// BIG SECURITY NEWS // SimBad: the malware downloaded nearly 150 million times on the Google Play Store

in #news5 years ago

Security researchers have discovered an adware that has contaminated more than 200 popular apps. A real danger for Android users.

Sans titre.png

The info

Security researchers at the mobile division of CheckPoint have found a pernicious malware, a new adware campaign. Called SimBad, it is hidden in 206 applications on the official Android Store and has been downloaded a total of nearly 150 million times.

fd357448fed1b432dcd31504a8.png
CheckPoint - Schematic overview of the SimBad attack.

What does that entail

At the root of this whole business, we find RXDrioder, a crooked development kit provided by an addroider[.]com site - whose domain expired seven months ago. This SDK is supposed to allow the inclusion of a link to online advertising servers, ads that will be displayed in applications. According to CheckPoint, it is quite possible that a trick was found and that a trap was set for the developers to use it.

Thus, 206 applications, including most simulations (hence the name SimBad), were contaminated without the knowledge of their developers.

0183c23d0e05178aec14fda0c215e.png
CheckPoint - Some of the 206 "dirty" apps and their downloads.

And for the users? After being downloaded, the application made contact with a command and control server. Therefore, the next step could take three forms: opening a browser with a phishing site or adware, opening one or more apps in the Play Store or finally downloading an application on the sly.

With this last option, SimBad is no longer a simple Adware which exposes you to advertisements for other services, apps or sites ... but can become a source of significant contamination. It all depends on what the command center tells it to do.

The affected apps have been removed from the Play Store by Google. Like about 700,000 others last year.

Stay Informed, Stay Safe

Source: CheckPoint

DQmdpsoEfLe5nRg4Q1oKWHNjLdMnAucCYfRou1yF5Yiwrzs.png

DQmNuF3L71zzxAyJB7Lk37yBqjBRo2uafTAudFDLzsoRV5L.gif

Coin Marketplace

STEEM 0.29
TRX 0.12
JST 0.033
BTC 63318.34
ETH 3108.17
USDT 1.00
SBD 3.97