Malicious Play Store Apps Were Stealing Banking Credentials

Malicious Apps Play Store Featured

The effort to keep our devices free of malware, viruses, and threats is an endless battle and definitely seems winless – at least for the good guys. Malicious apps were found on the Google Play Store … again … and this time they were stealing banking credentials. While it’s great the threats have been removed, we know it’s just a matter of time before more land there.

Discovery of Malicious Apps on Google Play Store

Do you feel like you’re experiencing a bit of deja vu? At this point, it’s comparable to learning there’s another COVID variant lurking around.

Mobile security company ThreatFabric announced in a blog post that a group of apps had been found residing in the Play Store and that they’ve been stealing banking credentials. These masked trojans were downloaded more than 300,000 times before they were found.

Malicious Apps Play Store Android Dark

The apps stole user passwords and two-factor authentication codes, logged keystrokes, and took screenshots while masquerading as QR scanners, PDF scanners, and cryptocurrency wallets. They belonged to four separate Android malware families.

While Google has put security efforts up to prevent malicious apps from being uploaded, the malware developers were able to sneak in.

“What makes these Google Play distribution campaigns very difficult to detect from an automation (sandbox) and machine learning perspective is that developer apps all have a very small malicious footprint,” explained the blog post. “This small footprint is a (direct) consequence of the permission restrictions enforced by Google Play.

The malware developers were able to get around the Google rules by offering apps that didn’t include a threat initially. After the apps were downloaded, users were asked to download updates with updated features from third-party sources. This provided the avenue for the malware to get through.

Malicious Apps Play Store Cyberattack

There were other methods used as well to limit suspicion around the apps. “This incredible attention dedicated to evading unwanted attention renders automated malware detection less reliable,” stated the ThreatFabric blog post. “This consideration is confirmed by the very low overall VirusTotal score of the number of droppers we have investigated in this blog post.”

The Anatsa malware family was behind more malicious apps than the three others. It had remote access and automatic transfer systems that would steal from unsuspecting users’ bank accounts.

Limiting the Effect of Malicious Apps

The other malware families were Alien, Hydra, and Ermac. The malicious apps they offered on the Play Store included:

  • Two Factor Authenticator
  • Protection Guard
  • QR CreatorScanner
  • Master Scanner Live
  • QR Scanner 2021
  • QR Scanner
  • PDF Document Scanner – Scanner to PDF
  • PDF Document Scanner
  • PDF Document Scanner Free
  • CryptoTracker
  • Gym and Fitness Trainer.

Make sure you don’t have any of them on your Android devices.

Malicious Apps Play Store Google

While Google is always quick to pull these apps down, malicious apps on the Play Store is a nagging problem, whether they’re stealing banking information or performing other malicious duties.

But as these most recent malicious apps showed, it can be difficult to identify the apps as malicious. For sure, it’s good practice to avoid apps with bad reviews and a small presence. Also, if you have older, unused apps on your phone, uninstalling them is best.

Read on to learn about malware that was disguised as COVID messages and our review of Emsisoft Anti-Malware.

Subscribe to our newsletter!

Our latest tutorials delivered straight to your inbox

Laura Tucker Avatar

Read next

When the SS Great Eastern laid the first working transatlantic telegraph cable in 1866, a message that had taken ten days by steamship suddenly crossed the ocean in minutes, and the financial markets of London and New York were forced, within a single trading week, to invent the modern concept of synchronised global price.
The Big Ear telescope was scanning at 1420.4056 megahertz on the night of 15 August 1977, the exact frequency at which hydrogen atoms vibrate across the universe, because Giuseppe Cocconi and Philip Morrison had argued years earlier that any species trying to be found would broadcast on that channel — and then, for 72 seconds, something did.
In 2016, archaeologists dated two rings of snapped stalagmites in France’s Bruniquel Cave to 176,500 years ago, evidence that Neanderthals had walked 336 metres into darkness with fire and built architecture deep underground long before modern humans reached Europe
Otto von Bismarck was 74 when Germany adopted the world’s first national old-age social insurance program in 1889, setting the pension age at 70 after years of fighting socialists with bans, laws, and a promise few workers would live long enough to use
When cosmonaut Valeri Polyakov stepped out of his Soyuz capsule in March 1995 after 437 consecutive days aboard Mir, doctors recorded him at several centimetres above his pre-flight height, and his spine had become so unaccustomed to gravity that the recovery team carried him to a chair rather than risk the compression of letting him walk.
When Bell Labs engineer Karl Jansky pointed a rotating antenna at the sky in 1932 looking for sources of transatlantic radio static, he kept picking up a faint hiss that peaked every 23 hours and 56 minutes, and he eventually realized he had become the first human to hear the center of the Milky Way.
When Harvard astronomer Cecilia Payne submitted her 1925 doctoral thesis arguing that the Sun was made almost entirely of hydrogen, the field’s senior figure Henry Norris Russell talked her into adding a line calling the result ‘almost certainly not real,’ and then published the same conclusion himself four years later to widespread acclaim.
When seismic waves from the Chicxulub impact reached what is now North Dakota roughly ten minutes after the asteroid struck, they appear to have triggered a ten-metre standing wave in an inland river that flung fish onto the bank and buried them under glass beads still falling from the sky.