This new Android malware may be the most twisted yet.
An interesting new type of malware has been uncovered, coded within two dozen Android apps that have accumulated hundreds of thousands of downloads in the Google Play store.
Android users who downloaded any of the apps embedded with this malware, dubbed “the Joker,” will need to check their credit card bills. Joker’s purpose, once deployed, is to sign up its victims to subscription services without their knowledge or consent. This new malware was first detected by CSIS Security Group malware analyst Aleksejs Kuprins, who has been monitoring the malicious code and penned a detailed analysison Joker.
SEE ALSO: Here’s how malicious Android apps are sneaking malware onto your phoneAccording to Kuprins, the malware “delivers a second stage component, which silently simulates the interaction with advertisement websites, steals the victim’s SMS messages, the contact list and device info.” Basically, any user that was infected by Joker possibly had their phone’s texts and contact list stolen, too.
But the simulated interactions are where Joker gets a bit more twisted.
“The automated interaction with the advertisement websites includes simulation of clicks and entering of the authorization codes for premium service subscriptions,” writes Kuprins. “For example, in Denmark, Joker can silently sign the victim up for a 50 DKK/week service (roughly ~6,71 EUR). This strategy works by automating the necessary interaction with the premium offer’s webpage, entering the operator’s offer code, then waiting for a SMS message with a confirmation code and extracting it using regular expressions. Finally, the Joker submits the extracted code to the offer’s webpage, in order to authorize the premium subscription.”
According to Lifehacker, the list of apps harboring the Joker malware include Advocate Wallpaper, Age Face, Altar Message, Antivirus Security - Security Scan, Beach Camera, Board picture editing, Certain Wallpaper, Climate SMS, Collate Face Scanner, Cute Camera, Dazzle Wallpaper, Declare Message, Display Camera, Great VPN, Humour Camera, Ignite Clean, Leaf Face Scanner, Mini Camera, Print Plant scan, Rapid Face Scanner, Reward Clean, Ruddy SMS, Soby Camera, and Spark Wallpaper.
Kuprins says that in total, the 24 apps racked up more than 472,000 downloads in the Google Play store. The apps have since been removed. If a user has any of those apps on their phone, they should be deleted.
According to the report, the current iteration of Joker malware campaign appears to go back as far as June of this year. Kuprins notes that Google removed the apps before his security firm reached out to the company, so it appears that the tech giant has been monitoring the situation as well.
Malwarehas longbeen a problemplaguing Android devices. Facebook has even gone so far as to file a lawsuitlast month against one developer, whose malware-ridden Android app engaged in click fraud on the social media company’s ad network.
While other recent Android-targeted malware campaigns have had broaderreach, such as “Agent Smith,”which has infected 25 million devices, Joker’s automated subscription attack certainly makes it among the more interesting.
Copyright © 2023 Powered by
'Joker' malware secretly charges Android owners' credit cards-额手相庆网
sitemap
文章
1
浏览
468
获赞
4
Reddit recruits black tech entrepreneur to join board
Reddit is honoring Alexis Ohanian’s request to fill his board seat with a black candidate by nMeta Quest 1 will no longer get feature updates
Owners of the original Meta QuestVR headset have about two months left to get the most out of them.ITeam USA's women's gymnastics gold medal win sparks lots of online love
Led by the G.O.A.T. Simone Biles, Team USA's women's gymnastics team secured the gold medal at the 2Best book deal: Get 'The Three
SAVE $10.99: As of May 16, get the physical edition of Cixin Liu's The Three-Body Problemfor $8, dowMeghan and Harry reveal their newborn son's name
The Duke and Duchess of Sussex have announced their newborn son's name: Archie Harrison Mountbatten-Why do we obsessively watch our own Instagram Stories?
When you think of the term "Instagram stalking," what kind of scenarios come to mind? Is it vettingOnePlus 11 launches in China, 1 month ahead of global release
OnePlus' new flagship, the OnePlus 11, is here – sort of. The company launched the phone in Ch'Cancelled' is cancelled now. We're giving people the digitine.
There's an analogy activists often use called "dollar voting." Sustainable food advocate and authorGoogle says China and Iran tried to hack Biden and Trump's campaigns
Google has announced it has identified state-sponsored hacking attempts upon both Biden and Trump's2024 Polestar 2 gets more powerful engines, better batteries
Performance electric vehicle brand Polestar started selling its Polestar 2 fastback (as the companyTesla workers push to unionise in New York
Tesla workers in New York have launched a union campaign, hoping to turn the company's Buffalo plantMeta Quest 1 will no longer get feature updates
Owners of the original Meta QuestVR headset have about two months left to get the most out of them.ISo it snowed in Seattle, and the dogs are loving it
So it snowed in Seattle. Like, a lot. And wouldn't you know it, the city's canine residents can't geUsing Affirm on Amazon: How to buy now, pay later this Prime Day
Affirm is the first BNPL (Buy Now, Pay Later) service to be available directly through Amazon Pay, aCES 2023 trends: AI and the metaverse may rule, but 'basic' tech still stands out
CES 2023 kicked off on Tuesday, giving press outlets a sneak peek at the companies vying for everyon