[su_heading size=”18″ margin=”40″]New Android virus spreads via fake Google Chrome updates, putting your banking details at risk[/su_heading]
Security researchers have discovered a sophisticated malware targeting Android devices and “disguising” itself as an “innocent” Google Chrome update package .
The scammers distribute the fake update package as a downloadable APK file, which users must execute by clicking on it. If a user is not familiar with the process of updating applications through the Google Play Store, or simply their device does not have the specific market, then it is very easy to fall into the trap.
[su_divider top=”no” text=”Over 750,000 websites hacked in one year!” divider_color=”#9992″ margin=”25″]
Malware requests administrator privileges
[su_divider top=”no” text=”Over 750,000 websites hacked in one year!” divider_color=”#9992″ margin=”25″]
When the user clicks run, the fake Chrome update package asks for administrator privileges. Since this is an update provided by “Google,” most users will probably be willing to grant these privileges. Once the malware obtains root privileges, it begins its malicious activity.
[su_quote]According to security researchers at Zscaler, the malware is very powerful and has a number of advanced features and capabilities. These include scanning devices for any installed antivirus solutions, such as Kaspersky, ESET, Avast, and Dr.Web, and then terminating their operation.[/su_quote]
Additionally, the malware can monitor incoming and outgoing calls, SMS messages, as well as the initiation or termination of calls and the sending of SMS messages.
[su_button url=”https://www.secnews.gr/103478/how-to-use-your-android-smartphone-as-remote-mouse-and-keyboard-for-pc” target=”blank” style=”3d” background=”#43e88b” color=”#ffffff7″ wide=”yes” center=”yes” radius=”0″ icon_color=”#ffffff”]See also: Turn your Android smartphone into a mouse/keyboard for your PC![/su_button]
[su_divider top=”no” text=”Over 750,000 websites hacked in one year!” divider_color=”#9992″ margin=”25″]
Malware steals your credit card information
[su_divider top=”no” text=”Over 750,000 websites hacked in one year!” divider_color=”#9992″ margin=”25″]
The most dangerous behavior observed in the malware is that it displays a pop-up window asking for users' credit card details every time they open the Google Play Store app .
If users make the mistake of filling out the information in the pop-up form, it is sent via SMS to a phone number in Russia. The malware also collects Chrome browsing history and sends it to a C&C server, along with various other information.
Another peculiarity of the malware distribution campaign is the fact that the attackers use a large collection of domains to “host” the malware, which change at regular intervals. All the domains are registered with names such as Android, Google, and Chrome, in order to confuse and deceive users into believing that they have downloaded the malware from the official Google server.
Zscaler experts say the only way to remove the malware is to reset your device to factory settings.

