Necro Malware Loader Infects 11 Million Android Devices via Google Play

25 Sep 2024

Necro Trojan on Google Play

The emergence of a new version of the Necro malware loader has raised significant concerns in the cybersecurity landscape, particularly for Android users. This sophisticated malware has infiltrated approximately 11 million devices through Google Play, leveraging malicious software development kits (SDKs) embedded in legitimate applications. These SDKs were found in various Android game modifications and altered versions of widely-used software, including Spotify, WhatsApp, and Minecraft.

Once installed, the Necro Trojan deploys a range of harmful payloads, activating a variety of malicious plugins designed to exploit users. The notable functionalities include:

  • Adware: Operates through invisible WebView windows, utilizing plugins such as Island and Cube SDK.
  • Modules: Capable of downloading and executing arbitrary JavaScript and DEX files through Happy SDK and Jar SDK.
  • Tools: Specifically crafted to facilitate subscription fraud, including Web plugin, Happy SDK, and Tap plugin.
  • Mechanisms: Repurpose infected devices as proxies to route malicious traffic, exemplified by the NProxy plugin.

Kaspersky’s investigation unveiled the presence of the Necro loader in two popular applications available on Google Play, both boasting substantial user bases. The first, Wuta Camera by ‘Benqu,’ is a photo editing tool that has garnered over 10 million downloads. The malware was introduced with version 6.3.2.148 and persisted until version 6.3.6.148, at which point Kaspersky alerted Google. Although the trojan was eradicated in version 6.3.7.138, remnants of the malware may still linger on devices that had previously installed the affected versions.

The second app identified as a carrier of the Necro Trojan is Max Browser by ‘WA message recover-wamr,’ which had amassed 1 million downloads before its removal following Kaspersky’s findings. The latest version, 1.2.0, still harbors the malware, leaving users with no clean upgrade option. Kaspersky advises immediate uninstallation of Max Browser in favor of safer alternatives.

The analysis revealed that both applications were compromised via an advertising SDK named ‘Coral SDK,’ which utilized obfuscation techniques to conceal its malicious intent. Additionally, it employed image steganography to download a secondary payload, shellPlugin, disguised as innocuous PNG images.

Outside Official Sources

Beyond the confines of the Play Store, the Necro Trojan predominantly spreads through modified versions of popular applications available on unofficial websites. Kaspersky has identified several notorious examples, including WhatsApp mods like ‘GBWhatsApp’ and ‘FMWhatsApp,’ which claim to offer enhanced privacy features and extended file-sharing capabilities. Another example is the Spotify mod, ‘Spotify Plus,’ which promises free access to premium services without advertisements.

The report also highlights the prevalence of Minecraft mods and other game modifications, such as those for Stumble Guys, Car Parking Multiplayer, and Melon Sandbox, all of which have been compromised by the Necro loader. In each instance, the malware’s behavior remains consistent—displaying ads in the background to generate revenue for cybercriminals while compromising user security.

In response to these revelations, Google acknowledged awareness of the reported applications and stated that they are currently investigating the matter.

Top charts for Mobile Android

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6474791
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1307724
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
502593
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
455021
downloads

News and reviews for Mobile Android

Google Play Store Adds XR App Section

Google Play Store updates with an XR section, boosting app visibility on compatible devices.

Read more

AirSync Enhances macOS and Android Integration

AirSync enables Android notifications, clipboard syncing, and easy file transfers on macOS.

Read more

Google Introduces Advanced Sideloading for Experienced Android Users

Google will offer advanced sideloading on Android to experienced users with warnings and safeguards, affecting app installation options.

Read more

Google Introduces Advanced Flow for Sideloading on Android

Google will allow experienced users to sideload unverified Android apps, making the process safer in 2025.

Read more

Google Introduces Sideloading Workflow for Unverified Apps

Google unveils a new sideloading process for unverified app developers, responding to feedback about privacy concerns and user security.

Read more

Reducing Bloatware: Maximizing New Phone Experience

Transitioning to a new Pixel 10 Pro, users should critically assess bloatware and consider superior third-party apps for enhanced functionality.

Read more

Google Eases Sideloading Rules for Experienced Android Users

Google allows sideloading for experienced Android users, adjusting developer verification plans. Global rollout starts 2027.

Read more

Tandem Expands Mobi App to Android with FDA Clearance

Tandem Diabetes Care gains FDA clearance for its Android Mobi app, broadening U.S. market potential for automated insulin delivery.

Read more

Google Launches New Images Tab for iOS and Android

Google's app now features an Images tab, personalizing visual content on iOS and Android.

Read more

Google App Adds Personalized Images Tab for US Users

The Google app introduces a new Images tab for US Android and iOS users, offering a personalized visual feed.

Read more