Technology
42 malicious apps affected 8 million Android users
London, Oct 25
Security researchers have detected a massive year-long adware campaign where the involved apps were installed on users' Android devices eight million times from Google Play alone.
Slovak internet security company ESET identified 42 apps on Google Play as belonging to the campaign, which had been running since July 2018. Of those, 21 were still available at the time of discovery.
"We reported the apps to the Google security team and they were swiftly removed. However, the apps are still available in third-party app stores," said the researchers in a statement on Thursday.
Once launched, the "Ashas" adware family app sent "home" key data about the affected device: device type, OS version, language, number of installed apps, free storage space, battery status, whether the device is rooted and Developer mode enabled, and whether Facebook and FB Messenger are installed.
"The app receives configuration data from the command and control server (C&C) server, needed for displaying ads, and for stealth and resilience," said security researcher Lukas Stefanko.
Once a user installed an adware-infected app, the app will show full-screen ads on the device's display at intervals.
First, the malicious app tries to determine whether it is being tested by the Google Play security mechanism.
After dodging Google servers, the malicious app can set a custom delay between displaying ads. Based on the server response, the app can also hide its icon and create a shortcut instead.
"If a typical user tries to get rid of the malicious app, chances are that only the shortcut ends up getting removed. The app then continues to run in the background without the user's knowledge. This stealth technique has been gaining popularity among adware-related threats distributed via Google Play," the researchers noted.
According to the team, students at a Vietnamese university may be behind the malicious adware app.
"Due to poor privacy practices on the part of our culprit's university, we now know his date of birth, we know that he was a student and what university he attended. We retrieved his University ID; a quick googling showed some of his exam grades," said researchers.
"The malicious developer also has apps in Applea¿s App Store. Some of them are iOS versions of the ones removed from Google Play, but none contain adware functionality," said Stefanko.
Slovak internet security company ESET identified 42 apps on Google Play as belonging to the campaign, which had been running since July 2018. Of those, 21 were still available at the time of discovery.
"We reported the apps to the Google security team and they were swiftly removed. However, the apps are still available in third-party app stores," said the researchers in a statement on Thursday.
Once launched, the "Ashas" adware family app sent "home" key data about the affected device: device type, OS version, language, number of installed apps, free storage space, battery status, whether the device is rooted and Developer mode enabled, and whether Facebook and FB Messenger are installed.
"The app receives configuration data from the command and control server (C&C) server, needed for displaying ads, and for stealth and resilience," said security researcher Lukas Stefanko.
Once a user installed an adware-infected app, the app will show full-screen ads on the device's display at intervals.
First, the malicious app tries to determine whether it is being tested by the Google Play security mechanism.
After dodging Google servers, the malicious app can set a custom delay between displaying ads. Based on the server response, the app can also hide its icon and create a shortcut instead.
"If a typical user tries to get rid of the malicious app, chances are that only the shortcut ends up getting removed. The app then continues to run in the background without the user's knowledge. This stealth technique has been gaining popularity among adware-related threats distributed via Google Play," the researchers noted.
According to the team, students at a Vietnamese university may be behind the malicious adware app.
"Due to poor privacy practices on the part of our culprit's university, we now know his date of birth, we know that he was a student and what university he attended. We retrieved his University ID; a quick googling showed some of his exam grades," said researchers.
"The malicious developer also has apps in Applea¿s App Store. Some of them are iOS versions of the ones removed from Google Play, but none contain adware functionality," said Stefanko.
10 hours ago
Piyush Goyal meets Canadian Minister Maninder Sidhu to seal trade pact soon
11 hours ago
Marathi film ‘Gondhal’ announced as India's official selection for 99th Academy Awards
11 hours ago
Friendship Cup a celebration of cricket, reflects strong India-Afghanistan bond: DDCA chief Jaitley
15 hours ago
ActBlue faces scrutiny over foreign donations
15 hours ago
Kwatra recalls leadership lesson from mentorship under Satya Nadella’s father
17 hours ago
Zee TV’s Sa Re Ga Ma Pa – The Original Icon of Singing Shows is Back with Its Grandest Season Yet; Will Also Stream on ZEE5
17 hours ago
Lust Stories 3 Review: Four Stories. Unusual Desires and Plenty of Surprises
17 hours ago
Joey King: Sandra Bullock's one of the nicest people I’ve ever met in my life
17 hours ago
Upendra’s first look from Teja Sajja's 'Zombie Reddy2 NXT LVL' released!
17 hours ago
Karan Johar and Varun Dhawan to host IIFA Awards 2027 in Abu Dhabi
17 hours ago
Sana Thampi opens up about her first collaboration with Kiran Rao for ‘Lust Stories 3’
17 hours ago
Nivin Pauly pens note of gratitude as his Bethlehem Kudumba Unit's collections go past the Rs 300 crore mark!
17 hours ago
Actor Nani on why he does not want people to call his films pan-Indian!
