HomeSecuritySharkbot malware: Entered the Play Store disguised as file managers

Sharkbot malware: Entered the Play Store disguised as file managers

Malicious Android apps posing as file managers had infiltrated the Google Play Store, infecting users with the banking malware Sharkbot.

Sharkbot malware Play Store

The apps did not contain the malicious payload when they were installed, which helped them avoid detection when submitted to Google Play. Instead, they pulled it later from a remote resource.

The apps acted as file managers, so when they requested dangerous permissions to load the Sharkbot malware, users didn't realize anything strange was happening.

See also: Donut: The extortion gang now has its own ransomware

Fake file managers infect Android devices with Sharkbot malware

Sharkbot malware is particularly dangerous because it attempts to steal online banking credentials by mimicking real banking application. So, if an unsuspecting user attempts to log in to their bank via one of these fake forms, their credentials are transferred to cybercriminals.

Malware is constantly adapting and can appear in various forms on the Play Store or be downloaded from malicious apps.

The malicious apps masquerading as file managers were discovered by Bitdefender. After their discovery, Google Store removed them from the Play.

Users who had already downloaded them to their Android device are still at risk.

The first app to show signs of malicious activity is 'X-File Manager' by Victor Soft Ice LLC (com.victorsoftice.llc). It was downloaded 10,000 times from Google Play before the company removed it.

The app is designed to evade detection, and the Sharkbot malware only affects SIMs from the UK or Italy – this suggests that the app is part of a targeted attack.

The list of mobile banking apps targeted by the malware is long, but as Bitdefender notes, threat actors can update this list remotely at any time.

See also: Google: Published 165 YARA rules to detect Cobalt Strike attacks

According to Bitdefender data, most victims of the new Sharkbot malware campaign are located in the United Kingdom, Italy, Iran, and Germany.

The above application asks the user to grant permissions that could be harmful, such as reading and writing external storage, installing new packages, accessing account, deleting packages (to erase traces), etc.

Although these permissions seem common for file management apps, users should be careful.

X-File Manager asks the user to approve Sharkbot malware before installation, which is disguised as a fake program update.

The second application that installs the banking trojan is 'FileVoyager' by Julia Soft Io LLC (com.potsepko9.FileManagerApp). This application has been downloaded 5,000 times via Google Play.

FileVoyager works similarly to X-File Manager and is primarily targeted at the United Kingdom and Italy.

The third app found was “LiteCleaner M” (com.ltdevelopergroups.litecleaner.m) which had amassed 1,000 downloads before being removed from the Play Store.

Currently, the only way to get this app is through third-party app stores, such as APKSOS. The same store also has another malicious app that distributes Sharkbot called 'Phone AID, Cleaner, Booster 2.6' (om.sidalistudio.developer.app).

See also: Aurora malware: More and more hackers are using it

Android users who have the above apps on their device should uninstall them immediately, as well as change the passwords for any online banking accounts they have.

file managers
Sharkbot malware: Entered the Play Store disguised as Android file managers

The best way to protect your device from malicious apps is to enable Google Play Protect. This service will remove any apps that could be harmful to your device.

Additionally, an antivirus app for Android phones would help detect malicious activity and apps, sometimes even before they are reported on Google Play.

With over two billion active devices, Android is the most popular mobile operating system in the world – but it's also the most targeted by malware creators. That's why it's important to be aware of the risks and take steps to protect your device.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS