HomeinetMalware for Android secretly registers for Premium SMS services

Android Malware Secretly Enrolls in Premium SMS Services

The Android.Trojan.MKero.A malware is making a comeback in the land of Android, and this time hackers have found a way to combine it with legitimate apps to bypass Google's Bouncer scanning system.

Android Fake ID Malware

While the malware was first detected in 2014 and was mainly distributed to users through the installation of unsafe applications, Bitdefender reports that in several cases the trojan has been found to be distributed today through the official Google Play Store.

This time, the malware is packaged inside various Android, and when it infects the user's device, it secretly enrolls them in premium SMS services, without requiring any action from the user.

According to BitDefender researchers, the malware uses a clever and sophisticated set of processes that allows it to bypass various security mechanisms in place in premium SMS services to prevent fraud.

First, the malware initiates communication between the device and a C&C server, on which the URL of a premium subscription website is loaded.

Android.Trojan.MKero.A then extracts the CAPTCHA image from the registration form and sends it to antigate.com, a Web service that relies on humans to read the font of image CAPTCHAs. (Isn't that ironic??!)

After receiving the CAPTCHA solution from antigate.com, the malware subscribes the user to the service, and after receiving, parsing, and extracting the confirmation code from an SMS message, it enters the website code and upgrades the user's subscription to a premium service.

The purpose of Android.Trojan.MKero.A is simple. The attacker is likely to participate in various affiliate programs related to the SMS services that the victim user signs up for, and earns money from each user they bring.

“Considering the malware is designed to operate completely silently on the victim’s Android device, its detection and removal is extremely difficult,” says Liviu Arsene from BitDefender, who recommends using a mobile antivirus as well as regularly scanning devices.

Checking your mobile phone bills regularly is also a good idea, as increased costs that came out of nowhere could be a sign of a malware attack.

BitDefender staff detected 7 infected gaming apps in the Google Play Store, which have since been removed.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS