Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Share Post: Reddit Facebook
Android malware found embedded in APKPure store application
#1
Security researchers found malware embedded within the official application of APKPure, a popular third-party Android app store and an alternative to Google's official Play Store.

Android users use the application to install apps and games hosted on APKPure's platform, supposedly identical to those available through the Play Store.


The malware was discovered by

Kaspersky and Dr.Web malware analysts embedded within an advertisement SDK included with APKPure version 3.7.18.

As they discovered, it looks like a variant of the Triada trojan first spotted by Kaspersky in 2016, capable of spamming users of infected devices with ads and deliver additional malware.


[Image: EiXg0zp.jpg]

"The identified malicious code embedded in APKPure operates in the following way: upon launch of the application, the payload is decrypted and launched," Kaspersky said. "It then collects information about the user device and sends it to the C&C server."

Next, depending on its operators' instructions and monetizing scheme (ads or pay-per-install), it will:

show ads every time the Android device is unlocked,
repeatedly open web pages containing ads,
click the ads to sign up for paid subscriptions,
install other payloads or potentially malicious software without the users' consent.
The damage inflicted by this trojan varies depending on the Android version running on the compromised devices, ranging from being signed up for paid subscriptions and seeing intrusive ads on current versions to having unremovable malware like xHelper deployed on the system partition.


[Image: r9ABPke.png]

While no official download stats are available for the APKPure app, Kaspersky says that it has so far blocked the malware on the devices of 9,380 Android users running its security solutions on their devices.

Both Kaspersky and Dr.Web reported their findings to APKPure's developers, who have released APKPure 3.17.19 today without the malicious code.

Indicators of compromise, including APKpure app, payload, and malware sample hashes, are available at the end of Kaspersky's report.


BleepingComputer has reached out to APKPure's development team for more information but has not heard back.

Source
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Bogus Android Clubhouse App Drops Credential-Swiping Malware tarekma7 0 1,364 03-22-2021 , 10:19 AM
Last Post: tarekma7
  Cyber Security Today – Twitter hack aftermath, more Android malware, actors on alert Mike 0 1,607 07-20-2020 , 05:00 PM
Last Post: Mike
  New Android malware steals financial information, bypasses 2FA tarekma7 0 1,600 04-30-2020 , 10:21 PM
Last Post: tarekma7

Forum Jump:


Users browsing this thread: 1 Guest(s)