Recent observance by researchers in the Google Play Store showed that numbers of applications are malicious to the user. The malicious activities performed includes the stealing of credentials, private information such as private keys of the user’s crypto currency wallets.
These applications are named as Facestealer Spywares, which steals Facebook credentials from users through fake applications from the Google Play Store.
The stolen information, later used to compromise Facebook accounts for activities such as phishing scams, ad bots and more.
This Facestealer changes its code frequently creating more variants. From the day of its discovery, it has been constantly up against Google Play Store.
Of the 200 fake applications, 42 are VPN Services, 20 camera applications, 13 Photo-editing applications. Along with harvesting credentials, the apps are also designed to steal Facebook cookies and personally identifiable information associated with a victim’s account.
Also, Trend Micro disclosed that it uncovered over 40 rogue cryptocurrency miner apps that target users interested in virtual coins with malware designed to trick users into watching ads and paying for subscription services.
It also disclosed information about a few malicious applications that were involved and studied during their research process.
Their investigation further revealed that most of these fraudulent crypto mining applications are developed using the Kodular, a free online suite used for mobile application development.
These Fake apps are impersonating as genuine simple applications such as, Virtual Private Networks, Cameras, Picture Editing applications, and even as Fitness applications, to tempt the users in installing the applications in their devices.
They could be avoided by checking their reviews, especially the negative ones, to see if there are any unusual concerns or experiences from actual users who have downloaded the apps.
Users should steer clear of downloading apps from third-party sources, since these are where many malicious actors host their fraudulent apps.
INDICATORS OF COMPROMISE
|SHA-256||Package name||Detection name||Download count before being taken down|
|SHA-256||Package name||Detection name|