Overview of virus activity for mobile devices in October 2019

The second month of autumn this year turned out to be turbulent for owners Android-devices. Doctor Web virus analysts have discovered numerous malicious programs in the Google Play catalog, including Trojan-clickers. Android.Clickwho subscribed users to paid services. The detected threats also included malicious applications of the family Android.Joker. They also subscribed victims to expensive services and could execute arbitrary code. In addition, our experts have identified other Trojans.

Mobile Threat of the Month

In early October, Doctor Web informed users about several clicker Trojans added to the Dr.Web virus database as Android.Click.322.origin, Android.Click.323.origin и Android.Click.324.origin. These malicious apps silently downloaded websites where they signed up their victims for paid mobile services. Trojan features:

  • embedded in harmless programs;
  • protected by a commercial packer;
  • disguise themselves as well-known SDKs;
  • attack users of certain countries.

During the whole month, our virus analysts also detected other modifications of these clickers, for example, Android.Click.791, Android.Click.800, Android.Click.802, Android.Click.808, Android.Click.839, Android.Click.841. Later, similar malicious applications were found, which received the names Android.Click.329.origin, Android.Click.328.origin и Android.Click.844. They also subscribed victims to paid services, but their developers could be other virus writers. All these Trojans were hidden in seemingly harmless programs — cameras, photo editors, and collections of wallpapers for the desktop.

Overview of virus activity for mobile devices in October 2019 Overview of virus activity for mobile devices in October 2019
Overview of virus activity for mobile devices in October 2019 Overview of virus activity for mobile devices in October 2019

According to Dr.Web antivirus products, Android

Overview of virus activity for mobile devices in October 2019

  • Android.HiddenAds.472.origin — A Trojan that displays intrusive ads.
  • Android.RemoteCode.5564 - A malicious application that downloads and executes arbitrary code.
  • Android.Backdoor.682.origin — A Trojan that executes malicious commands and allows them to control infected mobile devices.
  • Android.DownLoader.677.origin - Loader of other malware.
  • Android.Triada.465.origin is a multifunctional Trojan that performs a variety of malicious actions.

Overview of virus activity for mobile devices in October 2019

Overview of virus activity for mobile devices in October 2019

Overview of virus activity for mobile devices in October 2019

  • Adware.Patacore.253
  • Adware.Myteam.2.origin
  • Adware.Toofan.1.origin
  • Adware.Adpush.6547
  • Adware.Altamob.1.origin

Trojans on Google Play

Along with clicker Trojans, Doctor Web's virus analysts have detected many new versions and modifications of already known malicious applications from the malware family on Google Play. Android.Joker. Among them - Android.Joker.6, Android.Joker.7, Android.Joker.8, Android.Joker.9, Android.Joker.12, Android.Joker.18 и Android.Joker.20.origin. These Trojans download and run additional malicious modules, are capable of executing arbitrary code, and subscribe users to expensive mobile services. They are distributed under the guise of useful and harmless programs - collections of images for the desktop, cameras with artistic filters, various utilities, photo editors, games, Internet messengers and other software.

Overview of virus activity for mobile devices in October 2019 Overview of virus activity for mobile devices in October 2019
Overview of virus activity for mobile devices in October 2019 Overview of virus activity for mobile devices in October 2019

In addition, our experts have discovered another adware Trojan from the Android.HiddenAdswho got the name Android.HiddenAds.477.originThe attackers distributed it under the guise of a video player and an app providing information about phone calls. Once launched, the Trojan hid its icon in the list of applications on the OS home screen. Android and started showing annoying ads.

Overview of virus activity for mobile devices in October 2019 Overview of virus activity for mobile devices in October 2019

Also, entries for detecting Trojans were added to the Dr.Web virus database. Android.SmsSpy.10437 и Android.SmsSpy.10447. They hid in the picture book and the camera app. Both malware intercepted the content of incoming SMS messages, while Android.SmsSpy.10437 could execute arbitrary code downloaded from the control server.

Overview of virus activity for mobile devices in October 2019 Overview of virus activity for mobile devices in October 2019

For guard Android- To protect devices from malicious and unwanted programs, users should install Dr.Web anti-virus products for Android.

Source: habr.com

Buy reliable hosting for sites with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster