Pokémon Go’ App Contains Droidjack Malware: Better Wait For An Official Release

O

Omnipotent

Thread author
If you downloaded Pokemon GO on your android device before it was officially released off a third-party website then your device may have been infected.

------------------------------------------------------------------------------------------------------

Augmented mobile reality game Pokémon Go was first rolled out in Australia and New Zealand. In the frenzy that happened right after, gamers on Android devices who could not wait for the app to be officially rolled out to their regions decided to search for and download the game's APK to get the title into their smartphones ahead of the planned release in their country.

The method, while used by many gamers to begin their Pokémon Go journey earlier, had some risk involved as the app that users downloaded could be a malicious one.

It seems that the risk is now a reality, as security research company Proofpoint has discovered a version of the Pokémon Go APK that contains malware.

The infected version of Pokémon Go contains Droidjack, also known as SandroRAT, which is a malicious remote access tool that basically gives the attacker complete control over the devices of their victims.

The infected Pokémon Go APK was uploaded to a malware repository service less than 72 hours after the game's initial release in Australia and New Zealand, showing that hackers did not waste any time in releasing the Droidjack-injected APK.

Because of the gradual rollout of Pokémon Go, with the United States seeing the app at the Google Play Store about half a day after it was launched in Australia and New Zealand, and the global rollout now paused due to server issues, there is a high demand for the app's APK, and this massive demand was exploited by hackers.

If you are one of these gamers who downloaded and installed an APK for Pokémon Go ahead of its official release in your country, there are a couple of ways to check if the app that is in your mobile phone is the legitimate one or the infected one.

One of the methods that Proofpoint mentioned is to check the permissions of the installed Pokémon Go by going to the Andorid device's Settings menu, then heading to the Apps section and selecting Pokémon Go. Under the game's permissions section, red flags that indicate the presence of the Droidjack malware include granted permissions to make phone calls, access SMS messages, record audio, modify contacts, read internet bookmarks and history, connect or disconnect from a Wi-Fi network, and run upon startup.


Read more: Infected ’Pokémon Go’ App Contains Droidjack Malware: Better Wait For An Official Release
 
Last edited by a moderator:

DJ Panda

Level 30
Verified
Top Poster
Well-known
Aug 30, 2015
1,928
I tried downloading it on my kindle (nothing is supported on the closest thing I have to a phone :p ) Wouldn't let me play it because of the GPS not working even though I have one. Also MBAM Moibke acted as though it was the first time I ever booted it up but I still had past logs. Didn't find any malware though.
 
  • Like
Reactions: Der.Reisende

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Well you can have Pokémon Go on 3rd party APK store which are trusted;

That is why reviews and ratings are implemented.

------------------------------

I already know that news from Facebook itself, definitely a payload will execute based on analysis of fake APK.

Internet, Camera and GPS are the requirements to install that game.
 

simbelmayne

Level 3
Verified
Jul 4, 2016
101
My wife installed it few days ago, and it's completely ok. Maybe, because there's no free space on her phone, after the installation of Hearthstone and PokemonGo. Ideal recipe for android security - keep your device packed to the eyeballs, and it wil be ok =)
 
  • Like
Reactions: Der.Reisende
G

Guest28

Thread author
image.jpeg
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
No Issue if you are going to sign the Google Account but rather think of it since the permission may provide below the belt conditions.
 

NekoHr

Level 3
Verified
Well-known
Feb 5, 2016
139
It would be good to have file hashes for every download, there are none on Google plays.
 

EmilyPx

Level 1
Verified
Aug 1, 2016
22
as for me this game is just wasting of time
better go out with your friends without phones and talk
 
  • Like
Reactions: frogboy

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top