Our malware analysis team has discovered a new social engineering trick used by criminals to target Android users. The attack vector guides the victim to a fake application market (or an untrustworthy third-party source). Once there, the victim downloads clones of popular apps that are cleverly disguised. Once such an application gets downloaded, it controls the read, send and receive functionality of the SMS and MMS service of the device.
The clones that are downloaded by the victim are latest versions of genuine apps so it is quite simple for people to get fooled. In this case, the alternate market that the malware connects to is vttp://myadroidmaklet.net/.
The malware then carries out the following nefarious activities:
Detailed analysis of the malware
Once the victim is guided to the fake market he can browse freely and find around 50 popular apps that can be downloaded.
Once the victim has picked the app of his choice (Adobe Flash Player in this example) he is shown a page of authentic permissions. Once the app has been installed, two rather strange looking icons are added to the home screen.
After installation, the corrupted app sends the following messages to the premium numbers mentioned:
The cloned apps that can be found are some of the most commonly used apps. There are about 50 such apps that have been successfully cloned by this malware and this creates a lot of confusion for potential victims. Here is a list of some of these apps:
Tips for safety
There are many more apps that have been successfully cloned and used to trick victims. In order to ensure safety we recommend the following steps:
The popularity of Android devices and their ability to install apps from third-party sources is a major risk for one and all. Innovative techniques like this will crop up from time to time, but the best security software and awareness will keep users protected.
Thanks to Sandip for the analysis.
18 Comments
good
nice
quick heal is very nice he is wrk is very fast ………
Thank you quick heal
Your team is doing excellent job
Just keep it up quick heal team
Keep it up
i m new to computer kindly keep on advicing me about any bad website
Hi Basant,
Keep reading the updates on our blog and website for more information. Quick Heal products will keep you protected against any threats that arise.
good job…keep it up…..
Quick Heal is very much useful to protect against anti-virus. Thank You Very Much.
dear sir my quick heal system is not getting updates from net so what should i do?
Hi Parveen,
Please visit this link – https://www.quickheal.com/supp_tic.asp.
You can file your complaint there. Our support team will get back to you with a suitable solution.
Thanks for your patience.
Quick Heal cannot scan Samsung Galaxy Note (GT-N7000)
Hi Bharat,
Please visit this link – https://www.quickheal.com/supp_tic.asp.
You can file your complaint here. Our support team will look into it and inform you about the progress.
Thanks for your patience.
Very Good
Thanks,
Really crucial and pratical info shared..!!
thanks ..!
@Vijay, @Krishna, @Panchal, @Tinu, @BP Mishra, @Jay, @Lallan, @Bajrang, @Sameer, @Adora info.: Thank you all for visiting our blog. Please check back regularly for more security news and information.
thanks quickheal team .