Malware for Android makes secret recording in Premium SMS services

Malware Malware Android.Trojan.MKero.A makes a come back to the Android country and this time hackers have found a way to combine it with legitimate applications to bypass Google's Bouncer scanning system.

Android Fake ID Malware

While Malware was first detected in 2014 and distributed primarily to users through insecure application deployment, Bitdefender reports that in many cases the trojan was found to be distributed today via the official Google Play Store.

This time, the malware is packaged in various his a Android, and when it infects the user's device then it secretly writes it to premium SMS services without requiring any user traffic.

According to BitDefender researchers, the malware uses an intelligent and sophisticated set of procedures that allows it to bypass various mechanisms s that exist in premium sms services to prevent fraud.

First, the malware initiates communication between the device and a C&C server, which is loaded with the URL of a of premium subscription.

Android.Trojan.MKero.A then extracts the image from the registration form and sends it to antigate.com, a Web service that relies on humans to read font one image CAPTCHAs. (Isn't that ironic??!)

After receiving the CAPTCHA solution from antigate.com, the malware subscribes the user to the service, and after receiving, analyzing and exporting the confirmation code from an SMS message, enters the site's code and upgrades its registration user to premium service.

The purpose of Android.Trojan.MKero.A is simple. The attacker is likely to participate in various affiliate programs in relation to the sms services that the user-victim registers, and has monetary gains from each user he brings.

"Taking into account the malicious software has been built to operate completely silently on the Android device of the victim, its detection and removal is extremely difficult," says Liviu Arsene from BitDefender, who recommend the use of an antivirus for mobile phones as well as regular scanning of the devices.

Ο of mobile phone bills at regular intervals is also a good idea, as increased charges that came out of nowhere can be a sign of a malware infection.

BitDefender's staff identified 7 infected game applications in the Google Play Store, which have been removed in the meantime.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).