Categories: AndroidMalware

New Malware Family “Venus” In Google Play Store Infects 285,000 Android Users to Subscribe Premium Ads

Researchers discovered a new Trojan family called “Venus” resides in the Google play store infected at least 285,000 Android users around the world.

There are 8 apps involved with the malicious activities in Android user’s device and it is mainly targeting the carrier billing and advertising area.

8 Malicious apps list

Threat actors developed these apps to interact with Ads and subscribe the user to premium services without any sort of notification, and it also bypasses the Google Play protect and malware detection system.

There are several countries were targeted by this malware campaign including Belgium, France, Germany, Guinea, Morocco, Netherlands, Poland, Portugal, Senegal, Spain, and Tunisia.

Malware Infection Process via Malicious App

Researchers observed that most of the data consumed by an application called “Quick scanner” which is protected by a library that encrypts and hides files. 

According to Evina research, “The application uses the libjiagu library created by the Chinese company Qihoo. The library protects the application’s content and runs protections against reverse engineering. Unfortunately, fraudsters take advantage of the library to use it dishonestly.”

Further deep analysis revealed that the apps have fraudulent code in compiled Android file and it processes the anti-reverse check after the file was imported and decrypted in memory in order to bypass Google’s detection.

“Venus is waiting for the right time to attack. The malware is able to register time after the application has been downloaded instead of being launched on the very first day.” Evina said.

Once it performed the successful attack, Venus malware communicates with the C2 server domain(glarecube[.]com) which is controlled by an attacker to send the encrypted request.

After decrypted, Server response with two following things.

  1) All the instructions containing URLs that redirect to premium services or websites containing ads, all created by the fraudster
     2) The javascript commands making the fraudulent process

With running an application, the URL simply loaded into the browser without letting users know whats going on and it subscribes to the premium ads, at the end attackers can make its profit from advertisements clicks and premium services subscriptions.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates

Balaji

BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Recent Posts

Threat Actors Leverage Email Bombing to Evade Security Tools and Conceal Malicious Activity

Threat actors are increasingly using email bombing to bypass security protocols and facilitate further malicious…

5 hours ago

Threat Actors Launch Active Attacks on Semiconductor Firms Using Zero-Day Exploits

Semiconductor companies, pivotal in the tech industry for their role in producing components integral to…

5 hours ago

Hackers Exploit Router Flaws in Ongoing Attacks on Enterprise Networks

Enterprises are facing heightened cyber threats as attackers increasingly target network infrastructure, particularly routers, following…

5 hours ago

Threat Actors Exploit Legitimate Crypto Packages to Deliver Malicious Code

Threat actors are using open-source software (OSS) repositories to install malicious code into trusted applications,…

5 hours ago

Tycoon 2FA Phishing Kit Uses Advanced Evasion Techniques to Bypass Endpoint Detection Systems

The notorious Tycoon 2FA phishing kit continues its evolution with new strategies designed to slip…

5 hours ago

Hands-On Labs: The Key to Accelerating CMMC 2.0 Compliance

INE Security Highlights How Practical, immersive training environments help defense contractors meet DoD cybersecurity requirements…

9 hours ago