Malware for Android makes secret recording in Premium SMS services

Malware (Malware) Android.Trojan.MKero.A does a in the land of Android and this time hackers have found a method to bundle it with legitimate apps so as to bypass Google's Bouncer scanning system.

Android Fake ID Malware

While the Malware was first detected in 2014 and distributed mainly to through the installation of insecure applications, the Bitdefender reports that in many cases the trojan was found to be distributed today via the official Google Play Store.

This time, malware is packaged in various games Android, and when it infects the user's device then it secretly writes it to premium SMS services without requiring any user traffic.

According to BitDefender researchers, malware uses an intelligent and complex set of processes that allows it to bypass the various security mechanisms in premium sms services to prevent fraud.

First, the malware initiates communication between the device and a C&C server, which is loaded with a website's URLof premium subscription.

Android.Trojan.MKero.A then exports the CAPTCHA image from the registration form and sends it to antigate.com, a human-based Web service to read the CAPTCHAs image font. (It's not ironic ??!)

After receiving the CAPTCHA solution from antigate.com, the malware subscribes the user to the service, and after receiving, parsing and of the confirmation code from an SMS message, enters the website code and upgrades the user's registration to a premium service.

The purpose of Android.Trojan.MKero.A is simple. The attacker is likely to participate in various affiliate programs in relation to the sms services that the user-victim registers, and has monetary gains from each user he brings.

"Taking into account the malicious software has been built to operate completely silently on the Android device of the victim, its detection and removal is extremely difficult," says Liviu Arsene from BitDefender, who recommend the use of an antivirus for mobile phones as well as regular scanning of the devices.

Auditing mobile phone bills at regular intervals is also a good idea, as the increased cost that came from nowhere may be a sign of a malware attack.

BitDefender's staff identified 7 infected game applications in the Google Play Store, which have been removed in the meantime.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).