Avast Blog_Threat Reseach: Fake mobile CCleaner app sneaked into the China Baidu app
#1
Bug 
Quote:[Image: TVDumYE.png]

[Image: genuine-vs-fake-apps-baidu.jpb.jpg?width=900]

Fake CCleaner app loaded with adware

Recently, Avast has discovered that a new fake mobile CCleaner app has been published in the China Baidu App Store (百度手机助手) and it’s specified as Certified Official Version (官方版).

This caught our eye because Avast hasn’t published any official versions of the CCleaner app in the Baidu App Store -- and the story begins.

The Baidu App Store

You can clearly see how this fake CCleaner app is being described on the web page and trying to trick users into downloading it.  It is being presented as the Certified Official Version (官方版). It also has a Chinese title which makes it appear to be official in the Baidu App Store.  One noticeable flaw, however, is in how they incorrectly categorized it under “办公学习 (office learning utilities).”  Another red flag is that it is receiving bad scores whereas, in other app stores around the world, CCleaner has top scores.


[Image: 1-fake-app-in-baidu.png?width=1600&name=...-baidu.png]

Analyzing the fake app with apklab.io

With Avast’s latest mobile threat intelligence platform, apklab.io, researchers can easily see the difference between this fake app and the genuine CCleaner app without trying to reverse engineer the app.

Comparing basic app metadata

First, you quickly notice two things:  1) the fake app is repackaged with a different app name (CCleaner垃圾清理) and a different package name (com.star.ccleaner) and 2) one extra service was introduced with the fake app.
Full Reading
[-] The following 2 users say Thank You to harlan4096 for this post:
  • darktwilight, jasonX
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
QOwnNotes
26.5.7 Note text ...Kool — 03:54
NanaZip 6.0 Update 7 (6.0.1711.0)
NanaZip 6.0 Update...harlan4096 — 06:10
Vivaldi 7.9 Build 3970.64
Vivaldi 7.9 Build ...harlan4096 — 06:09
Thunderbird 150.0.2 & Thunderbird 140.10...
Thunderbird 150.0....harlan4096 — 06:08
Brave v1.90.121 (Chromium 148.0.7778.96)
Release v1.90.121 ...harlan4096 — 06:07

[-]
Birthdays
Today's Birthdays
avatar (45)talsmanthago
avatar (31)mocetor
avatar (46)piomaibhaict
avatar (51)kingbfef
avatar (38)izenesiq
Upcoming Birthdays
avatar (28)akiratoriyama
avatar (48)Jerrycix
avatar (40)awedoli
avatar (82)WinRARHowTo
avatar (38)owysykan
avatar (49)beautgok
avatar (39)axuben
avatar (40)ihijudu
avatar (45)tiojusop
avatar (42)Damiennug
avatar (40)acoraxe
avatar (49)contjrat
avatar (41)axylisyb
avatar (44)tukrublape
avatar (44)knigiJow
avatar (46)1stOnecal
avatar (50)Mirzojap
avatar (36)idilysaju
avatar (40)GregoryRog
avatar (45)mediumog
avatar (40)odukoromu
avatar (46)Joanna4589

[-]
Online Staff
akiratoriyama's profile akiratoriyama
Administrator

>