Malicious Apps hosted in Google play store is a never ending process, researchers from Zsclarer and ESET reported dozens of the app that contain aggressive adware strains.
These fake mods reached up to 990,000 installs and they were split into two categories
These components only have necessary modules for installation, once it launched it seeks for admin permission.
If admission permission provided it will launch “INSTALLER MOD” to install additional modules “Block Launcher Pro” with several admin rights.
Upon installing it brings the user to dead end – a static Minecraft-themed screen with no clickable elements displayed on the screen,14 apps impersonating Minecraft mods with up to 80,000 installs has been discovered by ESET.
It just uses the old trick, once it launched it shows the download button. If the user clicks the download button it will take them to scam websites showing a various range of advertisements.
Remaining 73 apps fall into this category and they have reached up to 910,000 installs before they reported.
Four out of the 12 applications that were accounted for this suspicious activity have been downloaded in between 10,000 to 50,000 times.
In order to hide from Google’s Antivirus system, these apps will not show any activity for first six hours.
These apps once installed will communicate with the predefined C&C server to get instructions. The C&C server issue commands to the app to display various advertisements on the device.
Also Read:
Cybersecurity researcher "0xdf" has cracked the "Ghost" challenge on Hack The Box (HTB), a premier…
Google has unveiled Sec-Gemini v1, an AI model designed to redefine cybersecurity operations by empowering…
The United States has successfully extradited two Kosovo nationals, Ardit Kutleshi, 26, and Jetmir Kutleshi,…
Ivanti has issued an urgent security advisory for CVE-2025-22457, a critical vulnerability impacting Ivanti Connect…
A concerning malware campaign was disclosed by the AhnLab Security Intelligence Center (ASEC), revealing how…
EncryptHub, a rapidly evolving cybercriminal entity, has come under intense scrutiny following revelations of operational…