Over 60K Adware Apps Posing as Cracked Versions of Popular Apps Target Android Devices

June 6, 2023Ravi LakshmananMobile Security/Malvertising

adware app

As part of a campaign that began in October 2022, thousands of adware apps for Android were found disguised as cracks or mods of popular apps, redirecting users and serving unwanted ads to them.

“This campaign is designed to aggressively push adware onto Android devices for the purpose of increasing revenue,” Bitdefender said in a technical report shared with The Hacker News. “However, threat actors involved can easily switch tactics.

It redirects users to other types of malware such as banking Trojans and ransomware to steal credentials and financial information. “

A Romanian cybersecurity firm said it had found 60,000 unique apps with adware, mostly in the US, South Korea, Brazil, Germany, UK, France, Kazakhstan, Romania and Italy.

cyber security

It’s worth pointing out that none of the apps are distributed through the official Google Play store. Instead, users searching for apps like her Netflix, PDF viewers, security software, and cracked versions of her YouTube on search engines are redirected to ad pages that host malware.

Once installed, these apps have no icon or name to avoid detection.Additionally, users launching the app for the first time after installation will be prompted with the message “The application is not available in the region where the app is offered. To uninstall[OK]Tap ” and secretly activates malicious activity in the background.

The other modus operandi is an area to watch, where the adware’s behavior remains dormant for the first few days, after which the victim uses an Android WebView to deliver full-screen ads to the mobile phone. Unlocking wakes up adware.

The findings reveal that cybersecurity firm CloudSEK has identified the rogue SpinOK SDK (disclosed by Doctor Web last month) in 193 apps with 30 million downloads on the Google Play store. announced after receiving

upcoming webinars

🔐 Mastering API Security: Understanding Your True Attack Surface

Uncover untapped vulnerabilities in your API ecosystem and take proactive steps towards ironclad security. Join us for an insightful webinar!

join the session

On the surface, the SpinOk module is designed to keep users engaged with the app by making use of mini-games and tasks to earn rewards. However, a peek under the hood reveals that the Trojan hides the ability to steal files and replace the contents of the clipboard.

In a related development, the SonicWall Capture Labs threat research team also discovered another class of Android malware that masquerades as a legitimate app and exploits the operating system’s accessibility services to gather extensive information from compromised devices.

adware app

“These capabilities allow attackers to access a victim’s device and steal valuable information, potentially leading to various types of fraud, including financial fraud and identity theft,” SonicWall said. Stated.

Did you enjoy this article? Follow us twitter You can read more exclusive content we post on LinkedIn.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *