[ad_1]
Researchers say they have A batch of apps that had been downloaded more than 300,000 times from Google Play were discovered. These apps were then found to be banking Trojans that secretly steal user passwords and two-factor authentication codes, record keystrokes, and take screenshots.
These applications-impersonating QR scanners, PDF scanners and Cryptocurrency Wallet-belongs to four separate Android malware families, distributed within four months.They used several techniques to circumvent restrictions Google Designed to control the endless distribution of fraudulent applications on its official market. These restrictions include restricting visually impaired users from using access services to prevent automatic installation of applications without the user’s consent.
Small footprint
Researchers from the mobile security company ThreatFabric wrote in a report: “From the perspective of automation (sandbox) and machine learning, the reason why these Google Play distribution activities are difficult to detect is the malicious footprint of the dropper application. They are all very small.” postal“This small footprint is a (direct) consequence of Google Play’s implementation of permission restrictions.”
Instead, these activities usually provide a benign application initially. After installing the app, users will receive a message instructing them to download and install updates with additional features. These applications usually need to download updates from third-party sources, but at that time many users have begun to trust them.Most applications have zero initial detection malicious software Checkers available on VirusTotal.
These applications also fly under the radar by using other mechanisms. In many cases, malware operators only manually install malicious updates after checking the geographic location of the infected phone or updating the phone incrementally.
ThreatFabric’s post explains: “This incredible focus on avoiding unnecessary attention makes automated malware detection less reliable.” “The VirusTotal totals of the 9 droppers we investigated in this blog post The very low score confirms this consideration.”
The malware family that causes the most infections is called Anatsa.This “pretty advanced Android banking Trojan” provides a variety of features, including remote access and Automatic transmission system, It will automatically clear the victim’s account and send the content to the account belonging to the malware operator.
The researchers wrote:
The process of infecting Anatsa is as follows: After installing from Google Play, users are forced to update the application to continue using the application. at this moment, [the] The Anatsa payload is downloaded from the C2 server and installed on the device of the unsuspecting victim.
The participants behind it are responsible for making their applications look legitimate and useful. These apps have a lot of positive reviews. The number of installs and the presence of comments may persuade Android users to install the app.In addition, these apps do have the claimed functionality; after installation, they do run normally and further persuade [the] victim [of] Their legitimacy.
Despite the huge number of installations, not all devices with these dispensers will receive Anatsa, because participants strive to only target their areas of interest.
The other three malware families discovered by the researchers include Alien, Hydra, and Ermac. One of the droplets used to download and install malicious payloads is called Gymdrop. It uses filtering rules based on the infected device model to prevent devices from being targeted at researchers.
New exercise exercises
“If all conditions are met, the payload will be downloaded and installed,” the post said. “This dropper does not require accessibility service permissions; it just requests permission to install software packages and promises to install new exercises-to attract users to grant this permission. After installation, the payload will be launched. Our threat intelligence shows, Currently, this dropper is used to distribute [the] Alien banking Trojan. “
When asked for comment, a Google spokesperson pointed out This post From April, it detailed the company’s method of detecting malicious applications submitted to Play.
[ad_2]
Source link






