Despite the extensive efforts of Google to keep the Google Play Store “clean” from malicious applications with banking trojans, security researchers reveal that several apps are «escape», and ultimately are available to users.

Recently, security researchers from various European organizations disclosed on Twitter their findings on several banking trojans within the Play Store.
Lukas Stefanko, an ESET antivirus, found 3 of these banking trojans, which were hidden inside apps for zodiac signs and horoscopes. However, what these apps could do was much more, such as intercepting SMS and call logs, sending SMS from the user's device without their consent, downloading and installing applications without the user's consent, and finally stealing credentials from bank accounts thanks to the embedded banking trojans.
Before publishing his findings, Stefanko posted on Twitter, he notified Google, which in turn removed the apps from the Play Store. However, as the apps were available for several days, one of them had over 1000 downloads.
It is important to note that the reason the applications were not recognized as malicious from the start is because they had a very low detection rate. Some of them had only 12 (out of 60) positive results on the VirusTotal platform.
Android Legitimate Spyware with 10M+ installs.
App #Onavo owned by Facebook, is VPN service that collects your:
– mobile traffic
– location
– installed/opened apps
– visited websitesThis app should hide your traffic & increase privacy, instead it collects it. pic.twitter.com/gvhYDhphk2
— Lukas Stefanko (@LukasStefanko) August 31, 2018
Finally, apps that tell your zodiac signs aren't the only ones to be wary of. A VPN app from Onavo (owned by Facebook) was collecting data from users such as location, pages they visit, apps they use, and more, which is something you wouldn't expect from an app that's meant to keep users anonymous.
