Google Detects Android Spyware in Play Store, Removes It Before It’s Too Late

Bot

AI-powered Bot
Thread author
Apr 21, 2016
4,374
Android malware reaching the Google Play Store is not really something new, as infected apps are being detected on a regular basis, but search giant Google highlights one particular case that it managed to deal with thanks to the recently-released Google Play Protect security feature.

Specifically, Google says it came across a new form of Android spyware called Lipizzan which the company says is somehow linked to an Israeli company working with governments and intelligence agencies across the world.

An in-depth analysis of the malware reveals that apps managed to get past Google’s filters and become available for download in the Play Store using a new approach that relies on two-stage infection process.

“The first stage found by Google Play Protect was distributed through several channels, including Google Play, and typically impersonated an innocuous-sounding app such as a ‘Backup’ or ‘Cleaner’ app,” Google explains.

“Upon installation, Lipizzan would download and load a second ‘license verification’ stage, which would survey the infected device and validate certain abort criteria. If given the all-clear, the second stage would then root the device with known exploits and begin to exfiltrate device data to a Command & Control server.”

Read more: Google Detects Android Spyware in Play Store, Removes It Before It’s Too Late
 
  • Like
Reactions: Vasudev

ispx

Level 13
Verified
Well-known
Jun 21, 2017
616
just because it comes from the ' STORE ' need not mean it is safe, be it any store apple / google / microsoft / walmart ;) :D
 
  • Like
Reactions: Vasudev

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top