Roaming Mantis malware was initially found hijacking Internet routers last month to distribute Android banking malware designed to steal users’ login credentials and the secret code for two-factor authentication. The new campaign now support 27 languages to expand its operations to Europe and the Middle East. The criminals behind the campaign have broadened their targets by adding phishing attacks for iOS devices, and cryptocurrency mining script for PC users. The malware is distributed via DNS hijacking, wherein attackers change the DNS settings of wireless routers to redirect traffic to malicious websites controlled by them.
Source: https://thehackernews.com/2018/05/routers-dns-hijacking.html

