy App That Sends Stolen Data Between Target and Listening Post. </center>
<center> </center>
<center> ![STEEM-header-High.jpg](https://steemitimages.com/DQmNgmCnT2bZ7jxLFKrBxB61B9ivjbVAQQgWjgmoMtjot6L/STEEM-header-High.jpg) </center>
<center> </center>

Today WikiLeaks published further documents from their Vault 7 CIA archive. Developed in 2013 HighRise is malware designed for Android mobile devices running Android 4.0 - 4.3. The HighRise malware is hidden in an application called **TideCheck** and once installed allows the operator to redirect SMS messages from a targets device. 

<center> ![Highrise-Tidecheck.jpg](https://steemitimages.com/DQmXTqa6S6a6ed7fs7RMtEsErCmtMMed6EYvfriU14h4EvL/Highrise-Tidecheck.jpg) </center>

HighRise is a SMS proxy that provides greater separation between devices in the field (“targets”) and the listening post by proxying "incoming" and "outgoing" SMS messages to an internet listening post. One use for it would be to intercept SMS's messages generated by Indicator of compromise (IoC) tools that use SMS messages for communication. 


> [Indicator of compromise (IOC)](https://en.wikipedia.org/wiki/Indicator_of_compromise) — in computer forensics is an artifact observed on a network or in an operating system that with high confidence indicates a computer intrusion.
> 
> Typical IOCs are virus signatures and IP addresses, MD5 hashes of malware files or URLs or domain names of botnet command and control servers. After IOCs have been identified in a process of incident response and computer forensics, they can be used for early detection of future attack attempts using intrusion detection systems and antivirus software.

### <center> Uncovering Indicators of Compromise (IoC) Using PowerShell, Event Logs and a Traditional Monitoring Tool - [SANS Institute](https://www.sans.org/reading-room/whitepapers/critical/uncovering-indicators-compromise-ioc-powershell-event-logs-traditional-monitorin-36352) - </center>

</b>
</b>
<div class="center"><center><img src="https://steemitimages.com/DQmUf9hN6MtLAtB27zRemyg8cqWVdLSB1S2UZRkGkQ59DXE/highrise-flow.jpg" /><br/><em><sup>Highrise provides a communications channel between the HighRise field operator and the listening post with a TLS/SSL secured internet communication.</sup></em></center></div>


</b>
</b>
This malware is slightly different than most other computer viruses as it collects internet data from internet traffic and sends it via the SMS network which is a separate network all together. using this tewqunique allows the operator to keep a greater distance from the target. The HighRise manual shows that the tool must be manually downloaded, installed and activated on the "target" device. This means that the attacker either needs to gain physical access to the smartphone or they need to trick the "target" into installing it themselves. 

Manually activating the app requires the user to download and open the TideCheck app. Next they would need to “Initialize” it from the options menu by entering “inshallah” as the password (Arabic for “God willing”). After being activation and the device rebooted it will automatically stay running in the background.


<center> https://steemitimages.com/DQmRkdUg3ERdH12J2dCo2aqAh3Gy48R9Fzy5ELd1jfB1PMM/highrise-app.jpg </center>



The document states in the release logs that this malware was first created in December 2013. Since then Google have upgraded all the Android versions so I doubt this malware still works today. But we all know these things can be cauaght, copied and manipulated for other nefarious activities as we see has happened in this article below.


### <center> Android Malware About to Get Worse: GM Bot Source Code Leaked - [Security Intelligence](https://securityintelligence.com/android-malware-about-to-get-worse-gm-bot-source-code-leaked/) - February 19, 2016 </center>
> IBM X-Force threat intelligence has found that the source code for Android malware GM Bot was leaked on an underground board in December 2015. The leaked code for the malware and its control panel have since been further propagated to different users, making this popular Android Trojan accessible to fraudsters for free, with a tutorial and server-side installation instructions to match.

### <center> GM Bot will be available to cybercriminals who can recompile the code, create new variants and use the leaked sources to build, sell or deploy this malware for fraud scenarios. </center>


</b>
<center> </center>
----

<center> </center>
<center> http://i.imgur.com/7SGKH70.jpg </center>
### <center> FORTIFIED </center>
<center> **[Steemit](https://steemit.com/@fortified)  |  [Gab](https://gab.ai/fortified)** </center>
# <center> **THANK YOU FOR READING** </center>
<center> <sup> - If You Would Like To Help Me Make More Great Original Content Please Consider Upvoting and Re-Steeming - </sup> </center>
👍  , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , ,
properties (23)
authorfortified
permlinkhighrise-or-wikileaks-reveals-android-malware-that-steals-and-redirects-data-via-sms
categorywikileaks
json_metadata{"tags":["wikileaks","vault7","security","news","freedom"],"image":["https://steemitimages.com/DQmNgmCnT2bZ7jxLFKrBxB61B9ivjbVAQQgWjgmoMtjot6L/STEEM-header-High.jpg","https://steemitimages.com/DQmXTqa6S6a6ed7fs7RMtEsErCmtMMed6EYvfriU14h4EvL/Highrise-Tidecheck.jpg","https://steemitimages.com/DQmUf9hN6MtLAtB27zRemyg8cqWVdLSB1S2UZRkGkQ59DXE/highrise-flow.jpg","https://steemitimages.com/DQmRkdUg3ERdH12J2dCo2aqAh3Gy48R9Fzy5ELd1jfB1PMM/highrise-app.jpg","http://i.imgur.com/7SGKH70.jpg"],"links":["https://en.wikipedia.org/wiki/Indicator_of_compromise","https://www.sans.org/reading-room/whitepapers/critical/uncovering-indicators-compromise-ioc-powershell-event-logs-traditional-monitorin-36352","https://securityintelligence.com/android-malware-about-to-get-worse-gm-bot-source-code-leaked/","https://steemit.com/@fortified","https://gab.ai/fortified"],"app":"steemit/0.1","format":"markdown"}
created2017-07-13 19:31:15
last_update2017-07-13 19:31:15
depth0
children12
last_payout2017-07-20 19:31:15
cashout_time1969-12-31 23:59:59
total_payout_value38.360 HBD
curator_payout_value12.314 HBD
pending_payout_value0.000 HBD
promoted0.004 HBD
body_length4,899
author_reputation38,014,334,194,654
root_title"HIGHRISE | Wikileaks Reveals Android Malware That Steals And Redirects Data Via SMS"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id8,374,889
net_rshares12,278,671,598,364
author_curate_reward""
vote details (32)
@discordia ·
<p>This post gets a 0.18 % upvote thanks to @fortified - Hail Eris !</p>
properties (22)
authordiscordia
permlinkre-fortified-highrise-or-wikileaks-reveals-android-malware-that-steals-and-redirects-data-via-sms-20170713t204448586z
categorywikileaks
json_metadata{"tags":["wikileaks"],"app":"drotto/0.0.1"}
created2017-07-13 20:44:51
last_update2017-07-13 20:44:51
depth1
children0
last_payout2017-07-20 20:44:51
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length73
author_reputation1,655,947,713,289
root_title"HIGHRISE | Wikileaks Reveals Android Malware That Steals And Redirects Data Via SMS"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id8,381,324
net_rshares0
@fortified ·
I even made my infographic this time...
https://steemitimages.com/0x0/https://steemitimages.com/DQmUf9hN6MtLAtB27zRemyg8cqWVdLSB1S2UZRkGkQ59DXE/highrise-flow.jpg
👍  
properties (23)
authorfortified
permlinkre-fortified-highrise-or-wikileaks-reveals-android-malware-that-steals-and-redirects-data-via-sms-20170713t220615100z
categorywikileaks
json_metadata{"tags":["wikileaks"],"image":["https://steemitimages.com/0x0/https://steemitimages.com/DQmUf9hN6MtLAtB27zRemyg8cqWVdLSB1S2UZRkGkQ59DXE/highrise-flow.jpg"],"app":"steemit/0.1"}
created2017-07-13 22:06:21
last_update2017-07-13 22:06:21
depth1
children0
last_payout2017-07-20 22:06:21
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length161
author_reputation38,014,334,194,654
root_title"HIGHRISE | Wikileaks Reveals Android Malware That Steals And Redirects Data Via SMS"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id8,387,896
net_rshares0
author_curate_reward""
vote details (1)
@jwolf ·
thanks for info man!
properties (22)
authorjwolf
permlinkre-fortified-highrise-or-wikileaks-reveals-android-malware-that-steals-and-redirects-data-via-sms-20170713t220307843z
categorywikileaks
json_metadata{"tags":["wikileaks"],"app":"steemit/0.1"}
created2017-07-13 22:03:42
last_update2017-07-13 22:03:42
depth1
children0
last_payout2017-07-20 22:03:42
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length20
author_reputation124,912,730,383,826
root_title"HIGHRISE | Wikileaks Reveals Android Malware That Steals And Redirects Data Via SMS"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id8,387,686
net_rshares0
@randowhale ·
This post received a 1.6% upvote from @randowhale thanks to @fortified!  For more information, [click here](https://steemit.com/steemit/@randowhale/introducing-randowhale-will-you-get-the-100-vote-give-it-a-shot)!
properties (22)
authorrandowhale
permlinkre-highrise-or-wikileaks-reveals-android-malware-that-steals-and-redirects-data-via-sms-20170713t200848
categorywikileaks
json_metadata"{"format": "markdown", "app": "randowhale/0.1"}"
created2017-07-13 20:08:48
last_update2017-07-13 20:08:48
depth1
children0
last_payout2017-07-20 20:08:48
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length213
author_reputation47,657,457,485,459
root_title"HIGHRISE | Wikileaks Reveals Android Malware That Steals And Redirects Data Via SMS"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id8,378,342
net_rshares0
@thelightreports ·
Some elements of the CIA are soooooo dirty- but they're in the process of being taken out
properties (22)
authorthelightreports
permlinkre-fortified-highrise-or-wikileaks-reveals-android-malware-that-steals-and-redirects-data-via-sms-20170714t030557938z
categorywikileaks
json_metadata{"tags":["wikileaks"],"app":"steemit/0.1"}
created2017-07-14 03:05:57
last_update2017-07-14 03:05:57
depth1
children1
last_payout2017-07-21 03:05:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length89
author_reputation22,548,135,605,018
root_title"HIGHRISE | Wikileaks Reveals Android Malware That Steals And Redirects Data Via SMS"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id8,409,285
net_rshares0
@fortified ·
Yes and it's wonderful to watch.
properties (22)
authorfortified
permlinkre-thelightreports-re-fortified-highrise-or-wikileaks-reveals-android-malware-that-steals-and-redirects-data-via-sms-20170714t034719500z
categorywikileaks
json_metadata{"tags":["wikileaks"],"app":"steemit/0.1"}
created2017-07-14 03:47:24
last_update2017-07-14 03:47:24
depth2
children0
last_payout2017-07-21 03:47:24
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length32
author_reputation38,014,334,194,654
root_title"HIGHRISE | Wikileaks Reveals Android Malware That Steals And Redirects Data Via SMS"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id8,412,217
net_rshares0
@valued-customer ·
Better late than never.  This is why I bricked my old phone, which was KitKat that the vendor had promised to upgrade to lollipop, but didn't.  I did, and hadda buy a new phone lol.

I don't mean this specific 'sploit, but rather the improved security that comes with newer Android.

Thanks for this post!  upvoted and resteemed
properties (22)
authorvalued-customer
permlinkre-fortified-highrise-or-wikileaks-reveals-android-malware-that-steals-and-redirects-data-via-sms-20170714t044501052z
categorywikileaks
json_metadata{"tags":["wikileaks"],"app":"steemit/0.1"}
created2017-07-14 04:45:03
last_update2017-07-14 04:45:03
depth1
children3
last_payout2017-07-21 04:45:03
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length328
author_reputation361,270,498,588,486
root_title"HIGHRISE | Wikileaks Reveals Android Malware That Steals And Redirects Data Via SMS"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id8,416,132
net_rshares0
@fortified ·
Thank you. 

Yes anytime I buy a new phone the first thing I do is root it.
properties (22)
authorfortified
permlinkre-valued-customer-re-fortified-highrise-or-wikileaks-reveals-android-malware-that-steals-and-redirects-data-via-sms-20170714t050226800z
categorywikileaks
json_metadata{"tags":["wikileaks"],"app":"steemit/0.1"}
created2017-07-14 05:02:30
last_update2017-07-14 05:02:30
depth2
children2
last_payout2017-07-21 05:02:30
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length75
author_reputation38,014,334,194,654
root_title"HIGHRISE | Wikileaks Reveals Android Malware That Steals And Redirects Data Via SMS"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id8,417,233
net_rshares0
@scooter77 ·
??? @fortified you do know what that means in Australia don't you?
👍  ,
properties (23)
authorscooter77
permlinkre-fortified-re-valued-customer-re-fortified-highrise-or-wikileaks-reveals-android-malware-that-steals-and-redirects-data-via-sms-20170714t092801386z
categorywikileaks
json_metadata{"tags":["wikileaks"],"users":["fortified"],"app":"steemit/0.1"}
created2017-07-14 09:28:03
last_update2017-07-14 09:28:03
depth3
children1
last_payout2017-07-21 09:28:03
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length66
author_reputation76,673,123,521,581
root_title"HIGHRISE | Wikileaks Reveals Android Malware That Steals And Redirects Data Via SMS"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id8,437,045
net_rshares1,233,172,154
author_curate_reward""
vote details (2)
@viewangle ·
$0.03
Woke stuff as always! Would have been nice if this stuff got leaked a bit sooner.
👍  
properties (23)
authorviewangle
permlinkre-fortified-highrise-or-wikileaks-reveals-android-malware-that-steals-and-redirects-data-via-sms-20170713t193721511z
categorywikileaks
json_metadata{"tags":["wikileaks"],"app":"steemit/0.1"}
created2017-07-13 19:37:21
last_update2017-07-13 19:37:21
depth1
children1
last_payout2017-07-20 19:37:21
cashout_time1969-12-31 23:59:59
total_payout_value0.020 HBD
curator_payout_value0.005 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length81
author_reputation18,695,174,889
root_title"HIGHRISE | Wikileaks Reveals Android Malware That Steals And Redirects Data Via SMS"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id8,375,484
net_rshares6,738,865,994
author_curate_reward""
vote details (1)
@www.oye.news ·
Yes, many questions to ask about timing and the WikiLeaks narrative... 

https://steemit.com/wikileaks/@www.oye.news/breaking-news-assange-and-wikileaks-a-covert-intelligence-operation-uncovered
👍  
properties (23)
authorwww.oye.news
permlinkre-viewangle-re-fortified-highrise-or-wikileaks-reveals-android-malware-that-steals-and-redirects-data-via-sms-20170714t024955914z
categorywikileaks
json_metadata{"tags":["wikileaks"],"links":["https://steemit.com/wikileaks/@www.oye.news/breaking-news-assange-and-wikileaks-a-covert-intelligence-operation-uncovered"],"app":"steemit/0.1"}
created2017-07-14 02:50:00
last_update2017-07-14 02:50:00
depth2
children0
last_payout2017-07-21 02:50:00
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length194
author_reputation3,421,113,425,336
root_title"HIGHRISE | Wikileaks Reveals Android Malware That Steals And Redirects Data Via SMS"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id8,408,158
net_rshares638,942,583
author_curate_reward""
vote details (1)