HomeSecurityHackers lure Android users with fake antivirus and infect them with malware

Hackers lure Android users with fake antivirus and infect them with malware

A new series of malicious Android apps have been spotted that use well-known brand names to lure potential victims into a false sense of security, a fake antivirus. According to researchers at security firm Bitdefender, hackers are distributing malware-rigged versions of several popular apps, including the VLC media player, Kaspersky antivirus, and apps from FedEx and DHL.

Once installed, the malicious apps infect devices with either Teabot or Flubot, two banking trojans first discovered earlier this year.

Read also: iPhone: How to check if it is infected with malware and how to remove it?

According to reports, Teabot has the ability to monitor messages and Google authentication codes, record keystrokes on a device, perform overlay attacks, and, in some cases, gain full control of the infected device.

Android - fake antivirus - malware
Hackers lure Android users with fake antivirus and infect them with malware

On the other hand, Flubot is not as sophisticated, but it is still equipped with tools that allow it to steal banking credentials, messages, and other types of personal data from a device. This malware also exhibits “worm-like behavior” and spreads via malicious SMS messages sent from infected devices.

See also: Windows and Linux devices are attacked by a new cryptomining worm

Although malicious apps are known to occasionally make their way onto the Google Play Store, the majority of threats can be avoided by only downloading content from trusted sources. This is certainly true of the threats discovered by Bitdefender, which are not hosted on Google Play and can only be sideloaded.

Android fake antivirus malware
Hackers lure Android users with fake antivirus and infect them with malware

Specifically, Bitdefender stated the following: “Distributing malware to Android devices is not easy, as the official store can usually prevent these types of apps from reaching users. But one of Android’s biggest strengths, the ability to sideload apps from unofficial sources, is also a weakness. Using a combination of tricks to convince users to install apps outside the official store, hackers distribute the majority of their malware via sideloading.”

Proposal: 100 million Android users' data exposed

hackers
Hackers lure Android users with fake antivirus and infect them with malware

Furthermore, the researchers report that the malware campaign does not reflect the security standards of original, legitimate applications. The hackers simply chose a recognizable brand as a means of social engineering.

This campaign remains active, so Android users are advised to be especially careful when downloading content from unofficial sources, as well as to protect their devices with good security software.

Information source: techradar.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS