Necro Trojan Malware Found in Google Play Apps and Unofficial Mods

24 Sep 2024

Necro Trojan: A Growing Threat in the Digital Landscape

Recent findings from security researchers have unveiled a concerning trend involving certain Google Play apps and unofficial modifications of popular applications being exploited to disseminate a particularly insidious malware known as the Necro trojan. This malware exhibits a range of malicious capabilities, including keystroke logging, sensitive information theft, installation of additional malware, and remote command execution.

The Necro trojan first emerged in 2019, gaining notoriety when it infected the widely used PDF maker app, CamScanner. At that time, the official version of the app, boasting over 100 million downloads, posed a significant risk to users until a timely security patch resolved the issue.

According to a recent report by Kaspersky researchers, a new iteration of the Necro trojan has been detected within two applications on the Google Play Store: the Wuta Camera app, which has surpassed 10 million downloads, and Max Browser, with over a million downloads. Following Kaspersky’s alert, Google promptly removed the infected applications from its platform.

The Role of Modded APKs

The root of the problem lies in the proliferation of unofficial ‘modded’ versions of popular applications, frequently hosted on numerous third-party websites. Users may inadvertently download and install these modified Android application packages (APKs), thereby compromising their devices. Among the identified APKs harboring the malware are altered versions of well-known apps such as Spotify, WhatsApp, and games like Minecraft, Stumble Guys, Car Parking Multiplayer, and Melon Sandbox. These modded versions often entice users with promises of features typically reserved for paid subscriptions.

Interestingly, the attackers have employed a variety of tactics to ensnare users. For instance, the Spotify mod was found to contain a software development kit (SDK) that displayed multiple advertising modules. A command-and-control (C&C) server was activated to deploy the trojan payload whenever a user inadvertently interacted with the image-based module.

Similarly, in the case of the WhatsApp mod, researchers discovered that the attackers had manipulated Google’s Firebase Remote Config cloud service, repurposing it as their C&C server. Engaging with the module would trigger the deployment and execution of the same malicious payload.

Malware Capabilities and User Impact

Once activated, the malware is capable of downloading executable files, installing third-party applications, and opening hidden WebView windows to execute JavaScript code. Alarmingly, it can also subscribe users to costly paid services without their consent.

Although the compromised apps on Google Play have been removed, users are strongly advised to exercise caution when downloading Android applications from third-party sources. If there is any doubt regarding the trustworthiness of a marketplace, it is prudent to avoid downloading or installing any apps or files from that source.

Top charts for Mobile Android

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
7508580
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1735481
downloads
WinRAR

WinRAR

Streamline file management with fast compression, secure your documents, and save space.

5
735 reviews
746747
downloads
Minecraft

Minecraft

Shape environments, explore vast worlds, and survive against monsters with endless creativity.

5
750 reviews
496203
downloads

News and reviews for Mobile Android

Top Coin Apps Enhance Coin Valuation and Identification

Coin apps improve currency valuation and identification, aiding collectors and investors in the U.S. as of 2026. Key apps include CoinKnow and PCGS CoinFacts.

Read more

Optimize Android Apps Beyond Frontend with Backend Focus

Android apps need robust architecture and backend integration for high performance. Developers should focus beyond the UI to address backend challenges.

Read more

Explore Alternatives as Android Auto Exits Vehicles

Automakers shift from Android Auto, prompting tech users to adapt with alternatives.

Read more

WeChat Faces Potential U.S. Ban Amid Security Concerns

WeChat, a Tencent-owned app, may face a U.S. ban due to alleged ties with Chinese criminal networks, impacting national security.

Read more

Discounted Android App Deals for Gamers and Users

Discover top Android app deals available now, featuring discounted games for 2026-01-27.

Read more

iA Writer Boosts Focus for Writing-First Users

iA Writer helps reclaim focus for writers with distraction-free design. Notion users may prefer its simplicity for dedicated writing tasks.

Read more

Android Deals: Price Drops on Top Apps and Games

Check out the latest Android deals featuring popular games like D&D Lords of Waterdeep and Beastie Bay DX.

Read more

Today's Top App Deals: Lords of Waterdeep & More

Discover the latest app deals on Android with price drops for top games including Lords of Waterdeep and Legends of Heropolis.

Read more

Warframe Expands to Android with Cross Play, Save Features

Warframe launches on Android 2025-02-18, offering Cross Play and Save. Players gain rewards for early participation.

Read more

Waze Enhances Features for Android Auto Users

Waze adds improved navigation and alerts on Android Auto. Users in the US, Canada, Mexico, and France will see changes soon.

Read more