'File Manager' And 'Data Recovery' Sound Like Lifesavers When In Fact They're Malicious Android Apps

Android

Generic naming plays its role well this time, and more than a million fell as victims because of that.

Using this approach, in which two Android apps have been named with, the generic term that cannot be trademarked due to how common they are, allowed bad actors to trick people into downloading malicious apps that can significantly ruin their privacy.

Time and time again, malware or malicious apps find their way to Google Play Store

Researchers at Pradeo discovered that two separate apps on Google Play Store with a combined 1.5 million downloads, were found to be lying about the data they collected in the 'Data Safety' section of the store.

After conducting a behavioral analysis, the researchers found that two apps have the ability to collect a vast amount of sensitive data and shipping it to locations in China that were identified as malicious.

[block:block=87]

The apps in question are:

  1. ‘File Recovery and Data Recovery’ (com.spot.music.filedate) with over 1 million installs.
  2. ‘File Manager’ (com.file.box.master.gkd) with over 500,000 installs.

What the developers did here, was disguising the apps as file management apps using generic terms.

This made the apps sound a lot friendlier than they seem.

According to the report from the mobile security company that uncovered this alarming infiltration, these seemingly harmless Android apps use common malicious tactics, and are able to automatically launch when the device reboots without user input.

As malicious as they can be, data that the apps extract and send to China, include victims' contact lists, media compiled in the apps, real-time location, mobile country code, network provider name, network code of victims' SIM provider, operating system version number, device brand and model.

In total, each application performed "more than a hundred transmissions of the collected data, an amount that is so large it is rarely observed."

The researchers even said that the data can lead to vulnerable system exploit like the Pegasus spyware did.

File Recovery and Data Recovery
File Manager

Beyond the data collection, these apps are concerning as they implement some deceptive practices making them more potent.

The apps look legitimate, making people think that they're trustworthy and performant. But in this case, both apps "show a big user population, yet have no reviews."

The apps also require less user interaction, and the apps can do that by the advanced permissions they ask and then use, which include the ability to start by itself during each restart of the infected device.

And making things worse, the apps can prevent uninstallation by hiding their icons from the general view.

The threat actors behind these apps are believed to boost their app download numbers with install farms to make the apps seem more legitimate.

As malware is oft found on the Google Play Store, the researchers at Pradeo have a few recommendations to stay safe.

This includes not downloading apps with few reviews and many users, carefully reading the permissions before accepting them, and reading reviews to see if there is anything of concern.

Published