FalseGuide Malware in Play Store Infects 2M Users, Forces Phones to Join Botnet

Bot

AI-powered Bot
Thread author
Apr 21, 2016
4,367
About 600,000 Android users have mistakenly installed malware on their devices straight from Google Play, the company's official app store.
According to cybersecurity researchers from Check Point, the malware was hidden in more than 40 fake companion guide apps for popular games, such as Pokemon GO and FIFA Mobile, which led to the malware's name being FalseGuide.

While originally it was believed the oldest fake guide to hit Google Play was uploaded in February this year, making this a recent campaign, the researchers went a little deeper and discovered additional apps from back in November 2016.

FalseGuide was believed to have infected north of 600,000 users, but the number now sits at 2 million Android users, all of whom have mistakenly downloaded and installed malware on their devices while seeking guides for their favorite games.

After infection, FalseGuide creates a silent botnet out of the infected devices for adware purposes.

"FalseGuide requests an unusual permission on installation – device admin permission. The malware uses the admin permission to avoid being deleted by the user, an action which normally suggests a malicious intention. The malware then registers itself to a Firebase Cloud Messaging topic which has the same name as the app. Once subscribed to the topic, FalseGuide can receive messages containing links to additional modules and download them to the infected device," the report shows.

Read more: FalseGuide Malware in Play Store Infects 2M Users, Forces Phones to Join Botnet
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Google created a security checker algorithm which is so passive to detect malicious program, yet so many information collected through search engine which may enough to have own AI for more in-depth security reasons.
 

Winter Soldier

Level 25
Verified
Top Poster
Well-known
Feb 13, 2017
1,486
"FalseGuide requests an unusual permission on installation – device admin permission.
I think the best Intelligence comes from people, but they must know how to use it, mainly by reading the permissions that an app require.
How many people do this?
 
  • Like
Reactions: frogboy

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top