Security News > 2021 > April > Android malware found embedded in APKPure store application

Android malware found embedded in APKPure store application
2021-04-10 14:40

Security researchers found malware embedded within the official application of APKPure, a popular third-party Android app store and an alternative to Google's official Play Store.

The malware was discovered by Kaspersky and Dr.Web malware analysts embedded within an advertisement SDK included with APKPure version 3.7.18.

"The identified malicious code embedded in APKPure operates in the following way: upon launch of the application, the payload is decrypted and launched," Kaspersky said.

The damage inflicted by this trojan varies depending on the Android version running on the compromised devices, ranging from being signed up for paid subscriptions and seeing intrusive ads on current versions to having unremovable malware like xHelper deployed on the system partition.

While no official download stats are available for the APKPure app, Kaspersky says that it has so far blocked the malware on the devices of 9,380 Android users running its security solutions on their devices.

Indicators of compromise, including APKpure app, payload, and malware sample hashes, are available at the end of Kaspersky's report.


News URL

https://www.bleepingcomputer.com/news/security/android-malware-found-embedded-in-apkpure-store-application/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Android 4 0 17 2 0 19