Friday, February 28, 2025
HomeCyber Security NewsAndroid Trojan On the Google Play Store With Over 500,000 Installs Steals...

Android Trojan On the Google Play Store With Over 500,000 Installs Steals from Notifications

Published on

SIEM as a Service

Follow Us on Google News

On the Google Play Store, the cybersecurity analysts at Dr.Web have recently witnessed a major tip in trojan infiltration. Not only that even they have also detected one application that has more than 500,000 installs and steals users’ data from the notifications.

The threat actors use these malicious applications that belong to a family of trojan malware to perform several malicious tasks like:-

  • Scams
  • Data theft
  • Financial losses
  • Loss of sensitive personal information

Trojans Tracked

Here below we have mentioned all the trojans tracked by the cybersecurity experts at Dr.Web:-

  • Android.Spy.4498
  • Android.HiddenAds.3018
  • Android.HiddenAds.624.origin
  • Android.MobiDash.6922
  • Android.MobiDash.6929
  • Program.FakeAntiVirus.1
  • Program.SecretVideoRecorder.1.origin
  • Program.KeyStroke.3
  • Program.WapSniff.1.origin
  • Program.FreeAndroidSpy.1.origin
  • Tool.SilentInstaller.14.origin
  • Tool.SilentInstaller.6.origin
  • Tool.SilentInstaller.13.origin
  • Tool.SilentInstaller.7.origin
  • Tool.Loic.1.origin
  • Adware.AdPush.36.origin
  • Adware.SspSdk.1.origin
  • Adware.Myteam.2.origin
  • Adware.Adpush.16510
  • Adware.Adpush.6547

Fake WhatsApp mods

Among the detected Trojan malware, Android.Spy.4498 trojan is the one that is traced with high activity on the Google Play Store. The Android.Spy.4498 trojan is the unofficial modifications (mods) of WhatsApp messenger such as:-

  • GBWhatsApp
  • OBWhatsApp
  • WhatsApp Plus

The threat actors are spreading these fake malicious WhatsApp mods through several mediums like:-

  • Social media posts
  • Forums
  • SEO poisoning

Moreover, it has been also detected that all these above-mentioned malicious mods offer multiple utility features, and here they are:-

  • Arabic language support
  • Home screen widgets
  • Separate bottom bar
  • Hide status options
  • Call blocking
  • Auto-save received media

Other trojans on the Play Store

Along with this trojan, multiple numbers of trojan malware were detected on the Play Store by the experts of Dr.Web security firm. On the Google Play Store, the attackers are spreading threats under the hood of multiple genuine-looking applications.

Types of applications scattered by the threat actors on Google Play Store:-

  • Cryptocurrency management apps
  • Social benefit aid tools
  • Gazprom investment clones
  • Photo editors
  • A launcher themed after iOS 15

For diverting the stolen money from the victim’s account to the scammer’s bank account, the attacker tricks the user to deposit money for trading in the fake investment apps.

While in the case of other applications, the attackers trick the users into signing up for the costly subscriptions to steal their money.

Here the threat actors abuse the Flurry stat service to seize the notifications from the Google Play Store and the Samsung Galaxy Store apps.

Recommendations

For mitigations, the cybersecurity researchers have recommended:-

  • Avoid downloading APK’s from unknown sources.
  • Always check user reviews before downloading any applications.
  • Be cautious about the permission requested by the apps during the installation.
  • Always monitor the battery and internet data consumption.
  • Make sure to enable the Google Play Protect. 
  • Always use a robust mobile security tool.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Winos4.0 Malware Targets Windows Users Through Malicious PDF Files

A new wave of cyberattacks leveraging the Winos4.0 malware framework has targeted organizations in...

DeepSeek Data Leak Exposes 12,000 Hardcoded API Keys and Passwords

A sweeping analysis of the Common Crawl dataset—a cornerstone of training data for large...

Lotus Blossom Hacker Group Uses Dropbox, Twitter, and Zimbra for C2 Communications

The Lotus Blossom hacker group, also known as Spring Dragon, Billbug, or Thrip, has...

Squidoor: Multi-Vector Malware Exploiting Outlook API, DNS & ICMP Tunneling for C2

A newly identified malware, dubbed "Squidoor," has emerged as a sophisticated threat targeting government,...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Winos4.0 Malware Targets Windows Users Through Malicious PDF Files

A new wave of cyberattacks leveraging the Winos4.0 malware framework has targeted organizations in...

DeepSeek Data Leak Exposes 12,000 Hardcoded API Keys and Passwords

A sweeping analysis of the Common Crawl dataset—a cornerstone of training data for large...

Lotus Blossom Hacker Group Uses Dropbox, Twitter, and Zimbra for C2 Communications

The Lotus Blossom hacker group, also known as Spring Dragon, Billbug, or Thrip, has...