Google has notified those affected by Hermit and clarified how the hacking tool is spreading – by clicking a link in a message – in order to warn Android users.
In some cases, we believe the actors worked with the target’s ISP (internet service provider) to disable the target’s mobile data connectivity,. Once disabled, the attacker would send a malicious link via SMS asking the target to install an application to recover their data connectivity.
Collaborating Lookout researchers add that “Hermit tricks users by serving up the legitimate webpages of the brands it impersonates as it kickstarts malicious activities in the background.” While not a zero-click exploit as Pegasus, Hermit can still track what you type, speak, or your whereabouts, and that’s why Google is raising the alarm.