HomeSecurity500,000 downloads of malicious Pokemon Go take control of Android

500,000 downloads of malicious Pokemon Go take control of Android

Kaspersky Lab experts have discovered a new malicious application in the Google Play store called "Pokemon Go Guide", which is able to exploit root access rights on Android smartphones, using them to install or uninstall applications and display unsolicited advertisements.

The app has been downloaded more than 500,000 times, with at least 6,000 successful infections. Kaspersky Lab has reported the Trojan to Google , and the app has been removed from Google Play. Pokemon Go

The global Pokemon Go phenomenon has led to a growing number of related apps and, inevitably, increased interest from the cybercrime community. Kaspersky Lab’s analysis of the “Pokemon Go Guide” Trojan led to the discovery of malicious code that downloaded rooting malware, securing access to the Android operating system kernel, for the purpose of installing and removing apps, as well as displaying advertisements.

The Trojan includes some interesting features that help it evade detection. For example, it does not launch itself when the victim activates the application. Instead, it waits for the user to install or uninstall another application, and then checks to see if that application is running on a real device or in a virtual machine.

If it is a device, the Trojan waits an additional two hours before starting its malicious activity. Even then, “infection” is not guaranteed. After the Trojan connects to its command server and “uploads” details of the “infected” device, including the country, language, device model, and operating system version, the Trojan will wait for a response. Only when it receives this response will it proceed with further requests and download, install, and implement additional malicious functionality.

This approach means that the control server can block the attack if it wishes, bypassing users it does not want to target, or those it suspects are sandboxes or virtual machines, for example. This provides an additional layer of protection for malware.

Once rooting permissions are activated, the Trojan will install its functions in the device's system folders, silently installing and uninstalling other applications as well as displaying spam ads to the user.

Kaspersky Lab's analysis shows that at least one other version of the malicious Pokemon Go Guide app was available via Google Play in July 2016. In addition, researchers have tracked at least nine other apps infected with the same Trojan and available on the Google Play Store at different times since December 2015.

Kaspersky Lab data shows that there have been over 6,000 successful infections to date, including in Russia, India, and Indonesia. However, since the app is geared towards English-speaking users, people in those geographic regions, and many others, are also likely to have been affected.

 “In the online world, wherever consumers go, cybercriminals will follow. Pokemon Go is no exception. Victims of this Trojan may, at least initially, not even notice the increase in annoying and distracting ads, but the long-term effects of the ‘infection’ could be much more damaging. If you have been a victim, then someone else has entered your phone and is in control of its operating system and everything you do and store on it. Even though the app has now been removed from the app store, there are almost half a million people out there vulnerable to ‘infections’, and we hope this announcement will alert them to take appropriate measures,” said Roman Unuchek, Senior Malware Analyst at Kaspersky Lab.

People who are concerned that they may have come into contact with the Trojan should install a reliable security solution, such as Kaspersky Internet Security for Android, on their device.

If the security scan shows that they are already "infected", the best way to remove the rooting malware is to back up all data and restore the device to factory settings.

Additionally, Kaspersky Lab recommends that users always check that applications are created by a trusted developer, keep their operating system and applications up to date, and do not download anything that looks suspicious or whose origin cannot be verified.

To learn more about the rooting Trojan "Pokemon Go Guide", you can read information on the dedicated website Securelist.com.

All Kaspersky Lab products detect the Trojan named HEUR: Trojan.AndroidOS.Ztorg.ad.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS