Categories: Malware

Malicious Android ads leads to Automatically Download and Install Apps that Contain Malware in Android Devices

Malicious Android Apps are growing rapidly and it used to target victims in Many ways. Spreading Malware through malvertising campaign in Popular Forum Leads to automatically downloading Android apps by advertisements posted on forums.

This malvertising campaign Found in on of the Forum called “GodLikeProductions,” where used Reported about automatically apps are downloading when users visit the Forum.

Forums Hosts have randomly removed the visitors Complaints messages about this Malicious Advertisement which leads to Download the Malware Apps.

Also Read A Malvertiser called “RoughTed” Bypass Ad-blocker and Get Half a Billion visits in 3 Months
Malicious Android ads leads to Malware auto InstallationMalicious Android ads leads to Malware auto Installation

Malicious Downloaded APK from Forum

Researchers From zscaler Discovered, the APK file called “ kskas.Apk,”  and the App name Mentioned as “Ks Clean,” which used to Automatically downloaded form the  “GodLikeProductions,”   forum.

Once this APK Automatically installed into victims Android Device, its asked to update the used by Displaying te fake system update pop-up.

This system updates popup only option presented to the user is to select the “OK” button, forcing the user to accept the message.

Also Read Beware: Malicious Payload “Hworm” Dropped Through Embedded Youtube Video’s

Once Victims Pressed the “OK” Button, its promote into installing another Malicious APK file called “UPDATE”  This APK is stored locally inside the assets directory of the app. Once installed, the Update app immediately asks for Admin rights.

According to the Zscaler,”Once the app gains admin rights, it becomes impossible to remove it from the device. The traditional “Uninstall” option, by default, becomes disabled, because a user cannot remove apps with admin rights. Usually, one can uninstall such apps by first removing admin privileges via settings, but this app uses an unconventional method — registering as an Android receiver — to preserve its admin privileges.”

This malicious App Stats that, Once Victims tried to uninstall this app, suddenly phone gets locked for few seconds.

Some other suspicious activities, including:

  • Mount/Unmount filesystems
  • Read/Write bookmarks history
  • Overlay system window
  • Write Settings
  • Download Without Notification
AlsoRead 200 Million Downloaded video players including VLC Player are vulnerable to Malicious subtitles Attack -A Complete Takeover Attack
Balaji

BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Recent Posts

Two Systemic Jailbreaks Uncovered, Exposing Widespread Vulnerabilities in Generative AI Models

Two significant security vulnerabilities in generative AI systems have been discovered, allowing attackers to bypass…

6 hours ago

New AI-Generated ‘TikDocs’ Exploits Trust in the Medical Profession to Drive Sales

AI-generated medical scams across TikTok and Instagram, where deepfake avatars pose as healthcare professionals to…

7 hours ago

Gamers Beware! New Attack Targets Gamers to Deploy AgeoStealer Malware

The cybersecurity landscape faces an escalating crisis as AgeoStealer joins the ranks of advanced infostealers…

9 hours ago

Compliance And Governance: What Every CISO Needs To Know About Data Protection Regulations

The cybersecurity landscape has changed dramatically in recent years, largely due to the introduction of…

11 hours ago

XDR, MDR, And EDR: Enhancing Your Penetration Testing Process With Advanced Threat Detection

In the ever-evolving world of cybersecurity, organizations must continuously adapt their defense strategies to stay…

11 hours ago

How to Develop a Strong Security Culture – Advice for CISOs and CSOs

Developing a strong security culture is one of the most critical responsibilities for today’s CISOs…

14 hours ago