Beware! This Android Trojan Purloined Many Dollars from Over 10 Million Users

Android Trojan Purloined
Share It On:

30th September 2021, Kathmandu

An incipiently discovered “truculent” mobile campaign has infected north of 10 million users from over 70 countries via ostensibly innocuous Android apps that subscribe the individuals to premium accommodations costing €36 (~$42) per month without their erudition.

Zimperium zLabs dubbed the malevolent Trojan “GriftHorse.” The remuneratively lucrative scheme is believed to possess been under active development ranging from November 2020, with victims reported across Australia, Brazil, Canada, China, France, Germany, India, Russia, Saudi Arabia, Spain, the U.K., and the U.S.

No fewer than 200 Trojan applications were utilized within the campaign, making it one among the foremost widespread scams to possess been unearthed in 2021. What’s more, the malignant apps catered to a varied set of categories starting from Implements and Regalement to Personalization, Lifestyle, and Dating, efficaciously widening the size of the assailants. One of the apps, Handy Translator Pro, amassed the maximum amount of 500,000 downloads.

“While typical premium accommodation scams maximize phishing techniques, this concrete ecumenical scam has obnubilated behind malevolent Android applications acting as Trojans, sanctioning it to maximize utilizer interactions for incremented spread and infection,” Zimperium researchers Aazim Yashwant and Nipun Gupta verbally expressed during a report shared with The Hacker News.

“These maleficent Android applications appear innocuous when optically canvassing the shop description and requested sanctions, but this erroneous sense of confidence changes when users get charged month over month for the premium accommodation they get subscribed to without their erudition and consent.”
Like other banking trojans, GriftHorse doesn’t exploit imperfections within the Android OS, but rather convivially engineers users into subscribing their phone numbers to premium SMS accommodations upon downloading the apps.

Following a prosperous infection, the victims are bombarded with illusory alerts promising a free “GIFT” that, when clicked; redirect them to a geo-categorical webpage to submit their phone numbers for verification. “But in authenticity, they’re submitting their telephone number to a premium SMS accommodation that might commence charging their telephone bill over €30 per month,” the researchers verbally expressed.

Following responsible disclosure to Google, the apps are purged from the Play Store. But they perpetuate to be available on untrusted third-party app repositories, once more underscoring the perils related to sideloading arbitrary applications and the way they will emerge as an intrusion route for malware.

“Overall, GriftHorse Android Trojan capitalizes on minuscule screens, local trust, and misinformation to chicane users into downloading and installing these Android Trojans, also frustration or curiosity when accepting the fictitiously unauthentic free prize spammed into their notification screens,” Yashwant and Gupta concluded.


Share It On:

Recent Posts

Kumari Bank Promoter Share Sale: Eligibility, Application Process, and Price

Kumari Bank Promoter Share Sale: Eligibility, Application Process, and Price

Share It On:21st November, Kathmandu Kumari Bank Limited has officially declared its intention to sell a substantial number of promoter

Up to NPR 150 Cashback on Nepal Telecom and Ncell Services with Namaste Pay

Up to NPR 150 Cashback on Nepal Telecom and Ncell

Share It On:21st November, Kathmandu Namaste Pay has unveiled an exciting new campaign to reward its users with cashback on

Ncell introduces innovative feature, enabling customers to convert voice to data or data to voice services

Ncell introduces innovative feature, enabling customers to convert voice to

Share It On:21st November, Kathmandu Ncell customers can enjoy an innovative feature that allows them to convert or exchange remaining

Genese Solution’s G-TEC: Empowering Women in Tech and Creating a Diverse Tech Workforce in Nepal

Genese Solution’s G-TEC: Empowering Women in Tech and Creating a

Share It On:21st November 2024, Kathmandu Genese Solution – a value IT consulting company, and Kageshwori Manohara municipality, have joined

Shikhar Insurance: Celebrating 20 Years of Service and Commitment to Nepali Customers

Shikhar Insurance: Celebrating 20 Years of Service and Commitment to

Share It On:21st November 2024, Kathmandu Shikhar Insurance had a grand celebration for their 20th Anniversary. On the occasion of

India’s Generative AI Startups: A Comprehensive Look at 2024’s Key Trends and Investments

India’s Generative AI Startups: A Comprehensive Look at 2024’s Key

Share It On:21st November 2024, Kathmandu As 2024 draws to a close, India’s generative AI ecosystem stands out as a