Connect with us

Hi, what are you looking for?

HEADLINES

Kaspersky protects over 9,000 clients from malware attacks via infected marketplace app

Kaspersky experts have found malicious code in version 3.17.18 for the official client of the APKPure app store. To date, products belonging to 9,380 Kaspersky users have detected and blocked the threat.

Kaspersky experts have found malicious code in version 3.17.18 for the official client of the APKPure app store. To date, products belonging to 9,380 Kaspersky users have detected and blocked the threat.

According to the researchers, the code was found in the advertising library of the application. The code likely appeared there because of the app developers’ partnership with an unscrupulous advertiser. There was a similar case with the CamScanner incident, when a new advertising SDK from an unverified source was implemented.

The identified malicious code embedded in APKPure operates in the following way: upon launch of the application, the payload is decrypted and launched. It then collects information about the user device and sends it to the C&C server. Then, a Trojan is loaded that has much in common with the notorious Triada malware, in that it can perform a range of actions – from displaying and clicking ads to signing up for paid subscriptions and downloading other malware.

Afterwards, depending on the response received, the malware can:

Advertisement. Scroll to continue reading.
  • Show ads when the device is unlocked
  • Open browser pages with ads repeatedly
  • Load additional, executable modules

“Depending on the OS version, the Trojan can inflict various forms of damage on the victim. APKPure users with current Android versions are mostly at risk of having paid subscriptions and intrusive ads appear from nowhere. Users of smartphones who do not receive security updates are less fortunate: in outdated versions of the OS, the malware is capable of not only loading additional apps, but installing them on the system partition. This can result in an unremovable Trojan, like xHelper, getting onto the device. We were happy to inform the marketplace about the issue, which resulted in a fix for the version. We urge all APKPure users to immediately update the application to version 3.17.19,” comments Igor Golovin, security expert at Kaspersky.

Kaspersky solutions detected the malicious implant as HEUR:Trojan-Dropper.AndroidOS.Triada.ap.

Kaspersky reported the issue to the marketplace on April 8. The next day, it replied to Kaspersky, saying the issue would be solved in the new version. The fix was done in version 3.17.19, which is already available for download.

In order to stay safe, APKPure users are recommended to:

  • Immediately update the application to version 3.17.19
  • Scan the system for other Trojans using a reliable security solution, such as Kaspersky Internet Security for Android

Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

White Papers

When compared to 2023, Sophos saw a 51% increase in abusing “Living off the Land” binaries or LOLbins; since 2021, it’s increased by 83%.

HEADLINES

Someone illegally acquires or uses personal information such as bank account or credit card numbers of another person to obtain money, goods or services....

HEADLINES

To stay ahead of these challenges, organizations need to invest in AI-driven defenses, transition to quantum-safe encryption, and adopt a Zero Trust approach to...

HEADLINES

There was a 121% Year-on-Year (YoY) increase in identity fraud in 2024 across the region, with significant surges recorded in Singapore (207%), Thailand (206%)...

HEADLINES

As part of RCBC’s 2024 Cybersecurity literacy program, the webinar aims to help Filipinos level up their online banking safety by providing them with...

White Papers

The survey found that CXO’s feel less prepared than their global peers. Less than half or 48% in APAC said they felt completely prepared...

HEADLINES

On average, a single organization in the Philippines experiences 4,003 attacks per week, significantly higher than the APAC average of 2,870 attacks per week.

White Papers

Exploiting this vulnerability, cybercriminals craft deceptively authentic phishing emails that align with current trends, exploiting human emotions to invoke urgency and trick recipients into...

Advertisement