Google pulls malware-infected apps in its Store, over 3 million users at risk
(2022/07/19)
- Reference: 1658260814
- News link: https://www.theregister.co.uk/2022/07/19/google_malware_apps/
- Source link:
Google pulled 60 malware-infected apps from its Play Store, installed by more than 3.3 million punters, that can be used for all kinds of criminal activities including credential theft, spying and even stealing money from victims.
Zscaler's ThreatLabZ and security researcher Maxime Ingrao from fraud protection firm Evina discovered the downloader apps stuffed with software nasties including Joker, Facestealer, Coper, and Autolycos malware — the latter is a new family, according to Ingrao, who named and [1]discovered Autolycos in eight different apps with more than three million downloads to Android devices.
The new malware strain, similar to Joker, steals SMS messages when downloaded and also unwittingly subscribes users to — and charges them for using — premium wireless application protocol services, Ingrao [2]tweeted .
Found new family of malware that subscribe to premium services 👀8 applications since June 2021, 2 apps always in Play Store, +3M installs 💀💀No webview like [3]#Joker but only http requestsLet's call it [4]#Autolycos 👾 [5]#Android [6]#Malware [7]#Evina [8]pic.twitter.com/SgTfrAOn6H — Maxime Ingrao (@IngraoMaxime) [9]July 13, 2022
This spyware is designed to steal SMS messages, contact lists, and device information, and to sign the victim up for premium wireless application protocol (WAP) services.
"It retrieves a JSON on the C2 address: 68.183.219.190/pER/y," he further explained. "It then executes the urls, for some steps it executes the urls on a remote browser and returns the result to include it in the requests. This allows it not to have a Webview and to be more discreet."
[10]
Additionally, fraudsters created Facebook and Instagram ads to promote the phony applications, Ingrao [11]noted .
[12]
[13]
The malicious apps include:
Vlog Star Video Editor — 1 million downloads
Creative 3D Launcher — 1 million downloads
Wow Beauty Camera — 100,000 downloads
Gif Emoji Keyboard — 100,000 downloads
Freeglow Camera — 5,000 downloads
Coco Camera v1.1 — 1,000 downloads
Funny Camera — 500,000 downloads
Razer Keyboard & Theme — 50,000 downloads
Joker, Facestealer and Coper resurface
Meanwhile, Zscaler's threat hunters this week said Google removed an additional 52 malware-infested apps on the Play Store, and 50 of them were used to deploy Joker, which has been an ongoing problem for Android devices. They also discovered Facestealer and Coper malware in two other malicious apps, and those have been booted from the online marketplace as well.
The Joker-spreading apps were downloaded more than 300,000 times, according to security researchers Viral Gandhi and Himanshu Sharma, who provided a technical analysis of the three malware family payloads and listed all 50 Joker downloaders on a ThreatLabZ blog post.
"Despite public awareness of this particular malware, it keeps finding its way into Google's official app store by regularly modifying the malware's trace signatures including updates to the code, execution methods, and payload-retrieving techniques," Gandhi and Sharma [14]wrote .
[15]
Once downloaded, Joker malware steals SMS messages, contact lists, and device information and also unknowingly signs the victim up for premium services.
"Most commonly, threat actors disguise the Joker malware in messaging applications that require users to grant escalated access permissions by allowing them to serve as the default SMS app on the user's phone," the threat hunters noted. "The malware uses these advanced permissions to carry out its operations."
[16]Bogus cryptocurrency apps steal millions in mere months
[17]Botnet malware disguises itself as password cracker for industrial controllers
[18]North Koreans spotted harassing SMBs with malware
[19]CISA pulls the fire alarm on Juniper Networks bugs
Additionally, Zscaler discovered Facestealer hiding in the now-removed cam.vanilla.snap app on Google Play Store, which had 5,000 downloads. This malware targets Facebook users via fake Facebook login pages to steal credentials. And finally, the security team also discovered banking trojan Coper disguised as a Unicc QR Scanner app.
"Once downloaded, this app unleashes the Coper malware infection which is capable of intercepting and sending SMS text messages, making USSD (Unstructured Supplementary Service Data) requests to send messages, keylogging, locking/unlocking the device screen, performing overly attacks, preventing uninstalls and generally allowing attackers to take control and execute commands on infected device via remote connection with a C2 server," Gandhi and Sharma wrote. ®
Get our [20]Tech Resources
[1] https://twitter.com/IngraoMaxime/status/1547164768401858560
[2] https://twitter.com/IngraoMaxime/status/1547164768401858560
[3] https://twitter.com/hashtag/Joker?src=hash&ref_src=twsrc%5Etfw
[4] https://twitter.com/hashtag/Autolycos?src=hash&ref_src=twsrc%5Etfw
[5] https://twitter.com/hashtag/Android?src=hash&ref_src=twsrc%5Etfw
[6] https://twitter.com/hashtag/Malware?src=hash&ref_src=twsrc%5Etfw
[7] https://twitter.com/hashtag/Evina?src=hash&ref_src=twsrc%5Etfw
[8] https://t.co/SgTfrAOn6H
[9] https://twitter.com/IngraoMaxime/status/1547164768401858560?ref_src=twsrc%5Etfw
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YtcpgK0hv8WeV4gOysVkVgAAAA8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[11] https://twitter.com/IngraoMaxime/status/1547164790753267713
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YtcpgK0hv8WeV4gOysVkVgAAAA8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YtcpgK0hv8WeV4gOysVkVgAAAA8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[14] https://www.zscaler.com/blogs/security-research/joker-facestealer-and-coper-banking-malwares-google-play-store
[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YtcpgK0hv8WeV4gOysVkVgAAAA8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[16] https://www.theregister.com/2022/07/18/fbi-cryptocurrency-scams/
[17] https://www.theregister.com/2022/07/18/password-sality-malware/
[18] https://www.theregister.com/2022/07/16/north_korea_targets_small_business/
[19] https://www.theregister.com/2022/07/15/cisa_critical_juniper_bugs/
[20] https://whitepapers.theregister.com/
Zscaler's ThreatLabZ and security researcher Maxime Ingrao from fraud protection firm Evina discovered the downloader apps stuffed with software nasties including Joker, Facestealer, Coper, and Autolycos malware — the latter is a new family, according to Ingrao, who named and [1]discovered Autolycos in eight different apps with more than three million downloads to Android devices.
The new malware strain, similar to Joker, steals SMS messages when downloaded and also unwittingly subscribes users to — and charges them for using — premium wireless application protocol services, Ingrao [2]tweeted .
Found new family of malware that subscribe to premium services 👀8 applications since June 2021, 2 apps always in Play Store, +3M installs 💀💀No webview like [3]#Joker but only http requestsLet's call it [4]#Autolycos 👾 [5]#Android [6]#Malware [7]#Evina [8]pic.twitter.com/SgTfrAOn6H — Maxime Ingrao (@IngraoMaxime) [9]July 13, 2022
This spyware is designed to steal SMS messages, contact lists, and device information, and to sign the victim up for premium wireless application protocol (WAP) services.
"It retrieves a JSON on the C2 address: 68.183.219.190/pER/y," he further explained. "It then executes the urls, for some steps it executes the urls on a remote browser and returns the result to include it in the requests. This allows it not to have a Webview and to be more discreet."
[10]
Additionally, fraudsters created Facebook and Instagram ads to promote the phony applications, Ingrao [11]noted .
[12]
[13]
The malicious apps include:
Vlog Star Video Editor — 1 million downloads
Creative 3D Launcher — 1 million downloads
Wow Beauty Camera — 100,000 downloads
Gif Emoji Keyboard — 100,000 downloads
Freeglow Camera — 5,000 downloads
Coco Camera v1.1 — 1,000 downloads
Funny Camera — 500,000 downloads
Razer Keyboard & Theme — 50,000 downloads
Joker, Facestealer and Coper resurface
Meanwhile, Zscaler's threat hunters this week said Google removed an additional 52 malware-infested apps on the Play Store, and 50 of them were used to deploy Joker, which has been an ongoing problem for Android devices. They also discovered Facestealer and Coper malware in two other malicious apps, and those have been booted from the online marketplace as well.
The Joker-spreading apps were downloaded more than 300,000 times, according to security researchers Viral Gandhi and Himanshu Sharma, who provided a technical analysis of the three malware family payloads and listed all 50 Joker downloaders on a ThreatLabZ blog post.
"Despite public awareness of this particular malware, it keeps finding its way into Google's official app store by regularly modifying the malware's trace signatures including updates to the code, execution methods, and payload-retrieving techniques," Gandhi and Sharma [14]wrote .
[15]
Once downloaded, Joker malware steals SMS messages, contact lists, and device information and also unknowingly signs the victim up for premium services.
"Most commonly, threat actors disguise the Joker malware in messaging applications that require users to grant escalated access permissions by allowing them to serve as the default SMS app on the user's phone," the threat hunters noted. "The malware uses these advanced permissions to carry out its operations."
[16]Bogus cryptocurrency apps steal millions in mere months
[17]Botnet malware disguises itself as password cracker for industrial controllers
[18]North Koreans spotted harassing SMBs with malware
[19]CISA pulls the fire alarm on Juniper Networks bugs
Additionally, Zscaler discovered Facestealer hiding in the now-removed cam.vanilla.snap app on Google Play Store, which had 5,000 downloads. This malware targets Facebook users via fake Facebook login pages to steal credentials. And finally, the security team also discovered banking trojan Coper disguised as a Unicc QR Scanner app.
"Once downloaded, this app unleashes the Coper malware infection which is capable of intercepting and sending SMS text messages, making USSD (Unstructured Supplementary Service Data) requests to send messages, keylogging, locking/unlocking the device screen, performing overly attacks, preventing uninstalls and generally allowing attackers to take control and execute commands on infected device via remote connection with a C2 server," Gandhi and Sharma wrote. ®
Get our [20]Tech Resources
[1] https://twitter.com/IngraoMaxime/status/1547164768401858560
[2] https://twitter.com/IngraoMaxime/status/1547164768401858560
[3] https://twitter.com/hashtag/Joker?src=hash&ref_src=twsrc%5Etfw
[4] https://twitter.com/hashtag/Autolycos?src=hash&ref_src=twsrc%5Etfw
[5] https://twitter.com/hashtag/Android?src=hash&ref_src=twsrc%5Etfw
[6] https://twitter.com/hashtag/Malware?src=hash&ref_src=twsrc%5Etfw
[7] https://twitter.com/hashtag/Evina?src=hash&ref_src=twsrc%5Etfw
[8] https://t.co/SgTfrAOn6H
[9] https://twitter.com/IngraoMaxime/status/1547164768401858560?ref_src=twsrc%5Etfw
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YtcpgK0hv8WeV4gOysVkVgAAAA8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[11] https://twitter.com/IngraoMaxime/status/1547164790753267713
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YtcpgK0hv8WeV4gOysVkVgAAAA8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YtcpgK0hv8WeV4gOysVkVgAAAA8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[14] https://www.zscaler.com/blogs/security-research/joker-facestealer-and-coper-banking-malwares-google-play-store
[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YtcpgK0hv8WeV4gOysVkVgAAAA8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[16] https://www.theregister.com/2022/07/18/fbi-cryptocurrency-scams/
[17] https://www.theregister.com/2022/07/18/password-sality-malware/
[18] https://www.theregister.com/2022/07/16/north_korea_targets_small_business/
[19] https://www.theregister.com/2022/07/15/cisa_critical_juniper_bugs/
[20] https://whitepapers.theregister.com/
Steve Miller. Who he?
I suspect Jessica Lyons Hardcastle is more likely to have been named for the [1]1973 Doobie Brothers instrumental than to have been around when the contemporaneous title referenced in the lede by an aged subeditor appeared.
[1] https://books.google.com/ngrams/graph?content=Jessica&year_start=1800&year_end=2019&corpus=26&smoothing=3&direct_url=t1%3B%2CJessica%3B%2Cc0