• About
  • Advertise
  • Careers
  • Contact
Saturday, March 25, 2023
No Result
View All Result
NEWSLETTER
Cyber360 News
  • Home
  • Security
  • Data Breach
  • Cyber Attacks
  • Cyber Security
  • Cyber Crime
  • Contact Us
  • Home
  • Security
  • Data Breach
  • Cyber Attacks
  • Cyber Security
  • Cyber Crime
  • Contact Us
No Result
View All Result
Cyber360 News
No Result
View All Result
Home Security

Google’s War On Joker: 1,700 Android Apps Removed From Play Store

by Cyber360 News
January 10, 2020
in Security
0
Google’s War On Joker: 1,700 Android Apps Removed From Play Store
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

Google has removed over 1,700 malicious apps from Play Store that were infected with the Joker malware since the company started tracking it in 2017.

These also include 24 Android apps, discovered by CSIS Security Group security researchers back in September, which had about 500,000 downloads in total.

In a blog post, Google described the Joker malware (also known as Bread) as a “well organized, persistent attacker” that had been using different techniques for billing fraud.

The company’s security team found Bread developers’ approach to be “sheer volume.” At times, they had three or four variants on the Play Store targeting multiple carriers

“At peak times of activity, we have seen up to 23 different apps from this family submitted to Play in one day,” writes Google.

Joker: The Billing Fraud Family

The malware-infected apps were first engaged in SMS fraud, where they would target networks that allowed payments via SMS.

However, the malware family moved away from the technique after Google restricted the “use of the SEND_SMS permission and increased coverage by Google Play Protect.”

Currently, the primary technique used by the perpetrators is “Toll fraud,” which involves paying by visiting the carrier page and entering the phone number. Here, users are tricked into subscribing to different types of content via their mobile phone bill.

Crooks take advantage of automated billing systems that provide “device verification, but not user verification.”

“The carrier can determine that the request originates from the user’s device, but does not require any interaction from the user that cannot be automated.”

Since there is no interaction on behalf of the user, the malware authors use injected clicks, custom HTML parsers, and SMS receivers to automate the billing process.

Users who downloaded apps infected with Joker malware also found problems within the apps. In many instances, the app features would not match the app they installed.

The Joker creators were quickly adapting to the change in the Google Play Store. Thankfully, the company was able to remove the 1.7k Android apps before they could pose any real threat to users.

Cyber360 News

Cyber360 News

Next Post
It is no surprise that hackers use songs as bait to spread malware, but their song choice is debatable. 

It is no surprise that hackers use songs as bait to spread malware, but their song choice is debatable. 

Recent Posts

Twitch’s Entire Critical Data Leaked, Includes Streamer Earnings, Source Code

Twitch’s Entire Critical Data Leaked, Includes Streamer Earnings, Source Code

October 6, 2021
Former U.S. Security Firm Helped The UAE Carry Out “Karma” iMessage Hack: MIT Tech Review

Former U.S. Security Firm Helped The UAE Carry Out “Karma” iMessage Hack: MIT Tech Review

October 1, 2021
Facing “This App Has Been Blocked For Your Protection” Issue? Here’s How You Can Fix It

Facing “This App Has Been Blocked For Your Protection” Issue? Here’s How You Can Fix It

October 1, 2021

Whats New in Kali Linux?

September 14, 2021

Kali Linux 2019.3 Release (CloudFlare, Kali-status, metapackages, Helper-Scripts & LXD)

September 14, 2021

Kali Linux 2021.3 Release (OpenSSL, Kali-Tools, Kali Live VM Support, Kali NetHunter Smartwatch)

September 14, 2021

Kali Linux 2018.4 Release

September 14, 2021

Kali Linux 1.0.5 and Software Defined Radio

September 14, 2021

Kali Tools Website Launched, 1.0.9 Release

September 14, 2021

Kali Linux Dojo at Black Hat Vegas 2016

September 14, 2021

Category

Site Links

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

About Us

We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc. Check our landing page for details.

© 2019 Cyber360 News - Powered by WebSensePro

No Result
View All Result
  • Home
  • Security
  • Data Breach
  • Cyber Attacks
  • Cyber Security
  • Cyber Crime
  • Contact Us

© 2019 Cyber360 News - Powered by WebSensePro

Login to your account below

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In