Many new Trojans for Android discovered on Google Play

Doctor Web, a cybersecurity company, published a report on malicious activity for mobile devices in January 2021.

Many new Trojans for Android discovered on Google Play

And although the total number of threats detected on Android devices has decreased, in January Doctor Web’s experts identified many new malicious and unwanted programs on Google Play. Among them were multifunctional Trojans that subscribed victims to paid services, and Trojans that loaded fraudulent websites, as well as applications with unwanted ad modules embedded in them. In addition, the owners of Android devices encountered banking Trojans.

Many new Trojans for Android discovered on Google Play

Applications with built-in adware modules of the Adware.NewDich family, which load various websites in the browser at the command of the command and control server, were announced as the threat of the month.

Many new Trojans for Android discovered on Google Play

These can be both harmless Internet resources and sites with advertising or fraudulent sites used for phishing. They are downloaded when users are not using applications containing Adware.NewDich. This makes it harder to pinpoint the cause of strange behavior on Android devices.

Many new Trojans for Android discovered on Google Play

In addition to applications with adware modules Adware.NewDich, in January Doctor Web specialists detected many new Trojans of the Android.FakeApp family on Google Play, which were distributed under the guise of software with information about social benefits, benefits, VAT refunds and other monetary compensations.

Many new Trojans for Android discovered on Google Play

At the same time, there were other modifications among them – for example, presented as programs for finding information about lotteries and receiving gifts from popular bloggers.

Many new Trojans for Android discovered on Google Play

In addition, new multifunctional Trojans belonging to the Android.Joker family and named Android.Joker.496, Android.Joker.534 and Android.Joker.535 were discovered. They were distributed under the guise of harmless applications – translation software and a multimedia editor for creating animated GIFs. However, their real functions were downloading and executing arbitrary code, as well as intercepting the content of notifications and subscribing users to premium services.

.

You may also like