
A new malware, discovered by security researchers, targets Android, replacing legitimate apps with fake copies of them and promoting its own ads or altering valid ads.
So far, the malware, found in unofficial app stores, has infected around 25 million devices and the researchers who discovered it have named it "Agent Smith.".
Victims are usually lured in by photo apps, games, or adult apps that come with malware. Once downloaded onto their device, the apps install Agent Smith.
The malware attempts to hide its presence by disguising itself as a Google – Google Updater, Google Update for U or “com.google.vending”, and hiding its icon from the user.
The malware then searches for applications on the device, which are also on a list that is either hardcoded or downloaded from the command and control server (C2).
Once it finds the right app, Agent Smith extracts the base APK and promotes a malicious ad module. It then replaces the original app with the fake one.
To complete the update installation process, the malware exploits the Janus vulnerability, which allows bypassing an application's verifications and adding arbitrary code to it.
Ultimately, what the user will see is a seemingly innocent advertisement. Moreover, even the ads in the original application bring profits to the malicious actors, as the malware can change them and use them to its advantage.
Check Point researchers have found that Agent Smith is only used to push ads, but they say that operators can also use it for more malicious purposes, such as stealing banking credentials.
The malware was discovered on popular third-party app stores such as 9Apps, which primarily caters to users in Indian, Arab, and Indonesian countries. However, incidents were also observed on devices in Saudi Arabia (245k), Australia (141k), the United Kingdom (137k), and the United States (303k).
The list of Android apps affected by the malware includes:
- com.whatsapp
- com.lenovo.anyshare.gps
- com.mxtech.videoplayer.ad
- com.jio.jioplay.tv
- com.jio.media.jiobeats
- com.jiochat.jiochatapp
- com.jio.join
- com.good.gamecollection
- com.opera.mini.native
- in.startv.hotstar
- com.meitu.beautyplusme
- com.domobile.applock
- com.touchtype.swiftkey
- com.flipkart.android
- cn.xender
- com.eterno
- com.truecaller
The malware is not limited to just infecting one application, but replaces any and all applications on its target list.
Between May 2018 and April 2019, operators began testing the ability to compromise legitimate applications and advance the campaign through updates, as well as by moving infrastructure to AWS cloud services.
It appears that the creators of Agent Smith were also trying to make their way to the official Android store, as researchers found 11 apps in the Google Play Storethat included “a malicious but dormant SDK related to the ‘Agent Smith’ agent.” The researchers immediately notified Google and the malicious apps were removed.
