We should always stay alert and cautious with the applications that we download and install from outside the Play Store since we can download an app with malware that could infect our Android devices.
As recently, the cybersecurity researchers at Zimperium have discovered a malicious app that can be downloaded outside of Google Play (third-party Android app stores).
Once the user downloads this malicious app on their smartphone, the app contacts the Firebase server and starts controlling the device remotely. Moreover, the security experts have affirmed that this malicious app screen itself as “System Update.”
This new “System Update” malware is surprisingly sophisticated malware, and this malware tricks and infects the users by launching a notification that pretends to be a system update.
In this situation, when the user clicks on the notification, the malware asks the user to install this new application, which will later request full access to the device.
And here once the user grants the access, it will simply take over the control of the device and will get access to all the following things that we have mentioned below:-
According to the report, the malware sends various data to its Firebase C&C server just after getting installed on the device. And the data that it sends includes storage stats, ISP details, and installed apps.
However, here the Firebase is used only for conveying commands, while a separate C&C server is used to collect other stolen data using POST requests. This malware collects data directly if it has root access or uses the “Accessibility Services” function on the compromised device.
Moreover, to hide its malicious activities, it publicised fake notifications about the search for updates when it receives new commands from its speculators.
But, here, the most relaxing thing is that this malicious app has never been available on Google Play, and not only that, even the developers at Google are trying their best to prevent it from circumventing its security walls.
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity, and hacking news updates.
Cybersecurity researchers have detected the active exploitation of a zero-day vulnerability in GeoVision devices, which…
A critical security flaw has been uncovered in certain TP-Link routers, potentially allowing malicious actors…
SilkSpecter, a Chinese financially motivated threat actor, launched a sophisticated phishing campaign targeting e-commerce shoppers…
The research revealed how threat actors exploit SEO poisoning to redirect unsuspecting users to malicious…
Black Basta, a prominent ransomware group, has rapidly gained notoriety since its emergence in 2022…
CVE-2024-52301 is a critical vulnerability identified in Laravel, a widely used PHP framework for building…