Kaspersky Finds Necro Malware in Popular Android Apps Wuta Camera, Max Browser

25 Sep 2024

Five years ago, a significant discovery by Kaspersky researchers unveiled a legitimate Android application lurking within the Google Play market, which had been compromised by a library intended for advertising revenue generation. This malicious entity, known as Necro, was responsible for infecting approximately 100 million devices, redirecting them to attacker-controlled servers to download covert payloads.

New Wave of Infections

In a recent turn of events, the same team at Kaspersky has identified two new applications that have collectively amassed 11 million downloads, both of which are tainted by the same malware family. The researchers suspect that a malicious software development kit (SDK) designed for integrating advertising functionalities is once again at the heart of this issue.

The first of the newly identified apps is Wuta Camera, which boasts an impressive 10 million downloads. Versions 6.3.2.148 through 6.3.6.148 of this app were found to harbor the malicious SDK responsible for the infections. Fortunately, the app has since undergone updates to eliminate the harmful component.

In addition to Wuta Camera, another app named Max Browser, which had around 1 million downloads, was also discovered to be infected. However, this particular app has been removed from the Google Play store.

Beyond Google Play

Moreover, Kaspersky’s investigation revealed that Necro has infiltrated a range of Android applications available in alternative marketplaces. These apps often masquerade as modified versions of well-known legitimate applications, including:

  • Spotify
  • Minecraft
  • WhatsApp
  • Stumble Guys
  • Car Parking Multiplayer
  • Melon Sandbox

The resurgence of Necro underscores the ongoing challenges in maintaining app security and the importance of vigilance among users when downloading applications from any marketplace.

Top charts for Mobile Android

News and reviews for Mobile Android

Google Enhances Live Threat Detection in PlayProtect

Google updates PlayProtect's Live Threat Detection, increasing user safety with enhanced alerts for harmful apps.

Read more

STAGE+ Launches Android App, Expands Streaming Access

STAGE+ releases its Android app on World Opera Day, offering free events and enhancing streaming availability and user experience.

Read more

Sora Update Introduces Pet Cameos and Android App

OpenAI's Sora app update adds pet cameos, basic editing, and announces Android version arrival.

Read more

Google Maps Adds 'Report' Button in Android Auto Update

Android Auto update brings 'Report' button to smaller screens. Users report incidents directly. Expected to enhance on-road safety.

Read more

Pixel Camera Requires Google Play Services in Update

Pixel Camera v10.x now needs Play Services, causing crashes on de-Googled devices like GrapheneOS.

Read more

Spotify Lossless Comes to Sonos; Android App Issues Surfaced

Spotify Lossless arrives for Sonos users with improved sound. Android app issues on Samsung and Pixel devices create challenges for users.

Read more

Meta Enhances Protection Against Scams on WhatsApp, Messenger

Meta adds new safeguards to protect WhatsApp, Messenger users, notably seniors, from scams.

Read more

Pixel Camera 10.x Requires Google Play Services

Pixel Camera update 10.x needs Google Play Services, affecting de-Googled systems and GrapheneOS.

Read more

Gboard Update Lets Users Customize Keyboard Layout

Google rolls out new Gboard settings on Android to remove the comma and period keys, improving customization options.

Read more

Apple Removes Tea App for Privacy Violations

Apple removes Tea app globally from App Store. Privacy concerns cited; alternative remains on Google Play.

Read more