MORE

    17 Android apps nabbed in WAP billing fraud removed from the Google Play Store

    Google has recently removed 17 Android apps from the official Play Store. The 17 apps, were spotted by security researchers from Zscaler, were infected with the Joker (aka Bread) malware.

    - Advertisement -

    Zscaler security researcher Viral Gandhi said this week said that; “This spyware is designed to steal SMS messages, contact lists, and device information, along with silently signing up the victim for premium wireless application protocol (WAP) services.”

    The 17 malicious apps were uploaded on the Play Store this month and didn’t get a chance to gain a following, having been downloaded more than 120,000 times before being detected.

    - Advertisement -

    The names of the 17 apps include:

    • All Good PDF Scanner
    • Mint Leaf Message-Your Private Message
    • Unique Keyboard – Fancy Fonts & Free Emoticons
    • Tangram App Lock
    • Direct Messenger
    • Private SMS
    • One Sentence Translator – Multifunctional Translator
    • Style Photo Collage
    • Meticulous Scanner
    • Desire Translate
    • Talent Photo Editor – Blur focus
    • Care Message
    • Part Message
    • Paper Doc Scanner
    • Blue Scanner
    • Hummingbird PDF Converter – Photo to PDF
    • All Good PDF Scanner

    The way these infected apps usually manage to sneak their way past Google’s defenses and reach the Play Store is through a technique called “droppers,” where the victim’s device is infected in a multi-stage process.

    The technique is quite simple, but hard to defend against, from Google’s perspective.

    Malware authors begin by cloning the functionality of a legitimate app and uploading it on the Play Store. This app is fully functional, requests access to dangerous permissions, but also doesn’t perform any malicious actions when it’s first run.

    Because the malicious actions are usually delayed by hours or days, Google’s security scans don’t pick up the malicious code, and Google usually allows the app to be listed on the Play Store.

    - Advertisement -

    IN THIS STORY STREAM

    Victor Tinka
    Victor Tinka
    Exploring Computer Vulnerabilities is my passion but I always find my hands dirty with code. The only “IT guy” in the family which makes me feel like the family head :)

    Fresh Tech

    How Real-Time Processing Is Changing the Live Casino Experience for Users

    Remember the early days of the internet? Back in...

    Why over 1 Million Ugandans have downloaded Bitchat

    In a world where internet access is increasingly weaponized...

    Uganda Imposes Nationwide Internet Blackout Ahead of General Elections

    Uganda Imposes Nationwide Internet Blackout Ahead of January 15,...

    Mobile Tech and the Evolution of Sports Betting in Uganda

    The landscape of entertainment in East Africa has shifted...
    - Advertisment -

    Discover more from Techjaja

    Subscribe now to keep reading and get access to the full archive.

    Continue reading