Google's App Store - Full Of Spyware

A significant number of Android Apps have been discovered to contain a potentially dangerous software development kit that is being used as spyware. The antivirus company Dr. Web has discovered spyware in over 100 Android applications with over 421 million downloads in Google Play.

They found malicious Software Development Kit (SDK) is hiding in more than a hundred Android Apps, many of which were previously available on the Google Play store. The SpinOK module offers mini games, and apparent prizes to gain users’ interest in downloading.

This module scrapes data from files on your device and sends that information back to bad actors, which is the antithesis of the privacy policy you want from the apps on your smartphone. Dr. Web has named it SpinOk which,  when downloaded to a device, can collect information about files, can send files to the attackers, and can steal clipboard content.

SpinOK also bypasses your device’s proxy settings, which enables it to hide its network connections. It can then serve you ads thanks to the connection to its remote server, which kicks off the scraping of your device’s data, including listing the files on your device, the location of a specific file or directory, stealing a specific file, and even copying or replacing the contents of your clipboard.

SDK connects to the command-and-control server and sends a trove of device information, including data from sensors, which allows it to detect emulator environments. The server response contains numerous URLs used to display advertising banners via WebView.

Additionally, the module can collect a list of files in specified directories, check for the presence of specific files and directories, upload files from the device, and copy or substitute clipboard content. “This allows the trojan module’s operators to obtain confidential information and files from a user’s device, for example, files that can be accessed by Apps with Android.Spy.SpinOk built into them... For this, the attackers would need to add the corresponding code into the HTML page of the advertisement banner,” Dr. Web explains.

Google has been notified and has removed some of the apps. In some cases, only certain versions contained the malicious SDK.

So far, the malicious module and various modifications have been identified in a total of 101 applications in Google Play and some of the most popular applications containing the malicious module include Noizz (over 100 million installations), Zapya (over 100 million installations the code was present in versions 6.3.3 to 6.4), VFly (over 50 million downloads), MVBit (more than 50 million installations), and Biugo (over 50 million downloads). Doctor Web has published a list of infected applications.

Protect Your Smartphone From SpinOK

It looks Google has responded to threat and has removed a majority of these Apps from the Play Store, with the notable exception of Zapya, which since the introduction of version 6.4.1 no longer contains the malicious SpinOK module.

However, while users can no longer download the module, that does not help users who have already installed it on their device. That’s why it’s important to look through the official list and see if you have any of those Apps on your device. If so, delete it immediately.

If you have Zapya on your device, update it now. Google removing an app from the Play Store won’t affect any Apps you have on your phone and users are advised to un-install it themselves.

Dr. Web:   GitHub:    Techradar:     LifeHacker:     Security Week:   GHacks:    SCMagazine

You Might Also Read:

Mobile Cyber Attacks: The Different Facets Of Smartphone Malware:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 


 

« Cyber Security & The Financial Services Industry
Year in Review: Biggest Application Security Breaches Of 2022 »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

Perimeter 81 / How to Select the Right ZTNA Solution

Perimeter 81 / How to Select the Right ZTNA Solution

Gartner insights into How to Select the Right ZTNA offering. Download this FREE report for a limited time only.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

Cloud Security Alliance (CSA)

Cloud Security Alliance (CSA)

The CSA is a not-for-profit organization with a mission to promote the use of best practices for providing security assurance within Cloud Computing

Brit

Brit

Brit PLC is a market-leading global specialty insurer and reinsurer, focused on underwriting complex risks including cyber, privacy and technology.

Beachhead Solutions

Beachhead Solutions

Beachhead's SimplySecure is a configurable, web-based management tool allowing you to remotely secure vulnerable mobile devices in your organization.

IntSights

IntSights

IntSights is an intelligence driven security provider offering rapid, accurate cyberthreat intelligence and incident mitigation in real time

Exprivia

Exprivia

Exprivia is active in the design, development and integration of IT systems including cyber security.

Cologix

Cologix

Cologix provides reliable, secure, scalable data center and interconnection solutions from 24 prime interconnection locations across 9 strategic North American edge markets.

Cognni

Cognni

Cognni (formerly Shieldox) will make your InfoSec think like a human, right out of the box, so you can focus on the bigger picture, keeping the information flow safe.

SecurityHQ

SecurityHQ

SecurityHQ (formerly known as Si Consult) is a Global Managed Security Service Provider (MSSP) that monitors networks 24/7, to ensure complete visibility and protection against your cyber threats.

Netsecurity AS

Netsecurity AS

Netsecurity is a Norwegian owned company focused and specialised within IT security and cybersecurity-as-a service.

Cyber Talents

Cyber Talents

CyberTalents is on a mission to close the gap of cyber security professionals shortage across the globe.

WisePlant

WisePlant

WisePlant's portfolio of solutions and services includes process measurement, secure automation, industrial cybersecurity, functional safety and more.

CyberWhite

CyberWhite

CyberWhite is a disruptive provider of cyber security and risk mitigation solutions.

Red River

Red River

Red River is a technology transformation company, bringing 25 years of experience and mission-critical expertise in analytics, cloud, collaboration, mobility, networking and security solutions.

Netizen

Netizen

Netizen is an award-winning company that develops and leverages innovative solutions to enable a more secure cyberspace for clients in government and commercial markets.

Eureka Security

Eureka Security

Eureka help organizations securely use any cloud data storage technology they need without having to compromise on security.

Eleos Labs

Eleos Labs

Eleos Labs' suite of security tools prevent Web3 cyber attacks, reduce economic risks, and protect digital assets.