Kaspersky Uncovers New Mandrake Android Spyware Variant on Google Play

30 Jul 2024

Mandrake Malware: A Persistent Threat in the Android Ecosystem

A recent investigation by Kaspersky has unveiled a new variant of the notorious Android spyware known as Mandrake, which has infiltrated five applications available on Google Play. These apps, collectively downloaded over 32,000 times, were present on the platform for at least a year before the last one, AirFS, was removed in March 2024. The original Mandrake malware was first documented by Bitdefender in 2020, showcasing its advanced spying capabilities and active presence since at least 2016.

Kaspersky’s analysis identified the five applications harboring the Mandrake malware as:

  • AirFS – File sharing via Wi-Fi by it9042 (30,305 downloads between April 28, 2022, and March 15, 2024)
  • Astro Explorer by shevabad (718 downloads from May 30, 2022, to June 6, 2023)
  • Amber by kodaslda (19 downloads between February 27, 2022, and August 19, 2023)
  • CryptoPulsing by shevabad (790 downloads from November 2, 2022, to June 6, 2023)
  • Brain Matrix by kodaslda (259 downloads between April 27, 2022, and June 6, 2023)

The majority of downloads originated from countries including Canada, Germany, Italy, Mexico, Spain, Peru, and the UK.

Evading Detection

What sets Mandrake apart from typical Android malware is its cunning approach to concealment. Instead of embedding malicious code directly into the app’s DEX file, Mandrake cleverly hides its initial stage within a native library named ‘libopencv_dnn.so,’ which is heavily obfuscated using OLLVM. Upon installation of the malicious app, this library exports functions designed to decrypt a second-stage loader DEX from its assets folder and subsequently loads it into memory.

The second stage of the malware requests permissions to draw overlays and loads another native library, ‘libopencv_java3.so,’ which is responsible for decrypting a certificate that facilitates secure communication with the command and control (C2) server. Once a connection is established, the app sends a device profile and, if the device meets certain criteria, receives the core Mandrake component (the third stage).

Once activated, the Mandrake spyware is capable of executing a variety of malicious activities, including:

  • Data collection
  • Screen recording and monitoring
  • Command execution
  • Simulation of user swipes and taps
  • File management
  • Installation of additional malicious apps

Notably, the malware can prompt users to install further malicious APKs by displaying notifications that mimic Google Play, thereby tricking users into downloading unsafe files under the guise of a trusted process.

In addition to its stealthy operations, Mandrake employs a session-based installation method to circumvent restrictions imposed by Android 13 and later versions regarding the installation of APKs from unofficial sources. Like many other Android malware variants, Mandrake can request permissions to run in the background and can hide the dropper app’s icon on the victim’s device, allowing it to operate undetected.

The latest iteration of Mandrake has also introduced battery evasion techniques, specifically checking for the presence of Frida, a dynamic instrumentation toolkit favored by security analysts. It further assesses the device’s root status, searches for specific binaries associated with rooting, verifies if the system partition is mounted as read-only, and checks whether development settings and ADB are enabled on the device.

While the five identified apps are no longer available on Google Play, the Mandrake threat persists, with cybercriminals continually evolving their tactics to stay ahead of detection mechanisms. As always, users are advised to exercise caution when downloading apps and to ensure their devices are protected with up-to-date security software.

Top charts for Mobile Android

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
7344673
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1696558
downloads
WinRAR

WinRAR

Streamline file management with fast compression, secure your documents, and save space.

5
735 reviews
728300
downloads
Minecraft

Minecraft

Shape environments, explore vast worlds, and survive against monsters with endless creativity.

5
750 reviews
491146
downloads

News and reviews for Mobile Android

Pixel Search Enhances Local Search on Android Devices

Pixel Search app brings streamlined local search capabilities to Android, offering quick access to apps, files, and contacts.

Read more

Exclusive App Deals Boost Android Users' Options

A range of app deals enhances Android options this week, featuring games and customization apps with significant price cuts.

Read more

Local Desktop Enables Full Linux Experience on Android

Local Desktop app allows Android devices to run Arch Linux without root, enhancing utility with desktop environments and apps.

Read more

Android 16 Eliminates Need for Third-Party Cleaner Apps

Android 16, released by Google, replaces third-party cleaner apps with built-in tools, enhancing security and efficiency.

Read more

Deezer Overhauls Android TV App for Enhanced Experience

Deezer upgrades its Android TV app for better speed, visuals, and Hi-Fi audio. Release begins on Google Play, with plans for Fire TV expansion.

Read more

Pepelo 2 Launches on iOS and Android with Global Levels

Tafusoft has released Pepelo 2 for iOS and Android, featuring global-inspired levels. The game offers enhanced visuals and expanded gameplay.

Read more

Intrusion Logging Feature Surfaces in Android Update

Google's Intrusion Logging emerges in Android Advanced Protection, with encrypted logs for enhanced security scrutiny.

Read more

Launches AutoSecT: AI-Driven Vulnerability Scanner

AutoSecT debuts as an AI-powered Android vulnerability scanner, enhancing security for enterprise apps by identifying and verifying threats.

Read more

New Android App Deals: Big Price Drops Today

Discover today's top Android app deals, featuring price drops on Maneater, Pocket Stables, and more. Find exciting options for your device.

Read more

New App Deals: Maneater, Pocket Stables Top Discounts

Android app deals on 2026-01-15 include discounts on Maneater and Pocket Stables, offering major savings for users.

Read more