Necro Trojan Compromises 11 Million Android Devices Worldwide

24 Sep 2024

The Evolution of Necro

In 2019, cybersecurity experts unearthed a seemingly legitimate Android application on the Google Play Store that had been subtly undermined by an ad library implemented by its developers. This breach led to a staggering 100 million devices falling victim to the malware. Fast forward five years, and Kaspersky has reported the return of the Necro Trojan, now affecting around 11 million Android users worldwide. This latest iteration has evolved, boasting new features and infiltration techniques that render it more adaptable, elusive, and potentially more hazardous than its predecessor.

The malware primarily disseminates through unverified ad integration tools employed by app developers, unofficial app sources, and modified versions of widely-used applications. Alarmingly, it has even infiltrated the Google Play Store, affecting apps like Wuta Camera and Max Browser.

Key Differences in the New Version

This reincarnation of the Necro Trojan exhibits several notable distinctions from its original form. It employs sophisticated obfuscation techniques to evade detection, with its malicious payload cleverly concealed within innocuous-looking PNG images. Moreover, various malicious modules can be combined for diverse actions on compromised devices.

While the original version infiltrated apps through an unverified ad integration tool, the new variant is believed to exploit a malicious software development kit designed for ad integration. This time, the Necro Trojan has successfully infiltrated multiple applications on Google Play, including:

  • Wuta Camera – 10 million downloads
  • Max Browser – 1 million downloads
  • Modded versions of Spotify
  • Unofficial mods for WhatsApp, Minecraft, Stumble Guys, Car Parking Multiplayer, and Melon Sandbox

In 2019, Kaspersky identified the malware within CamScanner, a text recognition app that had amassed over 100 million downloads on Google Play.

Malicious Capabilities

Once activated, the Necro Trojan possesses a range of malicious capabilities, including:

  • Downloading and executing DEX files
  • Installing additional applications
  • Tunneling through the victim’s device to facilitate the routing of malicious traffic or circumventing network security
  • Subscribing to paid services without user consent
  • Interacting with ads in invisible windows to generate fraudulent ad revenue for the attackers
  • Opening arbitrary links to execute JavaScript code
  • Uploading user data to attacker-controlled servers
  • Downloading malicious code with elevated system privileges

Precautionary Measures

To safeguard against the Necro Trojan, users are encouraged to adopt some straightforward yet effective precautions:

  1. Avoid downloading apps from unofficial sources.
  2. Exercise caution even with applications sourced from official platforms.
  3. Steer clear of modded or hacked versions of apps.
  4. Utilize reputable mobile security software for added protection.

The resurgence of the Necro Trojan serves as a stark reminder of the persistent threat posed by mobile malware, having already compromised 11 million devices globally. This situation underscores the critical need for users to exercise caution when downloading and utilizing mobile applications. With Necro now active, vigilance is paramount, particularly regarding modified versions of popular apps. Users are advised to meticulously verify the source and permissions of any application prior to installation.

Top charts for Mobile Android

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6831188
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1469516
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
608451
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
468555
downloads

News and reviews for Mobile Android

Google Play Offers Mid-Week Android Deals

Google Play launches mid-week Android deals. Key apps: Wind Peaks, Red Ronin, Undergrave.

Read more

Launch Announced for Star Wars CCG with All-Star Roster

Lucasfilm Games unveils a new Star Wars CCG by Zero36 and CCG Lab. Expected on Android, iOS, PC. No release date yet.

Read more

CloverPit Expands to iOS and Android on 2023-12-17

CloverPit, the popular Balatro-inspired roguelite, launches on iOS and Android this December, offering a complete mobile experience for $5.

Read more

Apple Home Limited to Apple Devices, Missing Android Support

Apple Home remains exclusive to Apple devices, excluding Android users from smart home integration and control.

Read more

Google to Introduce Native App Lock on Android 17

Android 17 will feature a system-level App Lock for Pixel users, enhancing privacy with biometric options.

Read more

Android 17 Introduces Native AppLock for Enhanced Security

Android 17 may add AppLock to secure apps without third-party tools. Expected in the 2024 update. Improves device security.

Read more

Google Play Books Marks 15 Years of E-Reading Excellence

Google Play Books, now 15 years old, remains a top e-reading app, offering versatile features for DRM-free and cross-device book access.

Read more

LibrePods Enhances AirPods on Android Amid Bluetooth Bug

LibrePods adds features to AirPods on Android but needs root due to a Bluetooth bug. Over 9,100 votes urge Google to fix it.

Read more

Top Casino Apps Enhance Gaming Experience in Pennsylvania

In 2025, top Pennsylvania casino apps offer bonuses and enhanced features for iPhone and Android players, boosting user experience.

Read more

Amazon Enhances CloudWatch RUM with Mobile Support

Amazon CloudWatch RUM now monitors iOS and Android apps, boosting mobile observability with real-time metrics and insights.

Read more