Malware News Android Trojan Can Buy and Install Apps from Google Play Store

BoraMurdar

Super Moderator
Thread author
Verified
Staff Member
Well-known
Aug 30, 2012
6,598
Russian security firm Dr.Web has discovered a new Android-targeting trojan that has the capability of buying and then installing applications hosted on the Google Play Store.

Named Android.Slicer, this trojan is embedded in a phone optimization app that offers to clean the device's memory, shutting down unused applications.

The app can also turn on/off a phone's Wi-Fi and Bluetooth module via quick commands shown on the user's homescreen in the form of a floating popup.

Your classic adware trojan...
This app ends up on devices either installed by users themselves or by other malware. Once it reaches a device, it will gather information about the smartphone and send it to its C&C server.

This includes the phone's IMEI identifier, MAC address, device manufacturer, and OS version.

At this point, the Android.Slicer C&C server will reply by telling the trojan to display ads, open a page in the user's browser, or open the Google Play Store on a designated app page.

... with a twist
In the latter case, security researchers have observed that, for devices running Android 4.3, Android.Slicer will download a rootkit named Android.Rootkit.40 that will root the device and give Android.Slicer enhanced control of the OS.

The trojan uses these new-found powers to tap on buttons shown inside the Play Store app, such as the "Continue," "Install," and "Buy" buttons.

This functionality can lead to serious financial damage for infected users, but the good news is that Google prevents the rootkit from working on devices running the SELinux component, which comes with all Android versions 4.4 and higher.

Despite this intrusive behavior, Android.Slicer's main functions are to deliver adds to all infected devices.

Once the trojan installs these new apps, Android.Slicer can also add a shortcut to the user's homescreen for all the new apps it managed to install.

android-trojan-can-buy-and-install-apps-from-google-play-store-507012-2.jpg
 

DardiM

Level 26
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
May 14, 2016
1,597
Thanks for the share :)

A lot of people are using android version < 4.4 :(
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top