Trojanized Android App Found on Google Play with More Than 5,000 Installs
#1
Quote:An Android call recording application with hidden malicious code designed as a malware dropper was found by malware researcher Lukas Stefanko in the Google Play store.

At the moment Stefanko discovered the "Simple Call Recorder" application published by FreshApps Group already had over 5,000 installs and it was available on Google Play for since November 30, 2017.
Although Simple Call Recorder was a functional call recorder it also had another hidden purpose which " was to download an additional app and trick the user into installing it as Flash Player Update," according to Stefanko.

The malicious app tries to compromise the device it is installed on by decrypting a binary file which it loads from its assets, dynamically loading it, and subsequently asking the user to install a fake flash updater from http://adsmserver[.]club/up/update.apk (the installer is now removed and redirects to Google's AdMob.)
Because the malware payload was no longer available, it's impossible to know what the FreshApps Group Android developer used it for but, given the way it was designed to be downloaded on the targeted devices, it's quite evident that it was a malicious tool.

Source: https://news.softpedia.com/news/trojaniz...3743.shtml
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
GFYI [Official] Master PDF Editor Mothe...
We are pleased to an...jasonX — 05:45
GFYI [Official] HitmanPro.Alert Mother'...
GIVEAWAY HAS ENDED. ...jasonX — 05:07
GFYI [Official] Master PDF Editor Mothe...
GIVEAWAY HAS ENDED. ...jasonX — 05:07
ON1 Software
  20 Years of O...jasonX — 05:02
Celebrating 20 Years of ON1: ON1 Photo C...
Celebrating 20 Years...jasonX — 05:00

[-]
Birthdays
Today's Birthdays
avatar (47)vadimTob
avatar (37)leannauu4
Upcoming Birthdays
avatar (38)Tedscolo
avatar (45)brakasig
avatar (44)JamesReshy
avatar (46)Francisemefe
avatar (39)leoniDup
avatar (38)Patrizaancem
avatar (38)biobdam
avatar (41)zacforat
avatar (46)NemrokReks
avatar (37)Barrackleve
avatar (39)Julioagopy
avatar (49)aolaupitt2558
avatar (39)storoBox
avatar (47)kinotHeemn
avatar (38)Ceballos1976
avatar (39)efynu
avatar (31)horancos

[-]
Online Staff
There are no staff members currently online.

>