An Android app has managed to infect around 1 million users of the platform. The app is available from Google's Play Store and, as researchers say, is almost impossible to uninstall. It's called Brain Test, and it's a simple IQ test tool, and it contains a combination of malware.
According to Check Point's research team, the app was first detected by the company's threat prevention system on a Nexus 5 device.
Because its owner, after receiving the malware notification, was unable to uninstall the malicious application, Check Point decided to take a closer look at the source of the infection.
So by reverse-engineering the Brain Test app, researchers discovered a very well-designed malware that allowed attackers to install third-party applications on the victim's phone, after first gaining root access to the device.
Digging deeper into the matter, researchers discovered a complex system that allowed the malware to evade detection by Google's Bouncer, an automated system for checking apps uploaded to the Google Play Store.
This is how Brain Test found its way onto its victims' devices. The app would run a time bomb function every time the user opened it for the first time.
This function ran after a 20-second delay, once every 2 hours, and slowly downloaded and decompressed the necessary code to gain root privileges on the victim's device.
Once it managed to gain root, the Brain Test application could install another application, brother.apk, which checked if the first one was working properly, and if it was removed by the user, it would reinstall it.
