Thursday, January 23, 2025
spot_img

New malware threats target Android users on Google Play

Date:

Share post:

spot_img
spot_img

Shillong, July 30: A recent report by cybersecurity software company Trend Micro has revealed the discovery of two new malware families on Google Play, named CherryBlos and FakeTrade.

These malicious apps are specifically designed to steal cryptocurrency credentials and funds, as well as conduct scams using optical character recognition (OCR).

Both malware families appear to be the work of the same threat actors, as they use the same network infrastructure and certificates. The distribution of these harmful apps is wide-ranging, with channels including social media, phishing websites, and even legitimate shopping apps on Google Play.

IANS reported that CherryBlos malware was initially spotted in April 2023, masquerading as APK files marketed as AI tools or cryptocurrency miners on platforms like Telegram, Twitter, and YouTube. The malicious APKs go by names such as GPTalk, Happy Miner, Robot999, and SynthNet.

Once the CherryBlos malware is downloaded (AndroidOS_CherryBlos.GCL), it gains the ability to steal cryptocurrency wallet-related credentials and manipulate victims’ withdrawal addresses. Additionally, the malware possesses an intriguing feature enabled through OCR. This feature allows CherryBlos to extract text from photos and images, which is then uploaded to the command-and-control (C&C) server at regular intervals.

The FakeTrade malware, on the other hand, was linked to a Google Play campaign involving 31 scam apps. These apps use the same C2 network infrastructure and certifications as the CherryBlos apps. The FakeTrade apps employ shopping themes and enticing money-making promises to deceive users into watching commercials, subscribing to premium services, or adding funds to their in-app wallets, all while preventing them from claiming the virtual rewards.

The discovery of these new malware families highlights the ongoing importance of vigilance and caution when downloading apps from Google Play or other sources. Android users must stay aware of potential threats and employ cybersecurity measures to protect their devices and sensitive information.

spot_img
spot_img

Related articles

WEF 2025: WHO’s role essential for maintaining global health systems, says Adar Poonawalla

New Delhi, Jan 23: Even as the US has pulled out from the World Health Organization, Serum Institute...

Foreign cigarettes valued at 3.38 crore seized in Mizoram, one arrested

Aizawl, Jan 23: Foreign cigarettes valued at Rs 3.38 crore were seized from Tuichang bridge areas of Lawngtlai...

Subhas Chandra Bose’s grand nephew recalls PM Modi’s efforts in honouring Netaji’s legacy

New Delhi, Jan 23: As the nation celebrates ‘Parakram Diwas’ (day of valour) marking the birth anniversary of...

Negligence caused Jalgaon train tragedy: Majeed Memon slams Indian Railways

Mumbai, Jan 23:  Senior NCP (SP) leader Majeed Memon on Thursday slammed the Indian Railways following the tragic...