Find news published in the date range below
and and
and and
and and
Clear
Euro
Arrow
53,9477
Dollar
Arrow
44,7286
Sterling
Arrow
63,0795
Gold
Arrow
6245,8354
BIST 100
Arrow
10.729

Kaspersky uncovers spyware infiltrating Google Play: Here is how your information is being stolen

Kaspersky experts have identified a new version of the 'Necro Trojan' software, which has infiltrated popular applications on Google Play and modified apps such as Spotify, WhatsApp, and Minecraft on unofficial platforms.

Don't leave your news choices to an algorithm - decide for yourself what you read. Add 12punto to your preferred sources!
Kaspersky uncovers spyware infiltrating Google Play: Here is how your information is being stolen

Kaspersky security experts have revealed that the malicious software 'Necro' has been targeting users in Russia, Brazil, Vietnam, Ecuador, and Mexico. According to the company's statement, Necro is defined as an Android downloader that downloads and executes additional malicious components on infected devices.

In the statement from Kaspersky, it was reported that Necro was first detected in a modified version of Spotify Plus, and was subsequently discovered in infected versions of various popular games such as WhatsApp, Minecraft, Stumble Guys, and Car Parking Multiplayer. Modified versions of these applications spread malware through unverified advertising modules.

The Necro variant can download modules that display ads in invisible windows on infected smartphones, click on them, download executable files, and install third-party applications. It can open random links in invisible WebView windows to execute JavaScript code. It can also subscribe users to paid services.

The downloaded modules allow attackers to route internet traffic through the victim's device. This enables cybercriminals to use the infected devices to visit banned or other resources.

A RARE TYPE OF ATTACK

On Google Play, Necro was embedded in applications such as Wuta Camera and Max Browser. It was noted that these two applications had been downloaded more than 11 million times in total, and that the malicious software has since been removed from Google Play. However, these risks persist for those using unofficial platforms.

Kaspersky recommends that users only download applications from official sources, perform regular updates, and use reliable security solutions to protect against these and similar threats.

In the statement, Kaspersky Cybersecurity Expert Dmitry Kalinin explained that Necro spreads when users download unofficial, modified applications to bypass restrictions in official apps.

Kalinin stated the following in his remarks:

'Cybercriminals take advantage of this behavior to spread malware through these applications because there is no oversight on third-party platforms. It is also noteworthy that the version of Necro embedded in these applications uses steganography techniques and hides its payload inside images to avoid detection. This is a very rare method in mobile malware.'


News Source: AA

Kaspersky smartphone spyware