Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Share Post: Reddit Facebook
Android malware apps with 2 million installs spotted on Google Play
#1
A new set of Android malware, phishing, and adware apps have infiltrated the Google Play store, tricking over two million people into installing them.

The apps were discovered by Dr. Web antivirus and pretend to be useful utilities and system optimizers but, in reality, are the sources of performance hiccups, ads, and user experience degradation.

One app illustrated by Dr. Web that has amassed one million downloads is TubeBox, which remains available on Google Play at the time of writing this.

[Image: tube-app.jpg]

TubeBox promises monetary rewards for watching videos and ads on the app but never delivers on its promises, presenting various errors when trying to redeem the collected rewards.

Even users who get to complete the final withdrawal step never really receive the funds, as the researchers say it’s all a trick to try and keep them on the app for as long as possible, watching ads and generating revenue for the developers.

Other adware apps that appeared on Google Play in October 2022 but have since been removed are:

Bluetooth device auto connect (bt autoconnect group) – 1,000,000 downloads
Bluetooth & Wi-Fi & USB driver (simple things for everyone) – 100,000 downloads
Volume, Music Equalizer (bt autoconnect group) – 50,000 downloads
Fast Cleaner & Cooling Master (Hippo VPN LLC) – 500 downloads

[Image: adware-apps.png]

The above apps receive commands from Firebase Cloud Messaging and load the websites specified in these commands, generating fraudulent ad impressions on the infected devices.

In the case of Fast Cleaner & Cooling Master, which had a low download volume, the remote operators could also configure an infected device to act as a proxy server. This proxy server would allow the threat actors to channel their own traffic through the infected device.

Finally, Dr. Web discovered a set of loan scam apps claiming to have a direct relationship with Russian banks and investment groups, each having an average of 10,000 downloads on Google Play.

[Image: russian-apps.png]

These apps were promoted via malvertizing through other apps, promising guaranteed investment profits. In reality, the apps take the users to phishing sites where their personal information is collected.

To protect yourself from fraudulent apps on Google Play, always check for negative reviews, scrutinize the privacy policy, and visit the developer’s site to evaluate its authenticity.

In general, try to keep the number of installed apps on your device at a minimum and periodically check and ensure that Google's Play Protect feature is active.

source
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  45,000 Android devices infected by unremovable malware sidemoon 1 3,100 11-30-2023 , 05:24 AM
Last Post: Pranav
  It was a bad week for millions of people who rely on Google for apps and Chrome exten mrtrout 0 681 06-03-2023 , 04:09 AM
Last Post: mrtrout
  Google ads push BumbleBee malware used by ransomware gangs mrtrout 0 761 04-23-2023 , 03:59 AM
Last Post: mrtrout
  Privacy-invasive and Clicker Android Adware found in popular apps in South Korea mrtrout 0 564 04-21-2023 , 10:12 PM
Last Post: mrtrout
  Android malware infected 300,000 devices to steal Facebook accounts tarekma7 0 466 12-05-2022 , 04:04 PM
Last Post: tarekma7

Forum Jump:


Users browsing this thread: 1 Guest(s)