Site navigation

Malware Campaign Infects 60,000 Android Apps, Including 1,200 in the UK

Michael Edgar

,

Malware campaign infects Android
A massive malware campaign has been uncovered by Romanian cybersecurity firm Bitdefender, infecting over 60,000 Android apps worldwide, over 1,200 of which in the UK.

Bitdefender believes the campaign began sometime in October 2022. The threat actors used a campaign that aggressively pushes adware to android devices, and could redirect users to malware. There are 60,000 discovered unique apps carrying this adware and Bitdefender suspects there may be many more out there. 

The Romanian cybersecurity firm found the malware through an app anomaly detection technology – an industry first according to Bitdefender. Researchers believe that the malware had been thriving for an extended period of time due to the absence of behaviour-based detection capabilities on Android. 

“(The malware) most likely would have been able to stay undetected. Because of the high number of unique samples discovered, the operation is most likely fully automated,” said the researchers at Bitdefender.

The malware targeted many countries, predominantly the United States, followed by countries like South Korea, Brazil, Germany, and the United Kingdom.

The Process 

The malware was being distributed on apps not hosted on Google Play, such as games with unlocked features, free VPNs, fake videos and tutorials, Netflix, YouTube and TikTok without ads, cracked utility programs, and fake security programs.

Distribution happens when users search for these ‘modded’ apps. Websites dedicated to them will redirect them to an ad page, which would have the malware download disguised as the download portal for the modded app the user was looking for. 

From there, the installed app does not configure itself to run automatically, relying on the normal Android app installation flow. Once a user opens the app, they are faced with an error message, saying ‘the application is unavailable in your region, tap OK to uninstall’. 


Recommended


The app then waits two hours before registering two ‘intents’ to cause it to launch when the device is opened. 

From there, the app connects to servers which retrieve advertisement URLs, causing them to be displayed in the mobile browser. Bitdefender warns that the threat actors could easily swap the adware URLs for banking Trojans or ransomware URLs

Bitdefender warns users to only use the Google play store to download apps, not third party websites. It has also put together a video of the adware in action which can be watched here

Michael Edgar

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data