Sophos experts found 22 dangerous applications in the official Google Play catalog that were installed more than 2,000,000 times in total (Sparkle Flashlight alone was downloaded over 1,000,000 times.)
Researchers They write that three malicious applications were added to the catalog as early as 2016-2017, and the rest appeared in the summer of 2018. Moreover, the malicious functionality appeared in the already mentioned Sparkle Flashlight and two more “old” applications in March of the current year, and later applications downloaded to Google Play contained a malicious code from the very beginning.
This family of Malvari was named Andr / Clickr-ad and, as is easy to understand by this identifier, mostly applications were used for background clicking All applications were launched and continued to work, even if the user tried to terminate them forcibly, while actively spending traffic and battery. So, the malware contacted the mobbt [.] com domain, from which it received modules for the advertising fraud and new instructions, every 10 minutes and 80 seconds, respectively.
To avoid suspicion and merge with the traffic of real users, the applications forged the user-agent and impersonating other products and devices, including the iPhone. Thus, the malware imitated the activity allegedly emanating from iPhone from 5 to 8 Plus, as well as 249 models from 33 manufacturers of Android devices (supposedly running Android from version 4.4.2 to 7.x). And here is Apple? The fact is that advertising on Apple devices is more expensive than on Android, Linux or Windows.
Experts point out that malware could harm not only users, but advertising networks and even the entire Android ecosystem. Worse, malicious applications were completely controlled by hackers from the management server and could at any time be used to install additional malware on the infected device.
Currently, all dangerous applications have already been removed from Google Play. Below you can see a list compiled by Sophos analysts.
|com.takatrip.android||Tak A Trip||0bcd55faae22deb60dd8bd78257f724bd1f2fc89|
|com.beacon.animalmatch||Animal Match||403c0fe a7d6fcd0e28704fccf5f19220a676bf6c|