COMPANIES

No Data Found

NEWS

No Data Found
Necro trojan found in popular Google Play apps and modded APKs, posing threat to Android users

Necro trojan found in popular Google Play apps and modded APKs, posing threat to Android users

Researchers warn of a resurgence of the Necro trojan, targeting popular apps and unofficial mods to steal sensitive information and install malicious software.

Pranav Dixit
Pranav Dixit
  • Updated Sep 25, 2024 3:31 PM IST
Necro trojan found in popular Google Play apps and modded APKs, posing threat to Android usersThreats discovered on Android

Security researchers at Kaspersky have discovered a new version of the Necro trojan targeting Android users through both Google Play apps and modified APKs (Android application packages) hosted on third-party websites. This malicious software poses a serious threat, capable of stealing sensitive data, installing additional malware, and remotely executing commands on infected devices.

Advertisement

Google Play Apps Removed

Kaspersky researchers identified two apps on the Google Play Store infected with the Necro trojan:

Wuta Camera: Downloaded over 10 million times.

Max Browser: Downloaded over 1 million times.

Google has since removed these infected apps from its Play Store after being notified by Kaspersky.

The researchers also discovered the Necro trojan lurking in unofficial "modded" versions of popular apps, including Spotify, WhatsApp, Minecraft, Stumble Guys, Car Parking Multiplayer, and Melon Sandbox. These modified APKs, often promising premium features for free, are widely available on third-party websites and pose a significant risk to unsuspecting users.

The attackers employ various methods to distribute the malware. In the case of the Spotify mod, an embedded SDK displayed advertising modules. If a user interacted with a specific image-based module, the trojan payload would be deployed from a command-and-control (C&C) server.

Advertisement

Similarly, the WhatsApp mod exploited Google's Firebase Remote Config cloud service as a C&C server, deploying the trojan upon user interaction with a specific module.

Necro Trojan Capabilities

Once installed, the Necro trojan can perform a range of malicious activities, including:

Downloading and installing malicious files and apps.

Opening invisible browser windows to execute malicious JavaScript code.

Subscribing users to expensive paid services without their knowledge.

Stealing sensitive information like login credentials and financial data.

Protecting Yourself

While the infected Google Play apps have been removed, the risk from modded APKs remains. Kaspersky strongly advises users to:

Avoid downloading apps from untrusted third-party sources.

Only download apps from official app stores like Google Play.

Advertisement

Be wary of apps promising premium features for free.

Install a reputable mobile antivirus solution.

For Unparalleled coverage of India's Businesses and Economy – Subscribe to Business Today Magazine

Published on: Sep 25, 2024 3:31 PM IST
    Post a comment