Lessons in Prevention and Cure

A User Study of Recovery from Flubot Smartphone Malware

Conference Paper (2023)
Author(s)

Artur Geers (Student TU Delft)

Aaron Yi Ding (TU Delft - Information and Communication Technology)

Carlos H Ganan (TU Delft - Organisation & Governance)

S.E. Parkin (TU Delft - Organisation & Governance)

Research Group
Information and Communication Technology
Copyright
© 2023 Artur Geers, Aaron Yi Ding, C. Hernandez Ganan, S.E. Parkin
DOI related publication
https://doi.org/10.1145/3617072.3617109
More Info
expand_more
Publication Year
2023
Language
English
Copyright
© 2023 Artur Geers, Aaron Yi Ding, C. Hernandez Ganan, S.E. Parkin
Research Group
Information and Communication Technology
Pages (from-to)
126-142
ISBN (electronic)
9798400708145
Reuse Rights

Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons.

Abstract

The smishing-based malware Flubot was taken down in mid-2022, yet there is little understanding of how it directly impacted smartphone users. We engage with customers of a partner Internet Service Provider (ISP), who have suffered a Flubot infection on their smartphones. We surveyed 87 ISP customers who had been notified of a Flubot infection, in the months around and preceding the take-down of Flubot. We found that slightly over half of respondents were unaware of the malware infection before being notified, though many others had suspicions. We also observe that just over half of respondents experienced non-technical harms from the malware, with many experiencing harms before notification and several experiencing unwanted or aggressive activity from users of other infected devices. Many respondents reported not having removed the malware, while some discarded the infected device or stopped using online services in their efforts to be more secure afterwards. We offer recommendations, including that clearer guidance be sought to help users identify a malware infection (and not a focus only on prevention), and support provided for recovery from personal harms caused by mobile malware, as the impacts are not only technical.