Android Users Hit with TangleBot Malware Disguised as COVID Messages

Tanglebot Malware Android Featured

It’s not surprising that the malware industry is using the pandemic to spread its own viruses. Both COVID and malware are infecting people in exponential numbers. The newest malware, TangleBot, targets Android users by pretending to be helpful messages about COVID. It’s one virus using another.

Cloudmark Warns Android Users About TangleBot Malware

The TangleBot malware hits Android devices in the U.S. and Canada with SMS messages about COVID. If the messages are successful at spreading the malware, it can send more text messages from the infected device, make and block phone calls, and perhaps the most frightening, overlay screens over apps.

Security firm Cloudmark discovered one fake message that read, “New regulations about COVID-19 in your region. Read here.” Another said, “You have received the appointment for the 3rd dose. For more information, visit …” Both are said to be sent from TangleBot.

Tanglebot Malware Android Phone

The malware was named TangleBot because there are several levels of tangling up your device. It can even steal your financial credentials with the screen overlay function. This information can then potentially end up on the dark web.

This is cybercriminals taking advantage of a situation where people are vulnerable. People are either unsure about the virus or unsure about the methods to protect themselves. It makes them more likely to click on unsafe information. Sure, it’s advantageous for hackers, but it just makes it even more unethical, if that’s at all possible.

If you click on one of these malicious messages, it informs you that Adobe FlashPlayer needs to be updated. And, of course, FlashPlayer is long gone and certainly not being updated anymore. Instead of a FlashPlayer update, TangleBot is downloaded and installed.

This is where the TangleBot malware takes over your Android device, controlling your messages, phone, camera, screen, GPS, microphone, and more. Along with overlay screens covering your apps, it can also set up ways to watch the activity on your device.

How to Avoid Getting the TangleBot Malware

Smartphones give hackers an easy way to spread their phishing attacks, as we have our phones with us at all times and are likely less safe with them than our computers. We use them for so many social situations that spreading a phishing attack through social means, such as SMS messages, just becomes all too easy.

Tanglebot Malware Android Virus

To avoid getting COVID, you need to socially distance, wear a mask, and get the vaccine. Cloudmark suggests doing the following to avoid getting TangleBot:

  • Be wary of suspicious text messages
  • Protect your mobile number
  • Access links directly
  • Report SMS phishing and spam messages
  • Take care when installing apps
  • Avoid responding to unknown texts
  • Only install apps from legitimate app stores

To protect yourself further, check out our review of Emsisoft Anti-Malware, available for Windows and Android. Also check out Microsoft’s warning about the spike in cyberattacks of COVID data.

Subscribe to our newsletter!

Our latest tutorials delivered straight to your inbox

Laura Tucker Avatar

Read next

In 2016, archaeologists dated two rings of snapped stalagmites in France’s Bruniquel Cave to 176,500 years ago, evidence that Neanderthals had walked 336 metres into darkness with fire and built architecture deep underground long before modern humans reached Europe
Otto von Bismarck was 74 when Germany adopted the world’s first national old-age social insurance program in 1889, setting the pension age at 70 after years of fighting socialists with bans, laws, and a promise few workers would live long enough to use
When cosmonaut Valeri Polyakov stepped out of his Soyuz capsule in March 1995 after 437 consecutive days aboard Mir, doctors recorded him at several centimetres above his pre-flight height, and his spine had become so unaccustomed to gravity that the recovery team carried him to a chair rather than risk the compression of letting him walk.
When Bell Labs engineer Karl Jansky pointed a rotating antenna at the sky in 1932 looking for sources of transatlantic radio static, he kept picking up a faint hiss that peaked every 23 hours and 56 minutes, and he eventually realized he had become the first human to hear the center of the Milky Way.
When Harvard astronomer Cecilia Payne submitted her 1925 doctoral thesis arguing that the Sun was made almost entirely of hydrogen, the field’s senior figure Henry Norris Russell talked her into adding a line calling the result ‘almost certainly not real,’ and then published the same conclusion himself four years later to widespread acclaim.
When seismic waves from the Chicxulub impact reached what is now North Dakota roughly ten minutes after the asteroid struck, they appear to have triggered a ten-metre standing wave in an inland river that flung fish onto the bank and buried them under glass beads still falling from the sky.
When survivors near Lake Nyos woke on the morning of 22 August 1986, the cattle were dead in the fields, the birds had fallen out of the trees, and 1,746 of their neighbours were lying where they had stood the night before, with no fire, no flood, and no wound to explain it.
In October 2002, a Russian scientist named Dimitri Malashenkov stood up at a space conference in Houston and quietly explained that the dog Laika, whom the Soviet Union had publicly mourned as a heroic week-long orbiter in 1957, had actually died of heat and panic within about five hours of launch.