Kaspersky uncovers spyware infiltrating Google Play: Here is how your information is being stolen
Kaspersky experts have identified a new version of the 'Necro Trojan' software, which has infiltrated popular applications on Google Play and modified apps such as Spotify, WhatsApp, and Minecraft on unofficial platforms.
Kaspersky security experts have revealed that the malicious software 'Necro' has been targeting users in Russia, Brazil, Vietnam, Ecuador, and Mexico. According to the company's statement, Necro is defined as an Android downloader that downloads and executes additional malicious components on infected devices.
In the statement from Kaspersky, it was reported that Necro was first detected in a modified version of Spotify Plus, and was subsequently discovered in infected versions of various popular games such as WhatsApp, Minecraft, Stumble Guys, and Car Parking Multiplayer. Modified versions of these applications spread malware through unverified advertising modules.
The Necro variant can download modules that display ads in invisible windows on infected smartphones, click on them, download executable files, and install third-party applications. It can open random links in invisible WebView windows to execute JavaScript code. It can also subscribe users to paid services.
The downloaded modules allow attackers to route internet traffic through the victim's device. This enables cybercriminals to use the infected devices to visit banned or other resources.

A RARE TYPE OF ATTACK
On Google Play, Necro was embedded in applications such as Wuta Camera and Max Browser. It was noted that these two applications had been downloaded more than 11 million times in total, and that the malicious software has since been removed from Google Play. However, these risks persist for those using unofficial platforms.
Kaspersky recommends that users only download applications from official sources, perform regular updates, and use reliable security solutions to protect against these and similar threats.
In the statement, Kaspersky Cybersecurity Expert Dmitry Kalinin explained that Necro spreads when users download unofficial, modified applications to bypass restrictions in official apps.
Kalinin stated the following in his remarks:
'Cybercriminals take advantage of this behavior to spread malware through these applications because there is no oversight on third-party platforms. It is also noteworthy that the version of Necro embedded in these applications uses steganography techniques and hides its payload inside images to avoid detection. This is a very rare method in mobile malware.'

News Source: AA
Most Read
Historic words from Özgür Özel at the CHP group meeting
Air Force Academy student Veli Bilgin has died
Striking picture for Özgür Özel's 'New Party'
The PKK opening and Özgür Özel’s path!..
How did the newspapers view Özgür Özel's farewell to the CHP?
He killed his wife by slitting her throat: Their children witnessed the moments
Tuncer Bakırhan calls for a framework law
Here are the names that will be in Özgür Özel's new party!
What did the CHP do?
AKP mayor held responsible