Sunday, 24 Nov, 2024

Tech

Another malware alert

Adware found in Google Play store

ICT Desk |
Update: 2015-02-04 08:54:00
Adware found in Google Play store

DHAKA: A new report from security firm Avast out on Tuesday night reveals the discovery of a new form of malware on the Google Play store, which begins to display advertisements disguised as warning messages to end users when they unlock their Android smartphones.

What’s interesting about this malware – or adware, as it’s better known – is that some of the applications where it was discovered already have a large number of installs, reports the Tech Crunch.

According to the report, for instance, a card game app called Durak has 5 to 10 million installs.

Explains Avast researcher Filip Chytry, the malware was first brought to the company’s attention by way of a comment on the Avast forums, and, initially, he didn’t think much of it.

However, when he examined it further, he realized that the apps where the malware was found actually have a fairly large target audience.

Nevertheless, the apps are available in English-speaking countries and in other language versions as well, and have been downloaded by millions of users, assuming Google Play’s own data on app installs is accurate.

In addition to the card game, other apps, including an IQ test and a history app, were also found to be infected. The apps are from different developers, but each has the same malicious software installed.

The original commenter on Avast’s forums said he found the malware in a dozen infected applications and pointed to several more.

Avast says it has analyzed the three mentioned here, and is currently researching more apps that behave similarly right now. That means that the adware which already has an install base of millions, may actually be even larger still.


The apps are fairly clever about how they display the advertisements, too. Instead of beginning to show ads immediately after installation, they wait for several days. In some cases, the ads didn’t appear until after the app had been on the phone for a month.

“After 30 days, I guess not many people would know which app is causing abnormal behavior on their phone, right?” writes Chytry.

The ads also don’t begin showing up until you’ve rebooted your device at least once, he notes. Afterwards, the ads will appear each time the end user unlocks their phone, presenting warnings saying that your device is infected or “out of date” or is full of porn.

The user is then asked to take some action, but is instead redirected to downloads of other malware-laden apps, including those that send premium SMSes or those that collect a ton of personal data.

Oddly, users were also sometimes pointed to mobile antivirus apps on Google Play – some from legitimate companies. For instance, antivirus provider Quihoo 360 was one of the targets. It’s not likely that these companies are marketing their services via adware, however.

It’s more probable that the malware authors are benefitting from some sort of referral scheme.

Avast tells us that they’re now in touch with the antivirus company which was receiving the redirects, and that company is currently investigating the situation.

Obviously, using the Google Play Store to distribute malware is a violation of Google’s Terms of Service. We’ve reached out to Google to ask if it was aware of the problem Avast uncovered, and if it will investigate or ban the apps and the developers from its app store.

We will update this post if and when Google responds.

BDST: 1953 HRS, FEB 04, 2015

All rights reserved. Sale, redistribution or reproduction of information/photos/illustrations/video/audio contents on this website in any form without prior permission from banglanews24.com are strictly prohibited and liable to legal action.