Google Play apps downloaded 300,000 times stole bank credentials

Discussion in 'Headline News' started by RickAgresta, Nov 30, 2021.

  1. RickAgresta

    RickAgresta General Peanut, leader of the Peanutty Forces

    Messages:
    22,506
    Likes Received:
    21,527
    Trophy Points:
    288
    Crooks find new ways to prevent Google from detecting malicious packages.
    Researchers said they’ve discovered a batch of apps downloaded from Google Play more than 300,000 times before the apps were revealed to be banking trojans that surreptitiously siphoned user passwords and two-factor authentication codes, logged keystrokes, and took screenshots.

    The apps—posing as QR scanners, PDF scanners, and cryptocurrency wallets—belonged to four separate Android malware families that were distributed over four months. They used several tricks to sidestep restrictions that Google has devised in an attempt to rein in the unending distribution of fraudulent apps in its official marketplace. Those limitations include restricting the use of accessibility services for sight-impaired users to prevent the automatic installation of apps without user consent.

    Small footprint

    “What makes these Google Play distribution campaigns very difficult to detect from an automation (sandbox) and machine learning perspective is that dropper apps all have a very small malicious footprint,” researchers from mobile security company ThreatFabric wrote in a post. “This small footprint is a (direct) consequence of the permission restrictions enforced by Google Play.”

    Instead, the campaigns typically delivered a benign app at first. After the app was installed, users received messages instructing them to download updates that installed additional features. The apps often required updates to be downloaded from third-party sources, but by then, many users had come to trust them. Most of the apps initially had zero detections by malware checkers available on VirusTotal.

    The apps also flew under the radar by using other mechanisms. In many cases, the malware operators manually installed malicious updates only after checking the geographic location of the infected phone or by updating phones incrementally.

    “This incredible attention dedicated to evading unwanted attention renders automated malware detection less reliable,” the ThreatFabric post explained. “This consideration is confirmed by the very low overall VirusTotal score of the 9 number of droppers we have investigated in this blogpost.”
    The malware family responsible for the largest number of infections is known as Anatsa. This “rather advanced Android banking trojan” offers a variety of capabilities, including remote access and automatic transfer systems, which automatically empty victims’ accounts and send the contents to accounts belonging to the malware operators.

    The researchers wrote:
    Three other malware families found by the researchers included Alien, Hydra, and Ermac. One of the droppers used to download and install malicious payloads was known as Gymdrop. It used filter rules based on the model of the infected device to prevent the targeting of researcher devices.

    New workout exercises

    “If all conditions are met, the payload will be downloaded and installed,” the post stated. “This dropper also does not request Accessibility Service privileges; it just requests permission to install packages, spiced with the promise to install new workout exercises—to entice the user to grant this permission. When installed, the payload is launched. Our threat intelligence shows that at the moment, this dropper is used to distribute [the] Alien banking trojan.”

    The researchers listed 12 Android apps that participated in the fraud. The apps are:

    upload_2021-11-30_17-13-6.png
    Asked for comment, a Google spokesman pointed to this post from April detailing the company’s methods for detecting malicious apps submitted to Play.

    Over the past decade, malicious apps have plagued Google Play on a regular basis. As was the case this time, Google is quick to remove the fraudulent apps once it has been notified of them, but the company has been chronically unable to find thousands of apps that have infiltrated the bazaar and infected thousands or even millions of users.

    It’s not always easy to spot these scams. Reading user comments can help, but not always, since crooks often seed their submissions with fake reviews. Steering clear of obscure apps with small user bases can also help, but that tactic would have been ineffective in this case. Users should also think carefully before downloading apps or app updates from third-party markets.


    The best advice for staying safe from malicious Android apps is to be extremely sparing in installing them. And if you haven’t used an app for a while, uninstalling it is a good idea.


    Link to article:
    https://arstechnica.com/information...wnloaded-300000-times-stole-bank-credentials/
     
    scjjtt, lelisa13p and Hook like this.
Loading...

Share This Page