Categories: AndroidMalware

New Malware Family “Venus” In Google Play Store Infects 285,000 Android Users to Subscribe Premium Ads

Researchers discovered a new Trojan family called “Venus” resides in the Google play store infected at least 285,000 Android users around the world.

There are 8 apps involved with the malicious activities in Android user’s device and it is mainly targeting the carrier billing and advertising area.

8 Malicious apps list

Threat actors developed these apps to interact with Ads and subscribe the user to premium services without any sort of notification, and it also bypasses the Google Play protect and malware detection system.

There are several countries were targeted by this malware campaign including Belgium, France, Germany, Guinea, Morocco, Netherlands, Poland, Portugal, Senegal, Spain, and Tunisia.

Malware Infection Process via Malicious App

Researchers observed that most of the data consumed by an application called “Quick scanner” which is protected by a library that encrypts and hides files. 

According to Evina research, “The application uses the libjiagu library created by the Chinese company Qihoo. The library protects the application’s content and runs protections against reverse engineering. Unfortunately, fraudsters take advantage of the library to use it dishonestly.”

Further deep analysis revealed that the apps have fraudulent code in compiled Android file and it processes the anti-reverse check after the file was imported and decrypted in memory in order to bypass Google’s detection.

“Venus is waiting for the right time to attack. The malware is able to register time after the application has been downloaded instead of being launched on the very first day.” Evina said.

Once it performed the successful attack, Venus malware communicates with the C2 server domain(glarecube[.]com) which is controlled by an attacker to send the encrypted request.

After decrypted, Server response with two following things.

  1) All the instructions containing URLs that redirect to premium services or websites containing ads, all created by the fraudster
     2) The javascript commands making the fraudulent process

With running an application, the URL simply loaded into the browser without letting users know whats going on and it subscribes to the premium ads, at the end attackers can make its profit from advertisements clicks and premium services subscriptions.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates

Balaji

BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Recent Posts

Malware Discovered in Healthcare Patient Monitors, Traced to Chinese IP Address

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical advisory regarding multiple vulnerabilities…

9 minutes ago

Jailbreaking DeepSeek: Researchers Reveal Three New Methods to Override LLM Safety

Researchers at Palo Alto Networks' Unit 42 have revealed a troubling surge in large language…

15 minutes ago

Phorpiex Botnet Distributes LockBit Ransomware Through Compromised Websites

Cybereason Security Services has published a comprehensive threat analysis highlighting the resurgence of the Phorpiex…

22 minutes ago

Critical D-Link Router Flaw Allows Attackers to Take Full Remote Control

A critical unauthenticated Remote Code Execution (RCE) vulnerability has been identified in D-Link's DSL-3788 routers,…

2 hours ago

Massive Hacking Forum Network Dismantled by Authorities, Impacting 10M Users

Authorities have delivered a major blow to the cybercrime world by dismantling two of the…

2 hours ago

Microsoft Enhances M365 Bounty Program with New Services & Rewards Up to $27,000

Microsoft has announced updates to its Microsoft 365 (M365) Bug Bounty Program, offering expanded services,…

2 hours ago