Malware News Android malware found inside apps downloaded 500,000 times

Faybert

Level 24
Thread author
Verified
Top Poster
Well-known
Forum Veteran
Jan 8, 2017
1,321
8,958
2,279
Brazil
Cyber criminals have distributed malware to hundreds of thousands of Android users by successfully hiding it inside a series of apparently harmless apps.

The malware sneaked onto the Google Play store disguised as seven different apps - six QR readers and one 'smart compass' - and bypassed security checks by hiding their true intent with a combination of clever coding and delaying the initial burst of malicious activity.

Following installation, the malware waits for six hours before it begins work on its true purpose - serving up adware, flooding the user with full screen adverts, opening adverts on webpages and sending various notifications containing ad related links.
....
....
he general purpose nature of the apps allowed the attackers to pull in a large number of downloads. When the malicious app is first run, it calls home for configuration information on a server controlled by those behind the scheme.

Crucially, in order to hide the nefarious nature of the download, no malicious operations are run on an infected device for the first few hours after installation.
...
...