- By Vikas Yadav
- Thu, 01 Jun 2023 12:24 PM (IST)
- Source:JND
SEVERAL cyber security researchers and companies have repeatedly flagged malicious apps on Google Play Store. The latest one is among the biggest ones we've heard recently. According to Doctor Web, a cybersecurity company, 101 apps with over 400 million downloads were affected by a software module having spyware capabilities.
Dr Web said the module can collect data from files that include clipboard contents and send them to "malicious" actors. Dubbed "SpinOk" it is an advertising SDK (software development kit) that can be embedded in apps and games on the Google Play Store.
On the face of it, it maintains interest in apps via mini-games, alleged prizes and rewards. Once configured, it establishes a connection with a C&C server and forwards "technical information" to these servers.
"Included are data from sensors, e.g., gyroscope, magnetometer, etc., that can be used to detect an emulator environment and adjust the module's operating routine in order to avoid being detected by security researchers."
Additionally, the trojan SDK can expand the capabilities of JavaScript code to retrieve files from specific directories, verify file location, substitute clipboard contents and more. As a corrective measure, the research company reported the finding to Google.
Further, the company listed the top 10 most downloaded apps in the report. They are shared below.
- Noizz: video editor with music
- Zapya - File Transfer, Share
- VFly: video editor & video maker
- MVBit - MV video status maker
- Biugo - video maker&video editor
- Crazy Drop
- Cashzine - Earn money reward
- Fizzo Novel - Reading Offline
- CashEM: Get Rewards
- Tick: watch to earn
In case you have installed any of these apps on your Android device, we recommend you uninstall them immediately. Additionally, here are a few measures you can take to ensure device safety.
Malware Apps: How you can be safe?
- Ensure you download apps from popular developers and check reviews before installing an app
- Do not install apps from unknown sources
- Restrict unnecessary permission to apps
- Monitor internet usage by apps and cross-check if an app is consuming more than usual data