Overview of virus activity for mobile devices in October 2019

The second autumn month of this year turned out to be turbulent for owners of Android devices. Doctor Web virus analysts have found a lot of malicious programs in the Google Play catalog, in particular, clicker Trojans Android.Clickwho subscribed users to paid services. The detected threats also included malicious applications of the family Android.Joker. They also subscribed victims to expensive services and could execute arbitrary code. In addition, our experts have identified other Trojans.

Mobile Threat of the Month

In early October, Doctor Web informed users about several clicker Trojans added to the Dr.Web virus database as Android.Click.322.origin, Android.Click.323.origin ΠΈ Android.Click.324.origin. These malicious apps silently downloaded websites where they signed up their victims for paid mobile services. Trojan features:

  • embedded in harmless programs;
  • protected by a commercial packer;
  • disguise themselves as well-known SDKs;
  • attack users of certain countries.

During the whole month, our virus analysts also detected other modifications of these clickers, for example, Android.Click. 791, Android.Click. 800, Android.Click. 802, Android.Click. 808, Android.Click. 839, Android.Click. 841. Later, similar malicious applications were found, which received the names Android.Click.329.origin, Android.Click.328.origin ΠΈ Android.Click. 844. They also subscribed victims to paid services, but their developers could be other virus writers. All these Trojans were hidden in seemingly harmless programs β€” cameras, photo editors, and collections of wallpapers for the desktop.

Overview of virus activity for mobile devices in October 2019 Overview of virus activity for mobile devices in October 2019
Overview of virus activity for mobile devices in October 2019 Overview of virus activity for mobile devices in October 2019

According to Dr.Web anti-virus products for Android

Overview of virus activity for mobile devices in October 2019

  • Android.HiddenAds.472.origin β€” A Trojan that displays intrusive ads.
  • Android.RemoteCode.5564 - A malicious application that downloads and executes arbitrary code.
  • android.backdoor.682.origin β€” A Trojan that executes malicious commands and allows them to control infected mobile devices.
  • Android.DownLoader.677.origin - Loader of other malware.
  • Android.Triada.465.origin is a multifunctional Trojan that performs a variety of malicious actions.

Overview of virus activity for mobile devices in October 2019

Overview of virus activity for mobile devices in October 2019

Overview of virus activity for mobile devices in October 2019

  • Adware.Patacore. 253
  • Adware.Myteam.2.origin
  • Adware.Toofan.1.origin
  • Adware.Adpush.6547
  • Adware.Altamob.1.origin

Trojans on Google Play

Along with clicker Trojans, Doctor Web's virus analysts have detected many new versions and modifications of already known malicious applications from the malware family on Google Play. Android.Joker. Among them - Android.Joker.6, Android.Joker.7, Android.Joker.8, Android.Joker.9, Android.Joker. 12, Android.Joker. 18 ΠΈ Android.Joker.20.origin. These Trojans download and run additional malicious modules, are capable of executing arbitrary code, and subscribe users to expensive mobile services. They are distributed under the guise of useful and harmless programs - collections of images for the desktop, cameras with artistic filters, various utilities, photo editors, games, Internet messengers and other software.

Overview of virus activity for mobile devices in October 2019 Overview of virus activity for mobile devices in October 2019
Overview of virus activity for mobile devices in October 2019 Overview of virus activity for mobile devices in October 2019

In addition, our experts have discovered another adware Trojan from the Android.HiddenAdswho got the name Android.HiddenAds.477.origin. The attackers distributed it under the guise of a video player and an application that provides information about phone calls. Once launched, the Trojan hid its icon in the list of applications on the main screen of the Android OS and started displaying annoying ads.

Overview of virus activity for mobile devices in October 2019 Overview of virus activity for mobile devices in October 2019

Also, entries for detecting Trojans were added to the Dr.Web virus database. Android.SmsSpy. 10437 ΠΈ Android.SmsSpy. 10447. They hid in the picture book and the camera app. Both malware intercepted the content of incoming SMS messages, while Android.SmsSpy. 10437 could execute arbitrary code downloaded from the control server.

Overview of virus activity for mobile devices in October 2019 Overview of virus activity for mobile devices in October 2019

To protect Android devices from malicious and unwanted programs, users should install Dr.Web anti-virus products for Android.

Source: habr.com

Add a comment