Category: Google|Apr 2, 2020 | Author: Admin

Tekya Malware Targets 1 Million Android Users Through Malicious Apps On Play Store

Share on

While Google employs some tough policies for app developers to keep the Play Store safe, yet it never remains so. Once again, criminal hackers managed to ditch Google’s policies and flood the Play Store with malicious Android apps.

This time, they target users with Tekya malware distributed via numerous apps with almost 1 million downloads.

Tekya Malware In Malicious Android Apps Researchers from Check Point Research has found further Android malware targeting users via Google Play Store. They found multiple Android apps that looked safe but actually contained Tekya malware. Elaborating on their findings in a post, researchers stated that they observed around 56 apps on Play Store exhibiting malicious behavior.

Of these, 24 specifically aimed at children as they impersonated various kids’ apps, such as games and puzzles. Whereas the remaining impersonated utility apps such as calculators, translators, cooking apps, etc. Upon downloading the app, the malware installs and executes on the target device. While the technical details of Tekya are available in the researchers’ post, in brief, it primarily serves ad fraud purposes.

With the goal of committing mobile ad fraud, the malware – dubbed ‘Tekya’ – imitates the user’s actions in order to click ads and banners from agencies like Google’s AdMob, AppLovin’, Facebook, and Unity.

To evade detection by Google Play Protect, the malware obfuscates the native code. It then leverages ‘MotionEvent’ feature on Android phones to imitate the victim’s actions for generating clicks. Together, these malicious Android apps had a total number of downloads of about 1 million. In other words, these apps potentially risked the security of around 1 million users. Apps Removed, But Threat Remains Check Point researchers have confirmed that Google has removed all the malicious apps detected in their study. The developers also removed a couple of those apps from the Play Store. So, at present, users are safe from Tekya malware. Nonetheless, this doesn’t mean that the threat is over. At any point, cybercriminals may flood Play Store with malicious apps to spread other malware, especially the unknown ones, just like Tekya that remained undetected by VirusTotal and Play Protect. As stated by the researchers,

There are nearly 3 million apps available from the store, with hundreds of new apps being uploaded daily – making it difficult to check that every single app is safe.  Thus, users cannot rely on Google Play’s security measures alone to ensure their devices are protected.

Let us know your thoughts in the comments.

Sponsored Ads:

Comments:


Admits lying

Category: General|Feb 2, 2023 | Author: Admin

This is what Netflix says about account sharing in Norway

Category: General|Feb 1, 2023 | Author: Admin

Fear of SSD health Trond Bee·30 January 2023 at 16:43

Category: General|Jan 31, 2023 | Author: Admin

The new Apple chips are coming this year and they will break records

Category: Apple|Jan 30, 2023 | Author: Admin

The iPhone 15 doesn't get this either

Category: Apple|Jan 29, 2023 | Author: Admin

After 26 years you can download

Category: General|Jan 28, 2023 | Author: Admin

Mac mini M2 256GB up to 50 percent slower

Category: Apple|Jan 27, 2023 | Author: Admin

Now HomePod can sense

Category: Apple|Jan 26, 2023 | Author: Admin

NASA and DARPA will test nuclear thermal engines for crewed missions to Mars

Category: General|Jan 25, 2023 | Author: Admin

Get ready to retire 30-year-old Windows technology

Category: Microsoft|Jan 24, 2023 | Author: Admin

“iPhone 15 looks like Android”

Category: Apple|Jan 23, 2023 | Author: Admin

Samsung has heard everyone's prayers

Category: General|Jan 22, 2023 | Author: Admin

This took them five years

Category: Microsoft|Jan 21, 2023 | Author: Admin

Apple activated the secret switch

Category: Apple|Jan 20, 2023 | Author: Admin

Microsoft fires 10,000

Category: Microsoft|Jan 19, 2023 | Author: Admin
more