A new threat to Android users! If you don't pay attention to this notification...
The spyware known as Morpheus, which spreads through fake system updates and internet outages, puts personal data on Android devices at risk. Experts have issued a warning, stating that WhatsApp accounts are also being targeted.
12punto
Those using the Android operating system are facing a new cyberattack threat that has been spreading rapidly in recent times. New research in the field of cybersecurity reveals that malicious software known as "Morpheus" is deceiving users with fake update notifications. This software, which infiltrates devices, does not just access personal data; it can also cause serious security vulnerabilities in popular messaging applications like WhatsApp.
The primary method used by Morpheus is sending update messages to users that appear to be legitimate. These messages often contain warnings such as "your phone needs to be updated" or "your account is at risk." Users who click the link in the message download a fake update application to their devices, and once installed, the software gains extensive permissions on the device.
The spyware in question specifically abuses Android's accessibility permissions. The installed application gains critical privileges, such as the ability to read content on the screen and interact with other applications. This allows attackers to access a great deal of information on the device without the user's knowledge.
Another notable method used by Morpheus is carried out via internet connection. According to a report by the Italian digital rights organization Osservatorio Nessuno, the internet connection is deliberately and temporarily cut off. Subsequently, an SMS is sent containing the message, "You need to install an update to restore the connection." When the application in the link is downloaded, the spyware becomes active and begins to run secretly.
Once the Morpheus software starts running on the device, it creates a fake WhatsApp login screen and requests the user to perform biometric verification. When the user grants permission, the attackers gain the authority to add a new device to the person's WhatsApp account. In this way, message history, contacts, and private chats can fall into the hands of unauthorized individuals.
Experts state that Morpheus could be used not only to target random users but specifically to target political activists or sensitive groups. Current allegations suggest that organizations linked to international technology companies may be behind this software.
Cybersecurity experts warn Android device users to always download applications only from official app stores. It is reminded that APK files obtained from sources other than Google Play carry a high risk. Furthermore, it is advised to approach SMS messages containing "mandatory updates" that arrive after an internet connection is lost with extreme suspicion. When granting accessibility permissions to applications installed on a phone, the description and developer information should be checked carefully.
In the face of ongoing cyber threats, digital security experts urge users to act consciously and take quick precautions against suspicious activities.