Categories: Malware

New Android Malware Found in 144 Google Play apps with 17.4 Million Installations

New Android Malware called “Grabos”  Found in 144 Google Play apps and its considering as one of the mass distribution play store Malware by huge number playstore apps.

There is no surprise now to see a malicious app in Google play store, hackers continued to deceive the Google safety checks and also they earn high ratings.

They named it as Grabos and the activity first discovered with free Android Music application “Aristotle Music audio player 2017”.

Most of the app found uploaded in August and October, in a short span they reached between 4.2 million and 17.4 million users downloaded and an average rating of 4.4.

Malicious apps details from Google Play.

Also Read: Beware!! Hackers Using New Tools to Break open Apple iCloud Accounts to Unlock Stolen iPhone’s

How Grabos Evades Google Play security

Grabos Android Malware using Commercial obfuscator which makes static analysis difficult and even dynamic analysis is difficult without knowing it’s what the app is checking.

Researchers decompiled the apk and proceeded with analysis. They found Grabos Android Malware injected with file explorer and music player applications, every time when the application is triggered it checks if any of the following settings is not true and then it decides to launch the app with legitimate functionality or the fake one.

“Fake” vs “real” app flow. “BL” stands for “blacklisted.”

  • isOnline: Checks if the device has Internet connectivity
  • getIsBlacklisted: Checks if the Android debug bridge (adb) and development settings are enabled or if the device is in an emulator. If the latter is the case, the device is blacklisted and the “fake” app is launched.
  • getIsForcedBlacklisted: Flag set by the control server.

In addition, Grabos Android Malware also present with the AndroidManifest that executes every time when the app installed or connectivity change. It collects and encrypts following data from the infected device.

Device information:

  • android_version
  • build_model
  • install_referrer
  • network_country
  • sim_country
  • carrier_name
  • language_code
  • country_code
  • time_timezone

Device location:

Grabos uses free IP geolocation API services to obtain IP address information such as

  • city
  • country code, ISP
  • organization
  • region
  • ZIP code.

Device configuration:

  • is_emulator
  • is_rooted
  • is_adb_enabled
  • is_dev_settings_enabled
  • allow_mock_location
  • allow_non_market (unknown sources enabled/disabled)
  • is_vpn_connected
  • dp checks (additional root, debug, and emulator checks provided by the commercial obfuscator)

Installed Grabos app information

  • version_code
  • package_name
  • and install_time

Specific apps installed: Grabos reports if any app in a predefined list is currently installed on the infected device (more on this later).

All these information submitted to C&C server and then it displays customized notifications when the user opens the app, such as pop-up to rate the app.Also it asks users to share the app with friends.

Along with tracking infected device’s location it also checks for some of the social media and Google apps are installed or not by using method packageinstalled and also with the app name.

Grabos gained popularity on Google Play because it allowed users to download music for free while constantly asking them to rate the app. However, users were not aware of the hidden functionality that comes with those apps, exposing them to custom notifications to download and install additional apps and open them without their consent. says McAfee.

It also checks for social media presence which may be utilized by cybercriminals to install additional malware by tricking the users.

According to McAfee, We reported this finding to Google, who are investigating. At this point we do not know the purpose of this app reporting. However, we believe this information could be very useful to malware authors because Grabos has implemented several mechanisms to trick users into installing applications provided by the remote server. Let’s look into those functions.

List of Grabos Android Malware Package Names

  • picklieapps.player
  • musicaplayer.stonetemples
  • mp3musicplayer.playmusicmp3
  • densebutter.musicplayer
  • airplaneapps.soundmeter
  • dinosaursr.musicplayer
  • tenuousllc.humneate
  • astropie.musicplayer
  • chargeshoes.videoplayer
  • callsaver.doubtful
  • unfestenedsail.freeapp
  • extendmilk.freeplayer
  • excellentlossapps.playermusic
  • AliciaTech.free
  • mp3player.musicplayer.freelocalmusicplayer
  • freemusicplayer.freemusicplayer.free
  • afromusicplayer.fremediaplayer
  • info_astro.glider_player
  • illfatednotice.humdrum
  • headybowl.musicplayer
  • musicgratisplayerfree.free
  • naturityllc.mp3player
  • anothertube.music.player
  • startdancingapps.callrecorder
  • social.video.saver.pro
  • gratis.video.downloader.hd
  • sportingapps.copyleft_music.player
  • auto_call_recorder.freeapp
  • freenewsreader.rssfeed
  • music.video.player
  • curatorinc.ringtone.search
  • mp3musicplayer.local_files_player
  • copyleft.stream.musica.player
  • mp3.music.player
  • nobodybeats.musicplayer
  • file.manager.pronessbest
  • ark.music.mp3.player
  • air.browser.free
  • aneeoboapps.playlistmanager
  • local_music_player.free_mp3_player
  • greenlinellc.voicechanger
  • free.playlist.creator.tube
  • toporganizer.fileorganizer
  • thumb.webbrowse
  • aspirator.ringtones.player
  • freevideoplayer.musicplayer
  • vimfast.videodl
  • whimsical.piano.free
  • truckneat.freeapp
  • crowdedarmy.volume.controller
  • arnold_legal.mp3.musica
  • descent.shutterfly
  • thankyou.arrowplayer
  • pocahantasapps.musicplayer
  • astroplayer.freee
  • couchpotato.musica.play_stream
  • abstractly.musica.player
  • matsumoto.mp3player
  • musicequalizer.freeequalizer
  • lifesbad.fileexplorer
  • videolunch.free
  • copyleft.cc.mp3.music
  • ark.music.mp3.player
  • musik.mp3.music
  • streamerplayer.stream_videos
  • voicerecorder.recordvoice
  • snip.browser
  • checkrein.musicapp
  • mp3musicplayer.freemusicplayer.playmusic
  • jadedprogram.mp3player
  • preoral.freeborn
  • voice.changer.freeappsapp
  • streamplay.stream.player
  • localmp3music.freeplayer
  • drummachine.machinedrums
  • coloringbook.freetrynow
  • videodownloader.social_video_download
  • ElephantApps.FileManager
  • scaricare.app.musica
  • quicksearch.tube.player
  • rooseveltisland.mp3player
  • mindprogram.musicf
  • freeborn.sdkintegration
  • koseapps.tubemusica
  • baixar.videos.gratis
  • adeptly.forgoneapp
  • musicas.gratis.player
  • miniaturef.swanky
  • insta.mp3.music.streamer
  • anchor.musicplayer
  • repeate.mp3musicplayer
  • FeisalLLC.MusicPlayer
  • shelfshare.freeapp
  • simple.streamer.player
  • streamplayer.freearnold
  • freeturkish.video.downloader
  • cowherd.freeapp
  • localmp3musicplayer.local_player
  • scaricare.apps.musica
  • silymove.freeapp
  • pinkphone.funfreetube
  • tissuepaper.freemusic
  • chopsuey.musicplayer
  • branchnotice.musicplayer
  • fradcip.MasterApp
  • music.player.mp3.ares
  • social.video.downloader.for_fb
  • frobenius.time.tube
  • spelldoom.comeup
  • bailymusic.player
  • sportifco.musicplayer
  • topsaver.video.downloader
  • coupleweeks.modcium
  • unbecomingllc.videodownloader
  • video.for_fb.downloader.saver
  • macdrop.apptool
  • callsaver.recorderfreeapp
  • arnie_legal.mp3.musica
  • kikiapps.freeplayer
  • pintaapps.expensetracker
  • marble.musicequalizer
  • artproject.searcher
  • UnitTest.FreeApp
  • exudedplayer.freemusicplayer
  • blackballed.player
  • mp3player.decisiveapps
  • rusticd.musicplayer
  • byunhyeong.jungfree
  • voicelessapps.mp3musicplayer
  • localmp3player.freeplayer
  • kinokunya.free
  • socialvideo.downloader_vim
  • viastore.video.saver_for_fb
  • disarmbit.reache
  • crackerbalancellc.mp3converter
  • vaskollc.jpfree
  • freemusicplayer.musicplayfreetoolpalyer
  • combustionapps.musique
  • arnold.mp3.musica
  • purpleheadphones.audioplayer
  • unscalableapps.free
  • freefile.organizerfree
  • free.mp3.stream_cc_music
  • mp3uncle.musiccamera
Gurubaran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

Threat Actors Exploit Google Docs And Weebly Services For Malware Attacks

Phishing attackers used Google Docs to deliver malicious links, bypassing security measures and redirecting victims…

8 hours ago

Python NodeStealer: Targeting Facebook Business Accounts to Harvest Login Credentials

The Python-based NodeStealer, a sophisticated info-stealer, has evolved to target new information and employ advanced…

9 hours ago

XSS Vulnerability in Bing.com Let Attackers Send Crafted Malicious Requests

A significant XSS vulnerability was recently uncovered in Microsoft’s Bing.com, potentially allowing attackers to execute…

11 hours ago

Meta Removed 2 Million Account Linked to Malicious Activities

 Meta has announced the removal of over 2 million accounts connected to malicious activities, including…

15 hours ago

Veritas Enterprise Vault Vulnerabilities Lets Attackers Execute Arbitrary Code Remotely

Critical security vulnerability has been identified in Veritas Enterprise Vault, a widely-used archiving and content…

16 hours ago

7-Zip RCE Vulnerability Let Attackers Execute Remote Code

A critical security vulnerability has been disclosed in the popular file archiving tool 7-Zip, allowing…

16 hours ago