New research from Check Point has uncovered a number of apps posing as anti-virus solutions to spread ‘Sharkbot’ malware via the Google Play Store.
The potent malware steals credentials and banking information of Android users, luring victims to enter credentials in windows that mimic legitimate credential input forms.
Once infected, the malware gains control of a large part of the victim’s device, researchers warned.
Spreading Sharkbot malware on Play Store
In total, Check Point research uncovered six malicious applications which affected at least 1,000 individual IPs in the space of a week.
According to Google Play statistics referenced in the study, the six malicious applications were also downloaded over 11,000 times, with the majority of victims located in Italy and the UK.
Alexander Chailytko, Cyber Security Research & Innovation Manager at Check Point said that the threat actors responsible “strategically chose” Google’s Play Store in an attempt to gain users’ trust.
Recommended
- DIGIT Deal Roundup | March 2022
- Apprentice Employer of the Month: Tech employers needed to mould new apprenticeships
- Police cut down Hydra, world’s largest dark web market
He added: “I think it’s important for all Android users to know that they should think twice before downloading any anti-virus solution from the Play Store. It could be Sharkbot.”
Check Point Research reported its findings to Google, which proceeded to permanently remove the applications.
Who is responsible?
Notably, four of the malicious apps came from three specific developer accounts – Zbynek Adamcik, Adelmio Pagnotto and Bingo Like Inc.
Some of the applications linked to these accounts were removed from Google Play, but still exist in unofficial markets.
Check Point said this could mean that the actor behind the apps is trying to stay under the radar while still involved in malicious activity.
Notably, researchers learned that the malware authors implemented a geo-fencing feature which purposefully ignored users in China, Russia, Ukraine, Belarus and India.
Although Check Point said it does not have enough evidence to make an attribution, researchers did say “we can assume that the malware authors speak Russian”.
Get the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





