ESET researchers have discovered a new Android malware that spreads through a third-party online store and compromises the device upon the first download the user makes. 
The Turkish CepKutusu is one of the stores that contains malicious downloads, with devices being infected with banking malware that allows hackers to install other applications.
The “Download now” button that appears on third-party stores is what leads to the download of the malware instead of the application the user selected. It should be noted that the hackers have installed a feature that turns the download button into a carrier of the malware only the first time the user attempts to download.
Seven days after downloading the malware, the device no longer carries the virus but clean links. It is likely that the hackers adopted this method to avoid being detected so easily.
When downloading the infected file, the application desired by the user is not installed, but a fake Flash Player which is used to spread the malware.
Although the malicious links have been removed from the app store, researchers have not yet figured out how the malware managed to get in. There are three scenarios in this case:
- An app store was built for the purpose of spreading malware.
- A legitimate app store was made malicious by an employee with bad intentions.
- A legitimate app store fell victim to a remote attacker.
If either of the latter two scenarios is true, researchers hope the attack will not go unnoticed by legitimate stores. User complaints, suspicious server logs, and code changes should be enough evidence for app store managers.
Of course, we should note that the researchers have already contacted the store managers and so far have not received any response.
