Necro Trojan Malware Compromises Android Apps, Users Urged to Uninstall

25 Sep 2024

Google's Commitment to Android Security Faces New Challenges

Google's ongoing commitment to enhancing the security of its Android operating system has been a focal point in its efforts to protect users from malicious threats. Despite the robust security measures implemented, a recent discovery has cast a shadow over the safety of certain applications available in the Google Play Store. A newly identified variant of the Necro Trojan malware has reportedly infiltrated several Android apps, raising concerns among users.

Among the affected applications are popular modded versions of well-known platforms such as WhatsApp and Spotify. This revelation serves as a cautionary reminder for users who frequently download modified apps from unofficial sources, urging them to exercise heightened vigilance. Before delving deeper into the specifics of the Necro malware, it is essential to understand its nature and implications.

Kaspersky Says Necro Trojan Malware is Back

First identified by Kaspersky's security researchers in 2019, the Necro Trojan malware has resurfaced, posing a significant threat to Android devices. The malware's modus operandi involves infecting a user's device upon the installation of a compromised application. Once activated, Necro discreetly downloads additional malicious payloads, employing steganography to conceal these payloads within seemingly innocuous messages. This tactic not only generates revenue for the attackers through invisible ad displays but also adversely impacts the device's battery life and overall performance.

Furthermore, the malware can enroll the infected device in subscription services without the user's consent. Notably, the Necro payloads possess the capability to download and execute arbitrary JavaScript and DEX files, amplifying the potential for harm.

In a recent investigation, Kaspersky researchers identified a modded version of Spotify, specifically Spotify Plus (version 18.9.40.5), available on a website deemed hazardous by the security firm. This site falsely claimed that the app was safe and certified, promoting features unavailable in the official Spotify application.

Image credit: Kaspersky

The Malware Also Infected Some Apps from the Google Play Store

In addition to modded applications, Kaspersky's findings revealed that several legitimate Android apps, boasting a combined total of 11 million downloads on the Google Play Store, were also compromised by the Necro Trojan malware. One notable example is the Wuta Camera app, which alone accounted for 10 million downloads. Another affected application, Max Browser, had over 1 million downloads and was identified as infected since the release of version 12.0.

Fortunately, Google has acted swiftly to remove both the Wuta Camera and Max Browser apps from the Play Store. However, users who previously installed these applications are strongly advised to uninstall them immediately. Additionally, a modified version of WhatsApp with the same package name available in the Play Store was found to harbor the Necro loader. Researchers have also detected the presence of Necro malware in various other modded gaming apps, including Minecraft, Stumble Guys, Car Parking Multiplayer, and Melon Sandbox.

The security firm suggests that the actual number of infected devices may far exceed current estimates, particularly as tech-savvy users often download modded applications from unverified sources, complicating tracking efforts. The Necro attack has predominantly impacted Android users in regions such as Russia, Brazil, and Vietnam. Users are encouraged to review the list of affected apps and their versions to ensure prompt removal and safeguard their devices against this persistent threat.

Top charts for Mobile Android

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
7291193
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1676924
downloads
WinRAR

WinRAR

Streamline file management with fast compression, secure your documents, and save space.

5
735 reviews
717807
downloads
Minecraft

Minecraft

Shape environments, explore vast worlds, and survive against monsters with endless creativity.

5
750 reviews
489155
downloads

News and reviews for Mobile Android

Today's Top Android App Deals: Discounts on Popular Titles

Discover exciting app deals on Android, featuring titles like Dream Town Island and Conquistadorio. Elevate your digital library today.

Read more

Notability Expands to Android, Launch Set for 2026

Ginger Labs plans to bring Notability, its AI-enhanced note-taking app, to Android in 2026, aiming to replicate its iOS success.

Read more

Microsoft Lens App Retirement Announced for 2026

Microsoft Lens app to be retired for iOS and Android on 2026-02-09. Transition advised to OneDrive scanning feature.

Read more

Microsoft Lens to End on iOS and Android by 2026-02-09

Microsoft will discontinue Microsoft Lens for iOS and Android on 2026-02-09. Users should switch to OneDrive's scanner for future scans.

Read more

Google Introduces Universal Commerce Protocol for Retail

Google's UCP empowers AI agents for product search and payments, starting in the U.S.

Read more

Top 15 Apps to Enhance Your E-Ink Android Tablet Experience

Discover 15 essential apps for optimizing E-Ink Android tablets in 2026, boosting productivity and reading enjoyment.

Read more

DynamicSpot Brings Apple's Dynamic Island to Android

DynamicSpot introduces Apple's Dynamic Island-like feature to Android devices, enhancing notification management and multitasking.

Read more

Top Free Android Apps Enhance Routine Automation

Explore how 7 Android automation apps streamline daily routines, offering free tiers and advanced features.

Read more

Android 15 Introduces App Archiving to Optimize Storage

Android 15 allows app archiving, saving space without losing data. Available globally.

Read more

Google Tests 'Try Before You Buy' for Play Store Games

Google tests a 'try before you buy' feature on the Play Store, allowing users to trial paid games before purchase, enhancing user experience.

Read more