Security News > 2022 > March > Android trojan persists on the Google Play Store since January
Security researchers tracking the mobile app ecosystem have noticed a recent spike in trojan infiltration on the Google Play Store, with one of the apps having over 500,000 installs and available to download. Most of these apps belong to a family of trojan malware used in various scams, resulting in financial losses and also loss of sensitive personal information.
The threats discovered on the Play Store by Dr. Web's analysts include cryptocurrency management apps, social benefit aid tools, Gasprom investment clones, photo editors, and a launcher themed after iOS 15.
The majority of the apps reported by Dr. Web have been removed from the Play Store, so while they might have been popular and widely downloaded, we don't have any numbers to share.
Bleeping Computer was able to find one of the reported apps that's still available on the Play Store, Top Navigation, which has over 500,000 installations, making this a significant concern due to its widespread use.
By checking the developer, Tsaregorotseva, we found a second app on the Play Store, Advice Photo Power, with over 100,000 downloads.
In the trojanized versions, bundled malware attempts to snatch notifications from the Google Play Store and the Samsung Galaxy Store apps via the Flurry stat service.
News URL
Related news
- Fake Trading Apps Target Victims Globally via Apple App Store and Google Play (source)
- ‘Pig butchering’ trading apps found on Google Play, App Store (source)
- Google removes Kaspersky's antivirus software from Play Store (source)
- Google Blocks Unsafe Android App Sideloading in India for Improved Fraud Protection (source)
- Google brings better bricking to Androids, to curtail crims (source)
- Over 200 malicious apps on Google Play downloaded millions of times (source)
- TrickMo Banking Trojan Can Now Capture Android PINs and Unlock Patterns (source)
- How to enable Safe Browsing in Google Chrome on Android (source)
- Google Warns of Actively Exploited CVE-2024-43093 Vulnerability in Android System (source)
- Google patches actively exploited Android vulnerability (CVE-2024-43093) (source)