11 million Android devices infected with malware from Google Play

A report from Kaspersky shows that more than 11 million Android devices have been infected with Necro malware through two seemingly harmless applications on Google Play.

Table of Contents

Necro was first discovered in 2019 in the text recognition app CamScanner with over 100 million downloads on Google Play.

11 million Android devices infected with malware from Google Play

Recently, cyber security researchers have discovered that Necro has reappeared both in popular applications on Google Play and in various app versions on unofficial websites. The new version of this malware has been upgraded with more features.

Kaspersky experts believe that the developers of legitimate applications may have used an unverified ad integration tool, which helped Necro infiltrate.

Wuta Camera and Max Browser, two popular apps on Google Play, have been found to contain Necro malware with a total of over 11 million downloads.

Necro has been able to bypass security systems using a technique called steganography, which hides malware inside images. Once on a device, the malware takes control, downloads additional malware, and even secretly subscribes to paid services without the user knowing.

Users should immediately remove apps like Wuta Camera (infected versions 6.3.2.148 to 6.3.6.148) and Max Browser if installed.

31 apps that steal bank account information, should be deleted immediately (September 3, 2024)

The 31 malicious apps below are capable of stealing login information to bank accounts without the user's permission.

Security researchers have discovered a malware called “Daam” that can bypass security applications installed on smartphones and cause many serious consequences.

11 million Android devices infected with malware from Google Play

This type of malware is assessed by experts as having a sophisticated way of operating, being able to steal data, collect sensitive information, eavesdrop and record all incoming and outgoing calls on the victim's smartphone, including calls made via applications such as Messenger, Telegram or WhatsApp...

According to CloudSEK experts, there are 3 applications containing Daam malware:

  • Psiphon application creates a virtual private network (VPN).
  • Boulders mobile game.
  • Currency Pro currency value converter application.

In addition, international information security research organizations said they have discovered 28 applications that tend to spread malware, disguised as useful applications to trick users into installing them. 17 of these applications disguise themselves as VPN tools, with advertisements that help users browse the web more securely and hide real information on the Internet.

28 apps containing malicious code include:

  • Lite VPN;
  • Anims Keyboard;
  • Blaze Stride;
  • Byte Blade VPN;
  • Android 12 Launcher;
  • Android 13 Launcher;
  • Android 14 Launcher;
  • CaptainDroid Feeds;
  • Free Old Classic Movies;
  • Phone Comparison;
  • Fast Fly VPN;
  • Fast Fox VPN;
  • Fast Line VPN;
  • Funny Char Ging Animation;
  • Limo Edges;
  • OK VPN;
  • Phone App Launcher;
  • Quick Flow VPN;
  • Sample VPN;
  • Secure Thunder;
  • Shine Secure;
  • Speed ​​Surf;
  • Swift Shield VPN;
  • TurboTrack VPN;
  • Turbo Tunnel VPN;
  • Yellow Flash VPN;
  • VPN Ultra;
  • Run VPN.

Experts warn that if users' devices contain these applications, they should quickly remove them to avoid unfortunate risks. At the same time, to ensure safety, users should not download strange applications, activate the Google Play Protect feature in Google Play to be protected from malware and use reliable anti-virus solutions.

NGate malware uses NFC reader to drain victims' money (August 27)

Cybersecurity firm ESET has discovered an Android malware that uses the NFC reader on an infected device to capture payment data from the phone and relay that information to a crook.

This malware uses the NFCGate toolkit to analyze NFC traffic, hence the name NGate.

11 million Android devices infected with malware from Google Play

This malware would allow crooks to withdraw money or pay for purchases at cash registers using user data at ATMs and POS (point of sale) machines.

NGate works by sending an instant message containing a link to a fake website that collects the victim's login credentials, asking the victim to install an application because there is a problem with their tax return. Based on the collected information, the attacker will gain access to the target's bank account.

The attacker then poses as a bank employee and calls the victim to send a text message containing a link to an app, which is actually the NGate malware. The attacker then asks the victim to enable NFC on their phone and swipe their card.

Using the compromised smartphone, NGate can relay NFC data from the victim's card to the attacker's smartphone, which can then emulate the card. From there, the crook will receive real-time information and withdraw money from the ATM.

Thanks to Google Play Protect's automatic protection, no apps containing NGate are currently detected on Google Play.

Warning: New malware specializes in stealing money and wiping Android devices

Security experts have discovered a new Android malware called 'BingoMod' that can steal money from bank accounts and wipe out victims' phone data.

BingoMod typically disguises itself as popular mobile security apps, and is distributed via phishing SMS messages to trick users into installing it. Once installed, the malware asks users to grant access to accessibility services, allowing it to take full control of the device to steal login credentials, take screenshots, intercept messages, and even conduct fraudulent transactions directly on the device.

11 million Android devices infected with malware from Google Play

According to research results, each transaction of this malware can be stolen up to more than 16,000 USD (about 404 million VND).

In addition, after successfully withdrawing money, BingoMod can also erase data on the phone, making it difficult for victims to recover information.

BingoMod is still in development at the moment and will definitely become more dangerous in the future.

Therefore, experts warn that Android users need to be especially vigilant with SMS messages containing links to download strange applications, especially those with names related to security to protect their bank accounts and personal data. In addition, users should carefully check the developer information and read other users' reviews before installing any application.

How to check if your smartphone has malicious apps installed

Users can use the "Play Protect" feature integrated by Google on CH Play to check if their smartphone has accidentally installed any applications containing malicious code.

To use this feature, users need to access the CH Play app store -> click on the account icon in the upper right corner -> select " Play Protect " settings -> click on the " Scan " button.

After scanning, if the message " No harmful applications found " appears, your phone is safe.

However, Play Protect only protects your smartphone from apps that Google has identified as malicious. In cases where Google has not identified apps containing malicious code, this feature cannot warn users.

How to remove malicious apps on Android smartphones

To remove malicious applications on Android smartphones, you need to access Settings -> select the Applications tab -> select Manage applications -> find the application you want to remove, click on it and select Uninstall .

Sign up and earn $1000 a day ⋙

Leave a Comment

Difference between regular TV and Smart TV

Difference between regular TV and Smart TV

Smart TVs have really taken the world by storm. With so many great features and the ability to connect to the Internet, technology has changed the way we watch TV.

Why doesnt the freezer have a light but the refrigerator does?

Why doesnt the freezer have a light but the refrigerator does?

Refrigerators are familiar appliances in families. Refrigerators usually have 2 compartments, the cool compartment is spacious and has a light that automatically turns on every time the user opens it, while the freezer compartment is narrow and has no light.

2 Ways to Fix Network Congestion That Slows Down Wi-Fi

2 Ways to Fix Network Congestion That Slows Down Wi-Fi

Wi-Fi networks are affected by many factors beyond routers, bandwidth, and interference, but there are some smart ways to boost your network.

How to Downgrade from iOS 17 to iOS 16 without Losing Data using Tenorshare Reiboot

How to Downgrade from iOS 17 to iOS 16 without Losing Data using Tenorshare Reiboot

If you want to go back to stable iOS 16 on your phone, here is the basic guide to uninstall iOS 17 and downgrade from iOS 17 to 16.

What happens to the body when you eat yogurt every day?

What happens to the body when you eat yogurt every day?

Yogurt is a great food. Is it good to eat yogurt every day? What will happen to your body when you eat yogurt every day? Let's find out together!

Which type of rice is best for health?

Which type of rice is best for health?

This article discusses the most nutritious types of rice and how to maximize the health benefits of whichever rice you choose.

How to wake up on time in the morning

How to wake up on time in the morning

Establishing a sleep schedule and bedtime routine, changing your alarm clock, and adjusting your diet are some of the measures that can help you sleep better and wake up on time in the morning.

Rent Please! Landlord Sim Tips for Beginners

Rent Please! Landlord Sim Tips for Beginners

Rent Please! Landlord Sim is a simulation mobile game on iOS and Android. You will play as a landlord of an apartment complex and start renting out an apartment with the goal of upgrading the interior of your apartments and getting them ready for rent.

Latest Bathroom Tower Defense Codes and How to Enter Codes

Latest Bathroom Tower Defense Codes and How to Enter Codes

Get Bathroom Tower Defense Roblox game codes and redeem them for exciting rewards. They will help you upgrade or unlock towers with higher damage.

Structure, symbols and operating principles of transformers

Structure, symbols and operating principles of transformers

Let's learn about the structure, symbols and operating principles of transformers in the most accurate way.

4 Ways AI Is Making Smart TVs Better

4 Ways AI Is Making Smart TVs Better

From better picture and sound quality to voice control and more, these AI-powered features are making smart TVs so much better!

Why ChatGPT is better than DeepSeek

Why ChatGPT is better than DeepSeek

DeepSeek initially had high hopes. As an AI chatbot marketed as a strong competitor to ChatGPT, it promised intelligent conversational capabilities and experiences.

Meet Fireflies.ai: The Free AI Secretary That Saves You Hours of Work

Meet Fireflies.ai: The Free AI Secretary That Saves You Hours of Work

It's easy to miss important details when you're jotting down other essentials, and trying to take notes while chatting can be distracting. Fireflies.ai is the solution.

How to raise Axolotl Minecraft, tame Minecraft Salamander

How to raise Axolotl Minecraft, tame Minecraft Salamander

Axolot Minecraft will be a great assistant for players when operating underwater if they know how to use them.

A Quiet Place: The Road Ahead PC Game Configuration

A Quiet Place: The Road Ahead PC Game Configuration

A Quiet Place: The Road Ahead's configuration is rated quite highly, so you will need to consider the configuration before deciding to download.