Security experts have warned of several legitimate-looking apps on the Google Play store which have infected potentially millions of Android users with adware.
Alerted by a user comment, Avast mobile malware analyst Filip Chytry investigated and discovered that the malware in question was operating on a massive scale.
One particular application, ‘Durak card game’ by a developer known as ‘Pocket games’, had already been downloaded 5-10 million times, he explained in a blog post.
The malware in question apparently waits several days before launching ads, so that the user is in two minds about where it has come from.
“Some of the apps wait up to 30 days until they show their true colors. After 30 days, I guess not many people would know which app is causing abnormal behavior on their phone, right?” said Chytry.
“Each time you unlock your device an ad is presented to you, warning you about a problem, eg that your device is infected, out of date or full of porn. This, of course, is a complete lie.”
If users then follow the on-screen prompts to take action over whatever ‘problem’ the adware has found on the device, they will be taken to pages that will attempt to trick them into downloading data slurping or premium SMS apps.
Some actually redirect to legitimate security apps on Google Play – another likely ploy to obfuscate the source of the adware.
“This kind of threat can be considered good social engineering. Most people won’t be able to find the source of the problem and will face fake ads each time they unlock their device,” concluded Chytry.
This article has been extracted from http://www.infosecurity-magazine.com, please click on this link to read the article in full http://www.infosecurity-magazine.com/news/google-play-adware-apps-downloaded/
Montash is a multi-award winning global technology recruitment business. Specialising in permanent and contract positions across mid-senior appointments across a wide range of industry sectors and IT functions, including:
ERP Recruitment, BI & Data Recruitment, Information Security Recruitment, IT Architecture & Strategy Recruitment , Energy Technology Recruitment, Demand IT and Business Engagement Recruitment, Digital and E-commerce Recruitment, Leadership Talent, Infrastructure and Service Delivery Recruitment, Project and Programme Delivery Recruitment.
Montash is headquartered in Old Street, London, in the heart of the technology hub. Montash has completed assignments in over 30 countries and has appointed technical professionals from board level to senior and mid management in permanent and contract roles.