Description

Dr. Web, a company specialized in anti-virus products for Android, published a report on December 2, 2022, to reveal about new set of Android malware, phishing and adware apps on the Google Play store which tricked over two million people into installing them. These apps pretend to be useful utilities and system optimizers, but instead lead to performance hiccups, ads, and user experience degradation. One of the apps revealed by Dr. Web is "TubeBox", which has over one million downloads and it is still available on Google Play. TubeBox is an app that promises monetary rewards for watching ads and videos but instead presents various errors when users try to redeem the collected reward, and even if the users are able to clear the withdrawal step, they never receive the fund. instead, it is a trick to keep users on the app as long as possible to generate revenue for the developers. Moreover, the other apps which appeared on Google Play in October 2022 but have been removed since are 1. "Bluetooth device auto connect" (bt autoconnect group) has over 1,000,000 downloads 2. "Bluetooth & Wi-Fi & USB driver" (simple things for everyone) has over 100,000 downloads 3. "Volume, Music Equalizer" (bt autoconnect group) has over 50,000 downloads 4. "Fast Cleaner & Cooling Master" (Hippo VPN LLC) has over 500 downloads All these apps receive a command from Firebase Cloud Messaging to load the particular website mentioned in the commands, making fraudulent ad impressions on the infected devices. Additionally, the "Fast Cleaner & Cooling Master" app can also be used by the remote operators to configure an infected device to act as a proxy server, which would allow the threat actor to channel their own traffic. Furthermore, Dr. Web also discovered a couple of loan scam apps which are pretended to be a Russian bank or an investment group with each having more than 10,000 downloads. These apps are promoted via malvertizing through other apps on Google Play that, when visited, take the users to phishing sites to steal and collect their personal information.