HomeSecurity35 Android malware apps found in Google Play Store

35 Android malware apps found in Google Play Store

A new batch of thirty-five Android malware apps that display unwanted ads has been found on the Google Play Store, with the apps having been installed over 2 million times on victims' mobile devices.

The apps were found by security researchers at Bitdefender, who used a real-time behavioral analysis method to discover the potentially malicious apps.

Following typical tactics, Android malware apps lure users into installing them by pretending to offer some specialized functionality but change their name and icon immediately after installation, making them difficult to find and uninstall.

From there, Android malware applications begin to display intrusive ads to users by abusing WebView, generating fake impressions and ad revenue for their operators.

See also: Malware devs are already bypassing Android 13 security

35 Android malware apps found in Google Play Store
35 Android malware apps found in Google Play Store

Furthermore, because these apps use their own framework to load ads, it would likely be possible to drop additional payloads on a compromised device.

As Bitdefender explains in the report, adware apps implement multiple methods to hide on Android and even receive subsequent updates to make hiding on devices easier.

After installation, applications usually change their icon to a gear and rename themselves to “Settings”to avoid detection and deletion.

If the user clicks on the icon, the Android app launches the malware with a size of 0 to hide it from view. The malware then launches the legitimate settings menu to trick users into believing they clicked on the correct app.

In some cases, the apps take on the appearance of Motorola, Oppo, or Samsung.

The malicious applications also feature heavily modified code and encryption to thwart reverse engineering attempts , hiding the main Java payload inside two encrypted DEX files .

Another method for hiding malware Android apps from the user is to exclude them from the “Recent apps”, so even if they are running in the background, checking open apps will not help you find them.

35 Android malware apps found in Google Play Store
35 Android malware apps found in Google Play Store

See also: Top malware and ransomware you should worry about

The 35 Android malware apps have download counts ranging from 10,000 to 100,000, totaling over two million downloads.

The most popular of these, with 100,000 downloads each, are the following:

  • Walls light – Wallpapers Pack (gb.packlivewalls.fournatewren)
  • Big Emoji – Keyboard 5.0 (gb.blindthirty.funkeyfour)
  • Grand Wallpapers – 3D Backdrops 2.0 (gb.convenientsoftfiftyreal.threeborder)
  • Engine Wallpapers (gb.helectronsoftforty.comlivefour)
  • Stock Wallpapers (gb.fiftysubstantiated.wallsfour)
  • EffectMania – Photo Editor 2.0 (gb.actualfifty.sevenelegantvideo)
  • Art Filter – Deep Photoeffect 2.0 (gb.crediblefifty.editconvincingeight)
  • Fast Emoji Keyboard APK (de.eightylamocenko.editioneights)
  • Create Sticker for Whatsapp 2.0 (gb.convincingmomentumeightyverified.realgamequicksix)
  • Math Solver – Camera Helper 2.0 (gb.labcamerathirty.mathcamera)
  • Photopix Effects – Art Filter 2.0 (gb.mega.sixtyeffectcameravideo)
  • Led Theme – Colorful Keyboard 2.0 (gb.theme.twentythreetheme)
  • Animated Sticker Master 1.0 (am.asm.master)
  • Sleep Sounds 1.0 (com.voice.sleep.sounds)
  • Personality Charging Show 1.0 (com.charging.show)
  • Image Warp Camera
  • GPS Location Finder (smart.ggps.lockakt)

Of the above, “Walls light – Wallpapers Pack”, “Animated Sticker Master” and “GPS Location Finder” are still available on the Play Store at the time of writing this article.

The remaining apps listed are available on many third-party app stores, such as APKSOS, APKAIO, APKCombo, APKPure, and APKsfull, but the download numbers presented are from their time on the Play Store.

That said, if you have installed any of these apps in the past, you should locate and remove them from your device immediately.

Because Android malware apps disguise themselves as Settings, running a AV tool to detect and remove them can be helpful in this case.

Source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS