A new malware-as-a-service (MaaS), called Cellik, is targeting Android and is being advertised on underground cybercrime forums, offering a powerful set of features. One of the most notable features is the option to embed the malware into any app available on the Google Play Store. Attackers can select apps from the official Android app store and create modified versions that appear legitimate while maintaining the interface and functionality of the real app.

By providing these capabilities, Cellik infections can remain undetected for a longer period of time. Additionally, the vendor claims that binding the malware in this way can help bypass Play Protect, although this has not been confirmed.
See also: SantaStealer malware steals documents and credentials
Cellik malware: Features
Mobile security firm iVerify discovered Cellik on underground forums, where it is offered for $150/month or $900 for lifetime access. Cellik is a full-fledged Android malware that can record and stream the victim's screen in real time, intercept app notifications , browse the file system, extract files, delete data , and communicate with the command and control server via an encrypted channel.

The malware also has a hidden browsing feature that attackers can use to access websites from the infected device, using the stored cookies . An app injection allows attackers to overlay fake login screens or inject malicious code into any application to steal the victim's account credentials .
See also: NexusRoute: New malware campaign targets Android users
The reported capabilities also include the option to inject payloads into installed applications, making it even more difficult to detect the infection, as known trustworthy applications suddenly become malicious.
The main feature is the integration of the Play Store into Cellik's APK builder, which allows cybercriminals to browse the store for apps, select the ones they want, and create a malicious variant of them.
The vendor claims that Cellik can bypass security features by hiding its payload in trusted apps, effectively disabling Play Protect detection.
See also: Phantom Stealer: Phishing attack with ISO images targets Russia

While Google Play Protect typically flags unknown or malicious apps, trojans hidden within popular app bundles may slip past automated reviews or device-level scanners.
To stay safe, Android users should avoid downloading APKs from questionable sites, ensure Play Protect is active on the device, check app permissions , and monitor for unusual activity.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
