Malware-Infested Apps on Google Play Store Reach 11 Million Downloads

24 Sep 2024

Emerging Threats in Mobile Security

In a concerning development for mobile security, altered versions of well-known Android applications linked to popular platforms such as Spotify, WhatsApp, and Minecraft have been identified as vehicles for a new iteration of the notorious malware loader, Necro. Kaspersky has reported that some of these malicious applications were available on the Google Play Store, amassing a staggering 11 million downloads collectively.

  • Wuta Camera – Nice Shot Always (com.benqu.wuta) – 10+ million downloads
  • Max Browser – Private & Security (com.max.browser) – 1+ million downloads

As of now, Max Browser has been removed from the Play Store, while Wuta Camera has undergone an update (version 6.3.7.138) aimed at eliminating the malware. The latest iteration, version 6.3.8.148, was released on September 8, 2024.

The precise method by which these applications were compromised remains unclear, although it is suspected that a rogue software development kit (SDK) designed for integrating advertising capabilities may be to blame. Necro, which should not be confused with a similarly named botnet, was first uncovered by Kaspersky in 2019, hidden within a widely used document scanning app called CamScanner. The developers of CamScanner attributed the issue to an advertisement SDK from a third-party provider, AdHub, which contained a malicious module capable of retrieving subsequent malware from a remote server, effectively acting as a loader.

The latest version of Necro continues this trend, employing advanced obfuscation techniques to evade detection, particularly through the use of steganography to conceal its payloads. According to Kaspersky researcher Dmitry Kalinin, “The downloaded payloads, among other things, could display ads in invisible windows and interact with them, download and execute arbitrary DEX files, install applications it downloaded.” Furthermore, it can “open arbitrary links in invisible WebView windows and execute any JavaScript code in those, run a tunnel through the victim’s device, and potentially subscribe to paid services.”

One of the primary methods of distributing Necro is through modified versions of popular applications and games found on unofficial websites and app stores. Upon installation, these applications initialize a module known as Coral SDK, which sends an HTTP POST request to a remote server. The server then responds with a link to a supposed PNG image file hosted on adoss.spinsok[.]com, from which the SDK extracts the main payload—a Base64-encoded Java archive (JAR) file.

The malicious capabilities of Necro are realized through a series of additional modules, or plugins, downloaded from a command-and-control (C2) server, enabling a wide array of actions on the compromised Android device:

  • NProxy: Creates a tunnel through the victim’s device.
  • island: Generates a pseudo-random number to determine the interval between intrusive ad displays.
  • web: Periodically contacts a C2 server and executes arbitrary code with elevated permissions when loading specific links.
  • Cube SDK: A helper module that loads other plugins to manage ads in the background.
  • Tap: Downloads arbitrary JavaScript code and a WebView interface from the C2 server responsible for covertly loading and displaying ads.
  • Happy SDK/Jar SDK: A module that combines NProxy and web modules with minor variations.

The emergence of these threats underscores the importance of vigilance in mobile security. Users are advised to download applications only from trusted sources and to keep their devices updated with the latest security patches.

Top charts for Mobile Android

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
4910858
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
818445
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
417205
downloads
Geometry Dash

Geometry Dash

Latest update Geometry Dash download for free for Windows PC or Android mobile

4
539 reviews
300008
downloads

News and reviews for Mobile Android

XChat Expands Features to Rival Major Messaging Apps

XChat, led by Elon Musk, enhances messaging with encryption, file sharing and more to challenge WhatsApp and iMessage.

Read more

Red Ronin Leads Top Android Game Discounts This Week

Red Ronin, a tactical turn-based game, is featured among top discounted deals on Google Play. Highlights include significant discounts on Galaxy Watch 7 and more.

Read more

Device Security Alert: Concerns Over Android Vulnerabilities

Significant security vulnerabilities in Android phones from Ulefone and Krüger&Matz have been identified by CERT Polska, risking user data. Prompt updates are advised.

Read more

Gmail Embraces Material 3 Design with Latest Android Update

Gmail's latest update unveils a Material 3-inspired UI, following the Android 16 design framework. The card-based changes include a fresh interface with a revised 'Compose' feature and search bar, aiming to bring consistency to Google's app ecosystem.

Read more

New Google App Brings AI Models to Android Devices

Google has unveiled an Android app enabling local use of AI models without internet, including interactive features and image analysis.

Read more

Gemini Introduces Email Summary Cards to Gmail on Mobile

Gemini launches new summary cards for Gmail on Android and iOS. These AI-powered tools offer automatic updates at the top of emails, assisting users in managing long threads effectively. Smart features must be enabled for full functionality.

Read more

Google Photos Enhances Experience with New Features

Marking its 10th anniversary, Google Photos introduces updated editing, AI, and sharing features to enhance user experience.

Read more

Google Enhances Android Phone App for Better User Experience

Google is preparing to release updates to the Android Phone app, improving readability and enhancing the user experience with new design elements.

Read more

Kiosk Software Enhances Business Operations and Security

Kiosk software streamlines business operations by optimizing Android devices for specific tasks. Leading software providers like Scalefusion and KioWare offer crucial features that enhance efficiency and ensure security, making these tools essential for many industries.

Read more

Auto-rotation Innovations Enhance Android Experience

Samsung's One UI and MacroDroid enhance Android's auto-rotation, enabling users to tailor screen rotation for specific apps effortlessly.

Read more