Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity

    Malware Posing as Legitimate Apps on Google Play, Security Firm Warns

    Written by

    Jaikumar Vijayan
    Published April 30, 2016
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      The people most at risk of downloading Android malware on their mobile devices are those who install apps from unofficial third-party mobile application stores. But that doesn’t mean that those who download apps from Google’s official Google Play store are completely immune to malicious software.

      PhishLabs, a company that provides anti-phishing services, this week said it has discovered 11 malicious applications disguised as mobile apps for popular online payment services on Google Play since the beginning of this year.

      The applications purport to give users access to their online payment accounts from their mobile devices, PhishLabs security analyst Joshua Shilko said in a blog post this week. But in reality, the only functionality the apps have is to collect the user’s logon credentials and personal data and to send that to a remote command and control server belonging to the malware authors, Shilko said.

      PhishLabs did not identify the 11 payment brands whose apps were spoofed and uploaded to Google Play. According to Shilko, 10 of the companies whose customers are being targeted by the malicious apps provide links in their Websites directly to their mobile applications. One of the companies being targeted explicitly notes on its Website that it has no mobile application, he added. All of the apps appear to have been developed by the same malware author or authors.

      Android owners who mistakenly download and use the fake apps are presented with a Web page designed to look and act like the real brand’s Web page. Any logon credentials a user supplies to the fake app are immediately sent to the attacker.

      The phishing apps then present the user with more forms seeking additional information such as the answers the user might have supplied to the apps’ security questions. Once the malware has collected and sent all the information, it presents the user with an error message claiming that either the username and password combination was wrong or some other similar error.

      Google did not respond to a message seeking information on how the same attackers might have managed to upload 11 malicious apps to its Google Play store since the beginning of January.

      Google, which used to have relatively little controls for checking the security of applications loaded to its Android app store, these days reviews all submissions using a combination of manual and automated security testing processes.

      But the presence of the malicious payment apps in Google Play suggests more work needs to be done in this regard, Shilko said. All of the malicious applications that PhishLabs identified went through Google’s security review process. The fact that none was identified as malware, despite some obvious red flags, raises questions about the effectiveness of Google’s security review processes, he said.

      In separate comments to eWEEK, Shilko said PhishLabs has been communicating with Google regularly regarding each application as it is detected. “We also communicate with the registrars and hosting providers whose infrastructure is being utilized for the related phishing content,” he said. “At of the time of publication, all of the applications referenced in the post had been removed except for one.”

      Jaikumar Vijayan
      Jaikumar Vijayan
      Vijayan is an award-winning independent journalist and tech content creation specialist covering data security and privacy, business intelligence, big data and data analytics.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.