Malicious Android apps masquerading as Google, Instagram, Snapchat, WhatsApp, and X (formerly Twitter) apps are stealing user credentials from compromised devices.

“ This malware uses famous Android app icons to mislead users and trick victims into installing the malicious app on their devices ,” said threat research team SonicWall Capture Labs .
At this time, we do not know how the apps are distributed. However, once a malicious app is installed on users' phones , it asks them to grant it permissions to the device's accessibility services and administrator API.
See also: Android malware PixPirate uses new hiding tactic
With these permissions, the malicious application gains control of the device, making it possible to perform arbitrary actions, such as data theft and malware deployment without the victims' knowledge.
The malware establishes connections to a command-and-control (C2) server and receives commands to perform actions that allow it to access contact lists, SMS messages, call logs, and installed applications. It can also send SMS messages, open phishing pages in the browser, and turn on the camera flash.
The phishing addresses mimic the login pages of well-known services such as Facebook, GitHub, Instagram, LinkedIn, Microsoft, Netflix, PayPal, Proton Mail, Snapchat, Tumblr, X, WordPress, and Yahoo.
See also: XLoader Android malware: New version runs automatically on device

What safety measures can someone take to protect themselves?
First of all, it's important to only download apps from trusted sources, such as the Google Play Store and the App Store. Avoid installing apps from unknown sources, such as third-party stores, untrusted sites, and links you receive via emails and SMS.
Additionally, it's important to keep device up to date. Software updates often include security fixes that can protect your device from malicious apps and other harmful software.
See also: HijackLoader malware: New more powerful version
It is also important to use a reliable security or antivirus. These programs can protect you from installing harmful software on your device.
Finally, you should be careful with the messages SMS you receive. Avoid clicking on links that look suspicious or come from unknown numbers.
Source: thehackernews.com
