Millions of Android owners urged to DELETE two dangerous apps that secretly sign you up to subscriptions to steal cash --[Reported by Umva mag]

ANDROID owners have been urged to delete two apps hosting malware that secretly sign you up to subscriptions, among other tricks. The two apps, which have been downloaded 11million times collectively, are carrying a new strain of Necro malware. GettyBRAZIL – 2021/08/25: In this photo illustration the Android logo seen displayed on a smartphone with a malware alert in the background. (Photo Illustration by Rafael Henrique/SOPA Images/LightRocket via Getty Images)[/caption] The malware installs at least four malicious payloads into infected devices, including: Adware that loads links through invisible WebView windows and can display unwanted adverts on your device. Modules that download and execute arbitrary JavaScript and DEX files. Tools that facilitate subscription fraud, where you are secretly signed up to fake memberships. Mechanisms that use infected devices as proxies to route malicious traffic, which cybercriminals use to hide their tracks. Necro was first discovered by cybersecurity experts as Kaspersky back in 2019. However, the team has since confirmed that Necro has returned to the Google Play store inside two apps, for a fresh wave of attacks on Android phones. The first app is Wuta Camera by little-known developer ‘Benqu’, with over 10million downloads, which masquerades as a photo editing and beautification tool. The second app is Max Browser from a developer called ‘WA message recover-wamr’, which had 1million downloads. How to spot a dodgy app Detecting a malicious app before you hit the 'Download' button is easy when you know the signs. Follow this eight-point checklist when you’re downloading an app you’re unsure about: Check the reviews – be wary of both complaints and uniformly positive reviews by fake accounts. Look out for grammar mistakes – legitimate app developers won’t have typos or errors in their app descriptions. Check the number of downloads – avoid apps with only several thousand downloads, as it could be fake. Research the developer – do they have a good reputation? Or, are totally fake? Check the release date – a recent release date paired with a high number of downloads is usually bad news. Review the permission agreement – this agreement gives permission for the app to take bits of your data, and fake apps often ask for additional data that is not necessary. Check the update frequency – an app that is updated too frequently is usually indicative of security vulnerabilities. Check the icon – look closely, and don’t be deceived by distorted, lower-quality versions the icons from legitimate apps. All of this information will available in both Apple’s App Store and the Google Play Store. Google has been notified of the findings, and has since removed Max Browser from the platform. However, Wuta Camera is still available to download because the malware was removed in a recent update. That being said, any payloads that might have been installed in the older versions of the app may still lurk on Android devices. While Google is generally very good at detecting and removing malicious apps – some do slip through the cracks. If you have downloaded one of these apps, it is advised to delete them immediately. If you suspect your Android device is infected, you can download a trusted antivirus app like Malwarebytes or Bitdefender from the Google Play Store. These apps will scan your phone for any threats, and give you steps on how to block adware. It’s also advised to keep an eye on your bank account for any fraudulent subscriptions and purchases, and report them to your bank. Must-know Android tips to boost your phone Get the most out of your Android smartphone with these little-known hacks: Secret button that boosts your battery and can save money Lazy hack to free up space on your phone Apps to delete for extra storage Simple trick to get from A to B faster on Google Maps Free upgrade protects Android users from scam apps Clever trick lets you respond to calls WITHOUT talking

Sep 24, 2024 - 16:09
Millions of Android owners urged to DELETE two dangerous apps that secretly sign you up to subscriptions to steal cash --[Reported by Umva mag]

ANDROID owners have been urged to delete two apps hosting malware that secretly sign you up to subscriptions, among other tricks.

The two apps, which have been downloaded 11million times collectively, are carrying a new strain of Necro malware.

a phone with the word android on it
Getty
BRAZIL – 2021/08/25: In this photo illustration the Android logo seen displayed on a smartphone with a malware alert in the background. (Photo Illustration by Rafael Henrique/SOPA Images/LightRocket via Getty Images)[/caption]

The malware installs at least four malicious payloads into infected devices, including:

  • Adware that loads links through invisible WebView windows and can display unwanted adverts on your device.
  • Modules that download and execute arbitrary JavaScript and DEX files.
  • Tools that facilitate subscription fraud, where you are secretly signed up to fake memberships.
  • Mechanisms that use infected devices as proxies to route malicious traffic, which cybercriminals use to hide their tracks.

Necro was first discovered by cybersecurity experts as Kaspersky back in 2019.

However, the team has since confirmed that Necro has returned to the Google Play store inside two apps, for a fresh wave of attacks on Android phones.

The first app is Wuta Camera by little-known developer ‘Benqu’, with over 10million downloads, which masquerades as a photo editing and beautification tool.

The second app is Max Browser from a developer called ‘WA message recover-wamr’, which had 1million downloads.

How to spot a dodgy app

Detecting a malicious app before you hit the 'Download' button is easy when you know the signs.

Follow this eight-point checklist when you’re downloading an app you’re unsure about:

  1. Check the reviews – be wary of both complaints and uniformly positive reviews by fake accounts.
  2. Look out for grammar mistakes – legitimate app developers won’t have typos or errors in their app descriptions.
  3. Check the number of downloads – avoid apps with only several thousand downloads, as it could be fake.
  4. Research the developer – do they have a good reputation? Or, are totally fake?
  5. Check the release date – a recent release date paired with a high number of downloads is usually bad news.
  6. Review the permission agreement – this agreement gives permission for the app to take bits of your data, and fake apps often ask for additional data that is not necessary.
  7. Check the update frequency – an app that is updated too frequently is usually indicative of security vulnerabilities.
  8. Check the icon – look closely, and don’t be deceived by distorted, lower-quality versions the icons from legitimate apps.

All of this information will available in both Apple’s App Store and the Google Play Store.

Google has been notified of the findings, and has since removed Max Browser from the platform.

However, Wuta Camera is still available to download because the malware was removed in a recent update.

That being said, any payloads that might have been installed in the older versions of the app may still lurk on Android devices.

While Google is generally very good at detecting and removing malicious apps – some do slip through the cracks.

If you have downloaded one of these apps, it is advised to delete them immediately.

If you suspect your Android device is infected, you can download a trusted antivirus app like Malwarebytes or Bitdefender from the Google Play Store.

These apps will scan your phone for any threats, and give you steps on how to block adware.

It’s also advised to keep an eye on your bank account for any fraudulent subscriptions and purchases, and report them to your bank.

Must-know Android tips to boost your phone

Get the most out of your Android smartphone with these little-known hacks:






The following news has been carefully analyzed, curated, and compiled by Umva Mag from a diverse range of people, sources, and reputable platforms. Our editorial team strives to ensure the accuracy and reliability of the information we provide. By combining insights from multiple perspectives, we aim to offer a well-rounded and comprehensive understanding of the events and stories that shape our world. Umva Mag values transparency, accountability, and journalistic integrity, ensuring that each piece of content is delivered with the utmost professionalism.