HomeSecurityGoogle Play Store: 17 more apps with Joker malware removed

Google Play Store: 17 more apps with Joker malware removed

Google has removed 17 Android apps from the Play Store more that were infected with the Joker malware and were discovered by security researchers at Zscaler .

Play Store

"This spyware is designed to steal SMS messages, contact lists, and device information, while also secretly enrolling the victim in premium WAP (wireless application protocol) services," said researcher Viral Gandhi.

The 17 malicious apps uploaded to the Play Store had a total of over 120,000 downloads.

The names of the 17 applications are:

  • All Good PDF Scanner
  • Mint Leaf Message-Your Private Message
  • Unique Keyboard – Fancy Fonts & Free Emoticons
  • Tangram App Lock
  • Direct Messenger
  • Private SMS
  • One Sentence Translator – Multifunctional Translator
  • Photo Collage Maker
  • Meticulous Scanner
  • Desire Translate
  • Talent Photo Editor – Blur focus
  • Care Message
  • Part Message
  • Paper Document Scanner
  • Blue Scanner
  • Hummingbird PDF Converter – Photo to PDF
  • All Good PDF Scanner

Once Google was notified of the malicious apps, it followed the prescribed procedures. It removed the apps from the Play Store and used the Play Protect service to disable the apps on infected devices . However, users must also remove the apps from their devices.

Joker malware Google

Many apps with Joker malware have been found on the Play Store

This is the third time Google has removed apps infected with Joker malware.

Earlier this month, the company removed six more such apps, which had been reported by security at Pradeo.

In July, Google was notified of similar apps by security researchers at Anquanke. This batch had been active since March and managed to infect millions of devices.

In most cases, these apps manage to bypass Google's defenses and reach the Play Store by using a technique called "droppers," where the victim's device is infected in multiple stages. The technique is quite simple, but it manages to bypass Google's obstacles.

Initially, malware creators clone the functionality of a legitimate app and upload it to the Play Store. This app is fully functional, requests many permissions to access sensitive data, but does not perform any malicious activities when it is first run.

Malicious actions begin after hours or even days, so Google's security scans do not pick up the malicious code, allowing the app to pass through the Play Store.

But malicious apps eventually download and install other components or applications on the device. These components contain Joker malware or other malicious software.

The Joker malware, which Google internally calls “Bread,” relies heavily on the dropper technique. This is how it has managed to infiltrate the Play Store multiple times, perhaps more times than any other malware.

In January, Google published a blog post describing the Joker malware as one of the most persistent and advanced threats it has faced in recent years. Google said its security teams have removed more than 1,700 apps from the Play Store since 2017. But apps with Joker are widespread and have also been reported in Android third-party

Anquanke researchers said they have identified more than 13,000 Joker malware samples since the malware was discovered in December 2016.

Protecting against Joker is difficult, but users can protect themselves to some extent by being careful about the apps they download. For example, they should avoid apps that request access to a lot of data and look at other users' ratings.

Other malicious applications

According to ZDNet, Bitdefender reported a group of malicious apps to Google's security team. Some of these apps are still available on the Play Store. The researchers did not mention the names of the apps, only the accounts developer from which they were uploaded to the Play Store. Users who have installed apps from these developers should remove them immediately.

  • Nouvette
  • Piast
  • imirova91
  • Progster
  • StokeGroove
  • VolkavStune
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS