Firstpost
  • Home
  • Video Shows
    Vantage Firstpost America Firstpost Africa First Sports
  • World
    US News
  • Explainers
  • News
    India Opinion Cricket Tech Entertainment Sports Health Photostories
  • Asia Cup 2025
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
Trending:
  • Nepal protests
  • Nepal Protests Live
  • Vice-presidential elections
  • iPhone 17
  • IND vs PAK cricket
  • Israel-Hamas war
fp-logo
More malware found on Google Play
Whatsapp Facebook Twitter
Whatsapp Facebook Twitter
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
  • Home
  • Tech
  • News & Analysis
  • More malware found on Google Play

More malware found on Google Play

Shunal Doke • July 11, 2012, 14:13:58 IST
Whatsapp Facebook Twitter

Google’s official Android market, Google Play was recently found to have more malware hosted; a discovery that demonstrates the limits of the

Advertisement
Subscribe Join Us
Add as a preferred source on Google
Prefer
Firstpost
On
Google
More malware found on Google Play

Google’s official Android store, Google Play was recently found to have some more malware hosted; a discovery that demonstrates the limits of the recently deployed scanning service that scours Google Play for malicious smartphone apps. The trojan - Android.Dropdialer, which racks up expensive charges from forced phonecalls to premium numbers, was found in two separate apps that weren’t identified for weeks, reports a blog post on the Symantec website by Irfan Asrar, a researcher with the antivirus provider.

STORY CONTINUES BELOW THIS AD

The apps “GTA 3 Moscow City” and “Super Mario Bros.” were carrying the trojan and generated as many as 10,000 downloads, though Asrar didn’t mention if that figure was for separate titles or in total. "What is most interesting about this Trojan is the fact that the threat managed to stay on Google Play for such a long time, clocking up some serious download figures before being discovered," Asrar wrote. “Our suspicion is that this was probably due to the remote payload employed by this Trojan."

More from News & Analysis
What is the US HIRE Bill and why is India’s $250-billion IT sector worried? What is the US HIRE Bill and why is India’s $250-billion IT sector worried? Is the internet dead? What's this theory that OpenAI's Sam Altman says might be true? Is the internet dead? What's this theory that OpenAI's Sam Altman says might be true?

Et tu Mario?

Et tu Mario?

Asrar had discussed malware deploying from a remote payload in a blog post last year where the author of the app would break it into separate staged payloads in order to avoid being detected during the automated QA screening process of the Play Store. “In the case of Android.Dropdialer, the first stage was posted on Google Play. Once installed, it would download an additional package hosted on Dropbox called ‘Activator.apk’.” he wrote.

Activator.apk sends SMS messages to a premium-rate number. It is interesting to note that the package attempts to uninstall itself after sending out the messages an obvious attempt to hide the true intent of the malicious app.

Another example of multiple payload malware is a variant of Android.Lightdd discovered last year, which runs a background process called “Game Services”. It attempts to connect to some domains and is responsible for reconnaissance and information gathering, such as phone model, language, country, IMEI, OS, etc. on the compromised device, and then continues to download additional payloads. The major obstacle for Android.Lightdd is that it requires the user to accept the installation of the app it has infected. However, another discovered threat, Android.Jsmshider, has found a way to overcome this obstacle.

STORY CONTINUES BELOW THIS AD

Asrar mentions in his old blog post about multiple payload malware, “By signing the payload with an Android Open Source Project (AOSP) certificate, the threat was capable of performing further downloads without any interactions or prompts, as the underlying device considered the payload to be a system update by virtue of the accompanying certificate. At this point, however, this deception only works for custom modifications.”

Android Security immediately removed the infected apps, “Super Mario Bros.” and “GTA 3 Moscow City”, from Google Play after Symantec notified them of the threat.

Tags
Google Android Malware Symantec Play Store Malware Apps
End of Article
Written by Shunal Doke
Email

Ever heard of one of those people who just never seem to shut up about something? Shunal is like the nerd equivalent of that guy. Believe us when we say that he can go on talking about games and smartphones for hours on end. We do manage to find some insight in his insane ramblings though, and through his moronic facade, he does seem to know more than he lets on. Sadly enough, it always ends up being about gaming with him. Or stupid, stupid puns. see more

Latest News
Find us on YouTube
Subscribe
End of Article

Top Stories

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Who is CP Radhakrishnan, India's next vice-president?

Who is CP Radhakrishnan, India's next vice-president?

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Who is CP Radhakrishnan, India's next vice-president?

Who is CP Radhakrishnan, India's next vice-president?

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Top Shows

Vantage Firstpost America Firstpost Africa First Sports
Latest News About Firstpost
Most Searched Categories
  • Web Stories
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Tech/Auto
  • Entertainment
  • IPL 2025
NETWORK18 SITES
  • News18
  • Money Control
  • CNBC TV18
  • Forbes India
  • Advertise with us
  • Sitemap
Firstpost Logo

is on YouTube

Subscribe Now

Copyright @ 2024. Firstpost - All Rights Reserved

About Us Contact Us Privacy Policy Cookie Policy Terms Of Use
Home Video Shorts Live TV