HomeSecurityGoogle Play: Malware was hiding using motion sensors

Google Play: Malware was hiding using motion sensors

on the Google Play that try tricks to avoid detection. Specifically, they use sensor motion input on an infected device before installing a powerful banking trojan to ensure it doesn't load on emulators, which researchers use to detect the attacks.

Google

The reasoning behind this is that the sensors are real end-user devices that will record movement as they are used. In contrast, the emulators used by security researchers and possibly Google employees do not use sensors. Recently, two apps were discovered on Google Play with Anubis banking malware on infected devices, which would only activate the payload whenever movement was detected. Otherwise, the trojan would dominate.

Also, a security company found that two apps were using a dropper to trigger motion. The first was BatterySaverMobi, which had 5,000 downloads, and the second was Currency Converter, which had an unknown number of downloads. Of course, once Google learned that the malware, they were immediately removed.

These malicious applications not only use motion detection to hide themselves but also other methods.

For example, one of the apps that Anubis installed on a device, its dropper used requests and responses via Twitter and Telegram to place the command and control the server. It then registered with the C&C server and checked for commands with an HTTP POST request. If the server responded to the app with an APK command and pasted the URL, then the Anubis payload would be moved to the background. The dropper would then attempt to trick users into installing the app, using the fake system update as shown below.

Google Play: Malware was hiding using motion sensors

Once Anubis was installed, it used a built-in keylogger that could steal user account credentials. The malware could also gain access to credentials by taking screenshots of the infected user's screen.

Specifically, the data showed that the latest version of Anubis was distributed in 93 different countries and targeted users using financial apps, so that attackers could exploit financial information to their advantage. If Anubis is successful, the hacker gains access to contact lists as well as location. It can also access and record audio, send messages, and make calls.

Taking all this into account, we conclude that unfortunately attackers are improving the quality of malicious Android applications more and more. Secondly, Android users should think more carefully before downloading applications from Google Play and be aware of the malicious activities that are observed. What we recommend for Android users is to always be careful and prefer applications from recognized developers.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS