Thursday, October 3, 2024
HomeMalware4.2 Million Android Mobile Infected by "ExpensiveWall" Malware That Can Control Your...

4.2 Million Android Mobile Infected by “ExpensiveWall” Malware That Can Control Your Mobile Wallet

Published on

A New Google Play Store Android Malware called “ExpensiveWall” Discovered that can able to Control the Android Mobile wallet by sending fraudulent premium SMS messages which leads to charge for fake services.

“ExpensiveWall” Infected almost 50 + Android Application and Downloads of this Apps Estimated Around 1 million and 4.2 million.

This New Variant Family has Discovered on earlier time of 2017 and the entire malware family has now been downloaded between 5.9 million and 21.1 million times.

- Advertisement - EHA

This Expensive Malware Is Completely Packed . Malware authors are Encrypt the Source code and also used Advanced obfuscated Technique to Evade the Google Play Security.

Also Read : Beware!! All Android Versions Up to 7.0 are Vulnerable to Toast Overlay Attack

How Does ExpensiveWall Android Malware Works

ExpensiveWall is Specially designed for Generating Profits from its Targeting Victims and also using Google Play Store, that is the fastest way to Targeting huge number of Victims.

Initially, Once Expensive Malware is Downloaded, it  asks Permission from users to access Internet, Message, and other Sensitive Permissions.

Most of the User will give Permissions without thinking the security. In This Case, Many of the Applications seeking Permission for Legitimate Purpose but Few of them are performing Malicious Activities.

App Permissions Leads  to connect  its C&C server – and SMS permissions – which enable it to send premium SMS messages and register users for other paid services all without the users knowledge.

Here, There is an Interface called  WebView which helps to running the JavaScript code  inside of the WebView that allow to trigger in-app activities by connecting App Activities and JavaScript  Code.

According to Checkpoint Report, Once C&C Sever Connection has successfully Established then, the infected device to its C&C server, including its location and unique identifiers, such as MAC and IP addresses, IMSI, and IMEI.

This Malware Connect to C&C server whenever Infected Device Switched on and received an URL in the WebView  interface that contains Malicious java script code.

Android Malware

Malicious code secretly click the link and subscribing them to premium services and sending SMS messages and generating revenue by silently  clicking ads.

Checkpoint Report this Malware activities to Google and Google promptly removed the reported samples from its store.

But already Millions of users were Download this Malware which remains to do the Malicious activities unless the App get uninstalled.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

ANY.RUN Upgrades Threat Intelligence to Identify Emerging Threats

ANY.RUN announced an upgrade to its Threat Intelligence Portal, enhancing its capabilities to identify...

Cisco Nexus Vulnerability Let Hackers Execute Arbitrary Commands on Vulnerable Systems

A critical vulnerability has been discovered in Cisco's Nexus Dashboard Fabric Controller (NDFC), potentially...

Hackers Now Exploit Ivanti Endpoint Manager Vulnerability to Launch Cyber Attacks

The Cybersecurity and Infrastructure Security Agency (CISA) has announced the addition of a new...

Tor Browser 13.5.6 Released – What’s New!

The Tor Project has announced the release of Tor Browser 13.5.6, which is now...

Free Webinar

Decoding Compliance | What CISOs Need to Know

Non-compliance can result in substantial financial penalties, with average fines reaching up to $4.5 million for GDPR breaches alone.

Join us for an insightful panel discussion with Chandan Pani, CISO - LTIMindtree and Ashish Tandon, Founder & CEO – Indusface, as we explore the multifaceted role of compliance in securing modern enterprises.

Discussion points

The Role of Compliance
The Alphabet Soup of Compliance
Compliance
SaaS and Compliance
Indusface's Approach to Compliance

More like this

DCRAt Attacking Users Via HTML Smuggling To Steal Login Credentials

In a new campaign that is aimed at users who speak Russian, the modular...

LummaC2 Stealer Leverages Customized Control Flow Indirection For Execution

The LummaC2 obfuscator employs a novel control flow protection scheme designed specifically for its...

Octo2 Android Malware Attacking To Steal Banking Credentials

The original threat actor behind the Octo malware family has released a new variant,...