Beware of malicious apps on Google Play... Downloaded 32,000 times...
Researchers from the Russia-based cybersecurity company Kaspersky have discovered a new spyware campaign that distributes the Mandrake malware under the guise of legitimate applications related to cryptocurrency, astronomy, and utility tools on Google Play.
Kaspersky experts have identified five Mandrake applications that were available on Google Play for two years and downloaded more than 32,000 times. These newly captured samples feature advanced obfuscation and evasion techniques that allow them to remain undetected by security systems.
First detected in 2020, the Mandrake spyware has been circulating as an advanced Android espionage platform that has been active since at least 2016. In April 2024, Kaspersky researchers uncovered a suspicious sample pointing to a new version of Mandrake with enhanced functionality. These new samples feature advanced obfuscation and evasion techniques, such as embedding malicious functions into native libraries obfuscated using OLLVM, performing certificate pinning for secure communication with command and control (C2) servers, and conducting comprehensive checks to detect whether Mandrake is running on a rooted device or an emulated environment.
DOWNLOADED MORE THAN 32,000 TIMES VIA 5 APPS
The most significant distinguishing feature of the new Mandrake variant is the addition of advanced obfuscation techniques designed to bypass Google Play's security checks and hinder analysis. The company's experts identified five applications containing the Mandrake spyware, which were collectively downloaded more than 32,000 times. All of these applications were published on Google Play in 2022 and remained available for download for at least a year. The applications were presented on the store under the guise of a Wi-Fi file sharing app, an astronomy app, the Amber for Genshin game, a cryptocurrency app, and a logic puzzle app. According to VirusTotal, as of July 2024, none of these applications were detected as malware by any vendor.
Although these malicious applications are no longer available on Google Play, the majority of the downloads were in a wide variety of countries, including Canada, Germany, Italy, Mexico, Spain, Peru, and the United Kingdom.
'REMAINED UNDETECTED ON GOOGLE PLAY FOR TWO YEARS'
Tatyana Shishkova, Lead Security Researcher at Kaspersky's GReAT (Global Research and Analysis Team), stated: “The Mandrake campaign, which evaded detection for four years in its initial versions, managed to remain undetected on Google Play for another two years. This demonstrates the advanced skills of the threat actors in question. This also highlights a disturbing trend: as restrictions tighten and security checks become more rigorous, the complexity of threats infiltrating official app stores increases, making them harder to detect.”
You can visit Securelist.com to learn more about the new Mandrake spyware campaign.
'STAYING SAFE' TIPS FROM EXPERTS
Kaspersky experts recommend that you consider the following tips to stay safe against threats like the Mandrake spyware:
Use official app marketplaces. Download applications and software from reputable and official sources. Avoid third-party app stores as they have a higher risk of hosting malicious or compromised applications. Remember that even official platforms can host malicious apps. Always check reviews and ratings before downloading.
Choose reputable security software. Install and maintain reputable antivirus and anti-malware software on your devices. Regularly scan your devices for potential threats and keep your security software up to date. Kaspersky Premium protects its users against known and unknown threats.
Educate yourself about common fraud methods. Stay informed about the latest cyber threats, techniques, and tactics. Always approach unsolicited requests, suspicious offers, or urgent demands for personal or financial information with skepticism.
Third-party software obtained from popular sources often comes with zero guarantees. Keep in mind that such applications may contain malicious implants, for example, due to supply chain attacks.
News Source: 12punto
Most Read
Striking picture for Özgür Özel's 'New Party'
The PKK opening and Özgür Özel’s path!..
How did the newspapers view Özgür Özel's farewell to the CHP?
He killed his wife by slitting her throat: Their children witnessed the moments
What did the CHP do?
Özel’s new party move in the world press
Kılıçdaroğlu's first message on Özgür Özel's new party announcement
The New CHP, against CEHAPE
From self-efficacy to despair
Zeydan Karalar's decision on the New Party