Malicious Android Apps are growing rapidly and it used to target victims in Many ways. Spreading Malware through malvertising campaign in Popular Forum Leads to automatically downloading Android apps by advertisements posted on forums.
This malvertising campaign Found in on of the Forum called “GodLikeProductions,” where used Reported about automatically apps are downloading when users visit the Forum.
Forums Hosts have randomly removed the visitors Complaints messages about this Malicious Advertisement which leads to Download the Malware Apps.
Researchers From zscaler Discovered, the APK file called “ kskas.Apk,” and the App name Mentioned as “Ks Clean,” which used to Automatically downloaded form the “GodLikeProductions,” forum.
Once this APK Automatically installed into victims Android Device, its asked to update the used by Displaying te fake system update pop-up.
This system updates popup only option presented to the user is to select the “OK” button, forcing the user to accept the message.
Once Victims Pressed the “OK” Button, its promote into installing another Malicious APK file called “UPDATE” This APK is stored locally inside the assets directory of the app. Once installed, the Update app immediately asks for Admin rights.
According to the Zscaler,”Once the app gains admin rights, it becomes impossible to remove it from the device. The traditional “Uninstall” option, by default, becomes disabled, because a user cannot remove apps with admin rights. Usually, one can uninstall such apps by first removing admin privileges via settings, but this app uses an unconventional method — registering as an Android receiver — to preserve its admin privileges.”
This malicious App Stats that, Once Victims tried to uninstall this app, suddenly phone gets locked for few seconds.
A newly identified malware, dubbed Zhong Stealer, has emerged as a significant threat to the…
In a recent development, the SPAWNCHIMERA malware family has been identified exploiting the buffer overflow…
A significant vulnerability in Sitevision CMS, versions 10.3.1 and earlier, has been identified, allowing attackers…
Chinese cybersecurity entities have accused the U.S. National Security Agency (NSA) of orchestrating a cyberattack…
The ACRStealer malware, an infostealer disguised as illegal software such as cracks and keygens, has…
A security vulnerability in Nagios XI 2024R1.2.2, tracked as CVE-2024-54961, has been disclosed, allowing unauthenticated…