HomeSecurity"Dark Herring" Scam: Targeting 105 million Android users

“Dark Herring” Scam: Targeting 105 Million Android Users

A premium subscription scam for Android services has been running for nearly two years. The operation, dubbed “Dark Herring,” used 470 Google Play Store apps and affected more than 100 million users worldwide, potentially causing hundreds of millions of USD in total losses.

See also: FluBot and TeaBot malware target Android users again

"Dark Herring" Scam: 105 Million Android Users Targeted

"Dark Herring" was present in 470 apps on the Google Play Store, the official and most trusted source of Android apps, with the first submission dating back to March 2020.

In total, the fraudulent apps were installed by 105 million users in 70 countries, signing them up for premium services that charge $15 per month via Direct Carrier Billing (DCB).

DCB is a mobile payment option that allows users to purchase digital content from the Play Store by charging it to their prepaid balance or prepaid account.

See also: BRATA Android malware: Steals data and performs factory resets

The operators of the “Dark Herring” operation cashed out the subscriptions while users became aware of the fraudulent charges much later, sometimes several months after the infection.

The discovery of "Dark Herring" comes from Zimperium zLabs, a Google partner.

How malware works

Dark Herring's long-term success was based on its AV anti-detection capabilities, propagation through a large number of applications, code obfuscation, and use of proxies as first-stage URLs.

While none of the above is new or groundbreaking, seeing them combined into a single piece of software is rare for Android fraud.

Additionally, the hackers used a sophisticated infrastructure that received communications from all users of the 470 applications, but handled each one individually based on a unique identifier.

The installed application does not contain malicious code, but it does have a hard-coded string that points to a first-stage URL hosted on Amazon's CloudFront.

The response from the server contains links to additional JavaScript files hosted on AWS instances, which are downloaded to the infected device.

"Dark Herring" Scam: 105 Million Android Users Targeted

These scripts prepare the application to acquire its configuration relative to the victim, generate the unique identifiers, retrieve the language and country details, and determine which DCB platform is applicable in each case.

Finally, the app serves a custom WebView page that prompts the victim to enter their phone number in order to receive a temporary OTP code to activate the account on the app.

Dark Herring

Applications and goals

With 470 apps distributing the malware, the targeted demographics were quite diverse. Most of these apps fall into the broader and more popular “Entertainment” category.

Other apps were photography tools, games, utilities, and productivity apps.

A key factor in the consequences of the Dark Herring operation is the absence of laws to protect DCB consumers, so some countries were targeted more fervently than others.

The countries at greatest risk are India, Pakistan, Saudi Arabia, Egypt, Greece, Finland, Sweden, Norway, Bulgaria, Iraq and Tunisia.

Dark Herring android scam

See also: How to close apps on an Android device

Even in countries where strict DCB protection rules apply, if victims are late in realizing the fraud, reversing transactions may be impossible.

The most popular Dark Herring apps, each counting many millions of downloads, are:

  • Smashex
  • Upgrade
  • Stream HD
  • Vidly Vibe
  • Cast It
  • My Translator Pro
  • New Mobile Games
  • StreamCast Pro
  • Ultra Stream
  • Photograph Labs Pro
  • VideoProj Lab
  • Driving Simulator
  • Speedy Cars – Final Lap
  • Football Legends
  • Football HERO 2021
  • Grand Mafia Auto
  • Offroad Jeep Simulator
  • Smashex Pro
  • Racing City
  • Connectool
  • City Bus Simulator 2

To access the entire list of all 470 malicious Android apps, check out this GitHub page.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS