HomeSecurityAndroid.Trojan.MKero.A|Malware makes registrations to Premium SMS Services

Android.Trojan.MKero.A|Malware makes registrations to Premium SMS Services

Android.Trojan.MKero.A | Malware Sign Ups for Premium SMS Services – – Its Victims May Be Faced with a Huge Phone Bill Next Month.

The Android.Trojan.MKero.A malware is making a comeback in the 'land of Android', and this time, hackers have found a way to attach it to legitimate apps, capable of bypassing Google's Bouncer app scanning system.
While the malware was first detected in 2014 and was mainly distributed to users during the installation of Android apps from unverified sources, it is now reported in several cases where this trojan is distributed through the official Google Play Store.

This time, the malware is packaged inside various Android games, and once infected, it secretly enrolls users in premium SMS services, all without the user having to take any action.

They use humans to bypass CAPTCHA filters

According to BitDefender researchers, the malware uses a clever and sophisticated set of processes that allows it to bypass various security mechanisms that have been put in place by premium SMS services for preventive reasons.

First, once the device is infected, the malware initiates communication with a C&C server, from where the URL of a premium subscription website is loaded.

Android.Trojan.MKero.A then activates to extract the CAPTCHA image from the registration form, which it then sends to antigate.com, a Web service that relies on humans to solve the 'puzzle' of image-to-text CAPTCHAs .

After receiving the CAPTCHA solution from antigate.com, the malware enrolls the user in the service, and after receiving, parsing , and extracting the confirmation code from an SMS message, it enters the code on the target website, effectively enrolling the user in the premium service.

The attackers are likely members of various affiliate programs

The purpose of infecting users with Android.Trojan.MKero.A and then signing them up for these types of services is simple. The attacker likely participates in various affiliate programs in connection with these services, and makes monetary profits from each user they bring.

Checking your accounts regularly is a good idea, since increased charges that came out of nowhere could be a sign of a malware infection.

BitDefender staff detected 7 infected gaming apps in the Google Play Store, which have since been removed.

Android.Trojan.MKero.A attack timeline

Android.Trojan.MKero.A|Malware makes registrations to Premium SMS Services

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS