Android is the most popular mobile operating system in the world. However, its popularity also makes it a target for hackers. Users should be constantly vigilant to avoid falling victim to an attack.
Google has taken some steps to protect Android users. One of them is the removal of 50 malicious apps that were available on the Google Play Store and had been downloaded by about 30 million users. The malicious apps were related to fitness, photo editing, and games.
For example, the Google Play Store had three “selfie beauty” apps, Pro Selfie Beauty Camera, Selfie Beauty Camera Pro, and Pretty Beauty Camera 2019, which were actually used by hackers to spread adware and spyware.
All three apps were very popular with over 500,000 downloads. Pretty Beauty Camera 2019 was used by 1 million users (most of whom were Android users in India).
Some details about this malware come from malware analysts working at apklab.io. Launched in February, apklab.io is a platform owned by Avast. Employees analyze samples from 145 million Android mobile devices worldwide.
Nikolaos Chrysaidos, head of security at Avast, provided more details about the applications.
The 50 apps were very popular. Downloads ranged from 5,000 to 5 million. Most of them spread adware, which constantly displayed ads and encouraged users to install other apps.
The adware applications were bundled with third-party Android libraries, which were used to bypass background service restrictions found in newer versions of Android.
Researchers discovered that applications using these libraries were draining the device's battery and also making it slower.
Regarding “selfie beauty” apps, Mr. Chrysaidos explained that the goal of these apps is to edit a selfie photo. However, almost all of these apps are designed to spread adware, which constantly displays ads and leads users to malicious pages and spyware, which steals data.
One of the unique features of these apps is that they are difficult to uninstall. Their icons don't always appear on the Android screen, making it difficult for a user to delete them. In the meantime, hackers can display more ads and make more money.
Analysts also found that the apps could make phone calls, record conversations, change network status, read memory, and more.
How was the malware discovered?
Mr. Chrysaidos said that the company collects file samples from partners, customers and third-party manufacturers and places them on the apklab.io platform. If a sample looks suspicious, then special processing is performed.
Essentially, the team finds malware and isolates it. These remain in the aklab.io database, which currently contains around 6.5 million malware samples.
In addition to adware and spyware, hackers also carry out ransomware. In the past, hackers used to lock the victim's phone and demand money to unlock it. Lately, ransomware has taken the form of cryptomining. Hackers use the device to mine cryptocurrency and steal the victim's money.
Finally, another category of malware that has been used recently are banking trojans. Their goal is to steal banking and credit card information on the victim's device.
Unfortunately, hackers will continue to exploit the Google Play Store to install malware on users, so we should all be very careful about the apps we download.
