Get Even More Visitors To Your Blog, Upgrade To A Business Listing >>

'DawDropper' Dropper Apps Found On Google Play Store, Infecting Millions Of Users

Another day, another security issue found on Google Play Store.

According to a report from the security research firm Trend Micro, a number of malware apps were found stealing users' data, including banking credentials, PIN numbers, passwords, and any other information. The Android apps could even intercept text messages and infect devices with additional harmful malware.

The apps in question are essentially dropper apps.

What this means, the apps don't necessarily have Malicious functions. They only serve as the trojan horse to install malicious programs, their payloads.

This is the main reason why the apps managed to pass Google Play Store's scrutiny, and managed to infect at least 7 million Android users around the world.

"Malicious actors have been surreptitiously adding a growing number of banking trojans to Google Play Store via malicious droppers this year, proving that such a technique is effective in evading detection," the researchers said.

DawDropper malicious apps Trend Micro found. (Credit: Trend Micro)

The dropper the campaign uses, is dubbed the 'DawDropper', first discovered back in 2021. And the apps include:

  1. Call Recorder APK (com.caduta.aisevsk).
  2. Rooster VPN (com.vpntool.androidweb).
  3. Super Cleaner- hyper & smart (com.j2ca.callrecorder).
  4. Document Scanner – PDF Creator (com.codeword.docscann).
  5. Universal Saver Pro (com.virtualapps.universalsaver).
  6. Eagle photo editor (com.techmediapro.photoediting).
  7. Call recorder pro+ (com.chestudio.callrecorder).
  8. Extra Cleaner (com.casualplay.leadbro).
  9. Crypto Utils (com.utilsmycrypto.mainer).
  10. FixCleaner (com.cleaner.fixgate).
  11. Just In: Video Motion (com.olivia.openpuremind).
  12. myunique.sequencestore.
  13. flowmysequto.yamer.
  14. qaz.universalsaver.
  15. Lucky Cleaner (com.luckyg.cleaner).
  16. Simpli Cleaner (com.scando.qukscanner).
  17. Unicc QR Scanner (com.qrdscannerratedx).

According to Trend Micro in a blog post:

"Malicious actors have been surreptitiously adding a growing number of banking trojans to Google Play Store via malicious droppers this year, proving that such a technique is effective in evading detection."

"Additionally, because there is a high demand for novel ways to distribute mobile malware, several malicious actors claim that their droppers could help other cybercriminals disseminate their malware on Google Play Store."

DawDropper infection chain. (Credit: Trend Micro)

According to the researchers, DawDropper’s malicious payload belongs to the Octo malware family, which is a modular and multistage malware capable of stealing banking information, intercepting text messages, and hijacking infected devices.

Octo is also known as Coper, and it has been historically used to target Colombian online banking users.

After the researchers reached Google, the tech company quickly removed the 17 apps.

But for those who have downloaded and installed the aforementioned apps, users are urged to manually uninstall the apps immediately.

"Cybercriminals are constantly finding ways to evade detection and infect as many devices as possible. In a half-year span, we have seen how banking trojans have evolved their technical routines to avoid being detected, such as hiding malicious payloads in droppers," Trend Micro concluded.

"As more banking trojans are made available via DaaS, malicious actors will have an easier and more cost-effective way of distributing malware disguised as legitimate apps. We foresee that this trend will continue and more banking trojans will be distributed on digital distribution services in the future."

In order to stay safe from malicious apps, Android users are recommended to always check app reviews, and know who the developer is. Users should then apply due diligence when looking into app they wish to download, and always avoid sideloading apps, or downloading apps from unofficial apps stores.

Published: 
29/07/2022
News
Google
Android
Malware
Privacy
Security
Review


This post first appeared on Eyerys | Eyes For Solution, please read the originial post: here

Share the post

'DawDropper' Dropper Apps Found On Google Play Store, Infecting Millions Of Users

×

Subscribe to Eyerys | Eyes For Solution

Get updates delivered right to your inbox!

Thank you for your subscription

×