Security News > 2023 > April > Cybercriminals charge $5K to add Android malware to Google Play

Malware developers have created a thriving market promising to add malicious Android apps to Google Play for $2,000 to $20,000, depending on the type of malicious behavior cyber criminals request.
The exact price for these services is negotiated on a case-by-case basis on hacker forums or Telegram channels, allowing cybercriminals to customize malicious Android apps with their own malware or functionality.
Being able to add a malicious Android app to the trusted Google Play store provides a wide base of targets to steal credentials and data, conduct financial fraud, or deliver unwanted advertisements.
In a new report by Kaspersky, researchers illustrate how threat actors offer services that promise the addition of Android malware apps to Google Play.
Kaspersky reports that apart from Google Play loaders, which sell for an average of roughly $7,000, cybercriminals also sell services like malware obfuscation for $8 to $30 or "Clean" Google developer accounts that cost $60. These malicious but innocuous-looking apps are published on Google Play but include the ability to fetch malicious code via a later update.
To increase the number of malware installations via the Google Play loaders, the cybercriminals may also offer to run Google Ad campaigns on account of their customers.
News URL
Related news
- APT36 Spoofs India Post Website to Infect Windows and Android Users with Malware (source)
- Android Malware Exploits a Microsoft-Related Security Blind Spot to Avoid Detection (source)
- New Crocodilus malware steals Android users’ crypto wallet keys (source)
- Counterfeit Android devices found preloaded With Triada malware (source)
- Triada Malware Preloaded on Counterfeit Android Phones Infects 2,600+ Devices (source)
- Google fixes Android zero-days exploited in attacks, 60 other flaws (source)
- Google Releases Android Update to Patch Two Actively Exploited Vulnerabilities (source)
- SpyNote, BadBazaar, MOONSHINE Malware Target Android and iOS Users via Fake Apps (source)
- Google adds Android auto-reboot to block forensic data extractions (source)
- New Android malware steals your credit cards for NFC relay attacks (source)