August 28, 2019 By David Bisson 2 min read

A PDF creator app potentially served a Trojan to more than 100 million Android users via downloads on the Google Play store.

In summer 2019, the CamScanner – Phone PDF Creator app caught the attention of Kaspersky Lab. The program had generated more than 100 million downloads through the Google Play store, but in July and August, it began to receive negative user reviews suggesting the presence of unwanted features.

Upon a closer look, security researchers discovered that the app used an advertising library that contained a malicious dropper at the time of analysis. This dropper, detected by Kaspersky as Trojan-Dropper.AndroidOS.Necro.n, decrypted and executed malicious code contained within the mutter.zip file in the app’s resources. The dropper then decrypted a configuration file, revealing several locations from which it could download and then execute an additional module as its malicious payload.

After Kaspersky reported its findings to Google, the app was promptly removed from the app marketplace.

Malware Hiding on the Google Play Store

Trojan-Dropper.AndroidOS.Necro.n isn’t the only malware family that’s been found on the Google Play store. In April 2019, for instance, Check Point detected a clicker malware family, dubbed PreAMo, that generated more than 90 million downloads across six apps available on the Play store.

That was just two months before ESET discovered several apps available for download on Google’s official app marketplace that were capable of stealing one-time passwords in SMS-based two-factor authentication (2FA) messages without achieving the proper permissions. And in August 2019, Trend Micro detected adware hidden within 85 photography and gaming apps that had registered a combined total of 8 million downloads on the Google Play store.

How to Defend Against Mobile App Threats

Security professionals can help defend their organizations against threats like Necro.n by following mobile security best practices, which include keeping devices up to date with the latest software patches and restricting app downloads to only trusted developers on official app marketplaces. Companies should also use a unified endpoint management (UEM) tool to monitor all devices for suspicious activity and automatically remediate suspicious behavior.

More from

SoaPy: Stealthy enumeration of Active Directory environments through ADWS

10 min read - Introduction Over time, both targeted and large-scale enumeration of Active Directory (AD) environments have become increasingly detected due to modern defensive solutions. During our internship at X-Force Red this past summer, we noticed FalconForce’s SOAPHound was becoming popular for enumerating Active Directory environments. This tool brought a new perspective to Active Directory enumeration by performing collection via Active Directory Web Services (ADWS) instead of directly through Lightweight Directory Access Protocol (LDAP) as other AD enumeration tools had in the past.…

Smoltalk: RCE in open source agents

26 min read - Big shoutout to Hugging Face and the smolagents team for their cooperation and quick turnaround for a fix! Introduction Recently, I have been working on a side project to automate some pentest reconnaissance with AI agents. Just after I started this project, Hugging Face announced the release of smolagents, a lightweight framework for building AI agents that implements the methodology described in the ReAct paper, emphasizing reasoning through iterative decision-making. Interestingly, smolagents enables agents to reason and act by generating…

4 ways to bring cybersecurity into your community

4 min read - It’s easy to focus on technology when talking about cybersecurity. However, the best prevention measures rely on the education of those who use technology. Organizations training their employees is the first step. But the industry needs to expand the concept of a culture of cybersecurity and take it from where it currently stands as an organizational responsibility to a global perspective.When every person who uses technology — for work, personal use and school — views cybersecurity as their responsibility, it…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today