Beware of malicious apps on Google Play... Downloaded 32,000 times...

Researchers from the Russia-based cybersecurity company Kaspersky have discovered a new spyware campaign that distributes the Mandrake malware under the guise of legitimate applications related to cryptocurrency, astronomy, and utility tools on Google Play.

12punto

Kaspersky experts have identified five Mandrake applications that were available on Google Play for two years and downloaded more than 32,000 times. These newly captured samples feature advanced obfuscation and evasion techniques that allow them to remain undetected by security systems. 

First detected in 2020, the Mandrake spyware has been circulating as an advanced Android espionage platform that has been active since at least 2016. In April 2024, Kaspersky researchers uncovered a suspicious sample pointing to a new version of Mandrake with enhanced functionality. These new samples feature advanced obfuscation and evasion techniques, such as embedding malicious functions into native libraries obfuscated using OLLVM, performing certificate pinning for secure communication with command and control (C2) servers, and conducting comprehensive checks to detect whether Mandrake is running on a rooted device or an emulated environment. 

DOWNLOADED MORE THAN 32,000 TIMES VIA 5 APPS

The most significant distinguishing feature of the new Mandrake variant is the addition of advanced obfuscation techniques designed to bypass Google Play's security checks and hinder analysis. The company's experts identified five applications containing the Mandrake spyware, which were collectively downloaded more than 32,000 times. All of these applications were published on Google Play in 2022 and remained available for download for at least a year. The applications were presented on the store under the guise of a Wi-Fi file sharing app, an astronomy app, the Amber for Genshin game, a cryptocurrency app, and a logic puzzle app. According to VirusTotal, as of July 2024, none of these applications were detected as malware by any vendor.

Although these malicious applications are no longer available on Google Play, the majority of the downloads were in a wide variety of countries, including Canada, Germany, Italy, Mexico, Spain, Peru, and the United Kingdom.

'REMAINED UNDETECTED ON GOOGLE PLAY FOR TWO YEARS'

Tatyana Shishkova, Lead Security Researcher at Kaspersky's GReAT (Global Research and Analysis Team), stated: “The Mandrake campaign, which evaded detection for four years in its initial versions, managed to remain undetected on Google Play for another two years. This demonstrates the advanced skills of the threat actors in question. This also highlights a disturbing trend: as restrictions tighten and security checks become more rigorous, the complexity of threats infiltrating official app stores increases, making them harder to detect.”

You can visit Securelist.com to learn more about the new Mandrake spyware campaign.

'STAYING SAFE' TIPS FROM EXPERTS

Kaspersky experts recommend that you consider the following tips to stay safe against threats like the Mandrake spyware:

Use official app marketplaces. Download applications and software from reputable and official sources. Avoid third-party app stores as they have a higher risk of hosting malicious or compromised applications. Remember that even official platforms can host malicious apps. Always check reviews and ratings before downloading. 

Choose reputable security software. Install and maintain reputable antivirus and anti-malware software on your devices. Regularly scan your devices for potential threats and keep your security software up to date. Kaspersky Premium protects its users against known and unknown threats. 

Educate yourself about common fraud methods. Stay informed about the latest cyber threats, techniques, and tactics. Always approach unsolicited requests, suspicious offers, or urgent demands for personal or financial information with skepticism. 

Third-party software obtained from popular sources often comes with zero guarantees. Keep in mind that such applications may contain malicious implants, for example, due to supply chain attacks.