A powerful Android Trojan distributed through Google Play store apps that posed as Fashion and game apps to generate a huge revenue using malicious invisible ads

This Trojan distributed under several Google Play store apps which have been downloaded more than 6,500,000 times in total.
Trojan detected as Android.RemoteCode.152.origin and it mainly distributed via Game based Android apps.
Malware developer embedded their malicious software module within the application that was distributed via Google Play store.
Once the Malicious apps installed into the victim’s device, silent downloading and launching of the auxiliary plug-ins designed for downloading advertising web pages and clicking on banners located on it.
How Do Hackers Earn Money using Android Trojan?
Once the In-built Trojan application(Android.RemoteCode.152.origin) successfully launched into victims Android device, it keeps starts itself every time users reboot the device.
After the successful launch, Malicious module downloads another Trojan module from the command & control servers that managed by the attackers and launch the downloaded Trojan module.
Later it downloads another module which is modified version of the advertising development SDK based on MobFox SDK advertising platform which is designed for monetizing applications.
Trojan itself perform the configuration set and it silently creates various advertisements and banners, and then clicks on them, earning money for criminals.
Also it Trojan connect the dedicated mobile marketing network AppLovin which is used to generate additional income by downloading the advertisements.
Following Program was detected as Malicious apps from Google Play Store.
- Beauty Salon – Dress Up Game, version 5.0.8;
- Fashion Story – Dress Up Game, version 5.0.0;
- Princess Salon – Dress Up Sophie, version 5.0.1;
- Horror game – Scary movie quest, version 1.9;
- Escape from the terrible dead, version 1.9.15;
- Home Rat simulator, version 2.0.5;
- Street Fashion Girls – Dress Up Game, version 6.07;
- Unicorn Coloring Book, version 134.
Comment(s)
Categories
- Other (42)
- Ransomware (142)
- Events and News (27)
- Features (45)
- Security (466)
- Tips (79)
- Google (23)
- Achievements (11)
- Products (34)
- Activation (7)
- Dealers (1)
- Bank Phishing (44)
- Malware Alerts (212)
- Cyber Attack (259)
- Data Backup (11)
- Data Breach (97)
- Phishing (154)
- Securty Tips (1)
- Browser Hijack (18)
- Adware (15)
- Email And Password (68)
- Android Security (70)
- Knoweldgebase (38)
- Botnet (15)
- Updates (3)
- Alert (71)
- Hacking (57)
- Social Media (8)
- vulnerability (56)
- Hacker (31)
- Spyware (9)
- Windows (6)
- Microsoft (21)
- Uber (1)
- YouTube (1)
- Trojan (2)
- Website hacks (4)
- Paytm (1)
- Credit card scam (1)
- Telegram (3)
- RAT (5)
- Bug (3)
- Twitter (2)
- Facebook (7)
- Banking Trojan (7)
- Mozilla (2)
- COVID-19 (5)
- Instagram (2)
- NPAV Announcement (9)
- IoT Security (1)
- Deals and Offers (2)
- Cloud Security (11)
- Offers (5)
- Gaming (1)
- FireFox (2)
- LinkedIn (2)
- WhatsApp (4)
- Amazon (2)
- DMart (1)
- Payment Risk (4)
- Occasion (3)
- firewall (2)
- Cloud malware (2)
- Cloud storage (2)
- Financial fraud (10)
- Impersonation phishing (1)
- DDoS (5)
- Smishing (2)
- Whale (0)
- Whale phishing (4)
- WINRAR (2)
- ZIP (2)
Recent Posts
Archive
Tags
cyber attack
phishing
data breach
phishing attacks
cyber threats
ransomware
phishing attack
ransomeware
malware
android malware
cyber security
data theft
phishingattack
cyberthreats
financial security
data stealing
cybercrime
network security
ddos attack
data security
critical vulnerability
cyber fraud
trojan
net protector total security
data protection
cert-in
financial fraud
phishing email
microsoft
lockbit
cybercriminals
cyber crime
ddos
phishing scam
cyber threat
india
twitter
android
ransomware attacks
cryptojacking
winrar
malicious apps
pakistan-backed hacker
android apps
email phishing
play store
server security
databreach
clop
ransomware attack