HomeSecurityNew WAPDropper malware infects Android devices for WAP scams

New WAPDropper malware infects Android devices for WAP scams

Security researchers at Check Point have discovered a new Android malware, used in attacks against users in Southeast Asia (primarily). The new malware is called WAPDropper and is currently distributed via malicious apps hosted on third-party app stores.

WAPDropper malware

Check Point said that when the WAPDropper malware infects a user, it begins registering them for premium phone numbers that generate large charges for various types of services.

The result is that infected users receive large bills every month until they unsubscribe from premium services or report the issue to their mobile provider.

This attack is known as “WAP spoofing” and was very popular in the late 2000s and early 2010s. It disappeared with the rise of smartphones, but returned again when malware creators realized that many modern phones and telecommunications support the older WAP standard.

The WAPDropper gang is likely based in Asia

Check Point says that based on the premium numbers used in these attacks, the gang behind the WAPDropper malware likely based in or working with someone in Thailand or Malaysia.

“It's just a numbers game: the more calls made with premium services, the more revenue is generated for those behind the services. Everyone wins, except the victims of the fraud.“.

As for the malware itself, Check Point says that WAPDropper operates with two different modules. The first is a dropper, while the second is the main component that carries out the WAP fraud.

Android

After downloading and installing the malicious apps on a device, the dropper downloads the second component. Thus, the scam begins.

Check Point researchers warn that the malware can later be used to install other malware.

“This type of multi-function “dropper,” which secretly installs itself on a user’s phone and then downloads other malware, was a key infection trend in 2020. These “dropper” trojans accounted for nearly half of the mobile malware attacks carried out between January and July 2020,” said Aviran Hazum, a researcher at Check Point.

"I expect the trend to continue in the new year," he said, and stressed that users should only download apps from the official Google Play Store.

Check Point’s research team said they have so far found the WAPDropper malware in apps named: “af,” “dolok,” an email app called “Email,” and a children’s game called “Awesome Polar Fishing.” Users who have downloaded these apps from stores other than the Play Storeshould remove them from devices as soon as possible.

Source: ZDNet

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS