Site navigation

Kaspersky Flag Malicious Apps Problem on Google Play Store

Elizabeth Greenberg

,

malicious apps
Research by Kaspersky security solutions revealed over a million malware and unwanted software installers targeting mobile users in 2022. 

While installers most commonly distributed these malicious apps in already dubious app stores, their authors were sometimes able to upload them to Google Play and other official stores.

Using Kaspersky Digital Footprint Intelligence, the report revealed the growing trends around using Google Play as a platform for malicious and unwanted applications.

Although Google Play is “policed vigorously,” according to the report, developers of the scam apps have come up with new complex ways to bypass security checks.

And this ability is sought after – a loader able to deliver a malicious app to Google Play ranges between $2000 to even $20,000 on the darkweb, an underground internet marketplace.

Cryptocurrency trackers, financial apps, QR-code scanners, and dating apps were the most common applications for hiding malicious or unwanted software

How Does It Work?

On the darkweb, cybercriminals typically sell developer’s Google Play accounts that can be hacked, as well as source code that can help the buyer upload their apps to Google Play.

In addition, cybercriminals also offer to launch Google ads to attract more people to the malicious apps – the cost ranges depending on the country, with the USA and Australia being the most expensive.

To communicate and negotiate, the report found that most cybercriminals use personal messages on forums and messenger applications like Telegram in order to keep their activities accessible but low-profile.

According to the report, most of the offers analysed involved the vending of Google Play loaders – programmes that inject malicious or unwanted code into an existing app. Once updated, a victim will download the app with its malicious code that will then get uploaded onto their device.

Typically the malicious code is to get key insider data or access to other applications – the updated app will prompt the victim to give it access to things like the camera or microphone, as well as other key data points. Once the permissions are granted, the app can be used as normal but the device is already infected.

For those looking to infect a device for a smaller price point, cybercriminals also offer a binding service. This is essentially the same as Google Play loaders, but the application itself is not suitable for an official Android store. These apps are instead typically distributed via phishing tests or dubious websites.


Recommended


Binding services usually only cost about $50-$100, while a loader costs about $5,000.

For payment, cybercriminals typically accept three main kinds: a subscription or rent for the product, a one-time payment, or a percentage of the final profit using the malware.

Recommendations 

Kaspersky also provided some recommendations on how to spot and avoid malware-infected applications.

They recommend never enabling the installation of unknown applications – if an app is urging this, it is most likely infected. If you suspect this, it is best to uninstall the app altogether.

Consider carefully when deciding to grant an app permissions that do not serve it’s main function, especially for high risk permissions like Accessibility Services.

Further, updating the operating system and apps as soon as possible is also recommended. Scanning a device right after an update can identify if any of the updates are malicious.

Using a reliable security solution or antivirus is also recommended.

“For organizations, it is necessary to protect their developer accounts with strong passwords and 2FA, as well as monitor the dark web to detect and mitigate credential leaks as early as possible,” the report added.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data