Malicious Apps on the Google Play Store
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
All 3 threats enable further attacks against a device or user, with two of them having the capability to download and execute files directly. Grabos is a trojan distributed as part of file explorer or music player applications that collects information on a device’s specification and location before sending it to a command and control (C2) server. This information could then be used to facilitate further malware or social engineering attacks. Grabos can also avoid detection by updating its settings daily and examining whether the device state allows it to run code undetected.
TrojanDropper.Agent.BKY acts as a dropper for other malware. It contains an encrypted payload, which, when downloaded, it decrypts and executes. This then presents a user with a prompt to install an additional app which contains the final payload. The final payload, typically containing a banking trojan, can then install with the permissions it needs.
AsiaHitGroup infects “Utilities” (clocks, file explorers, etc) apps and attempts to analyse a device’s location using a GeoIP search site. Once it has collected this information it downloads Trojan.SMS.Asia.Hit.Group, a secondary payload that intercepts text messages, and maintains persistence on the device.
Remediation advice
To prevent and detect a trojan infection, ensure that:Remediation steps
Last edited: 17 February 2020 11:34 am