Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Malware & Threats

Android Apps Fool Hundreds of Thousands With Empty Promises

Nearly one million Android users have fallen victims to eight fake applications that falsely claimed to help them gain more followers on social networks, but instead stole their information and money.

Nearly one million Android users have fallen victims to eight fake applications that falsely claimed to help them gain more followers on social networks, but instead stole their information and money.

Detected as Android/Fasurke, these applications made it to the Google Play about four months ago, which gave them enough time to gather between 250,000 and 1,000,000 downloads, researchers at ESET discovered. These pieces of software attracted users with empty promises, with interesting app names, and with bogus descriptions.

These fake applications promised to boost user’s followers on different social networks, but did nothing of the sorts, researchers warn. Instead of offering more followers, friends or views on social networks, these apps lured users into sharing their personal information, paying perpetual subscriptions, or consenting to receiving marketing messages or ads.

When running the application, users were requested to enter their mobile device model, username and the number of followers they wished to gain, promising thousands of new followers with just one click. However, after supposedly launching the “followers generating process,” users were presented with a “human verification” step.

This step was meant to trick the user into entering an endless set of offerings of gifts, coupons and free services, and into sharing their personal information (name, email, address, telephone, date of birth, and gender). Moreover, users were asked to consent to receiving telesales calls and text messages, some of which cost around $5.50 per week.

According to ESET researchers, this “verification step” is actually an endless spiral, its only purpose being that of milking as much information and money as possible from the unsuspecting user. Although many individuals who downloaded these apps decided to share their negative experience via comments and low rating on Google Play, thousands of other people still downloaded them.

Google was informed on these applications and has already removed them from the marketplace, but ESET researchers say that similar threats might still exist, including users naïve enough to install them and share their personal information.

To stay protected, users are advised to download applications only from official storefronts, as they contain the smallest number of malicious applications. Before downloading an app, however, users should also have a look at its rating, should analyze the permissions it requests, and should think twice before installing a program that promises something “too good to be true.”

Advertisement. Scroll to continue reading.

A golden rule that users should always apply is to never share their personal information with a third party, unless they are sure it is trustworthy. Moreover, users should not consent to something and should not be ordering goods or services unless they are sure about what they will receive in exchange.

Related: Android Trojan Posing as Flash Player Targets Banking Apps

Written By

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

Professional services company Slalom has appointed Christopher Burger as its first CISO.

More People On The Move

Expert Insights

Related Content

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Cybercrime

The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions.

Malware & Threats

The NSA and FBI warn that a Chinese state-sponsored APT called BlackTech is hacking into network edge devices and using firmware implants to silently...

Cyberwarfare

An engineer recruited by intelligence services reportedly used a water pump to deliver Stuxnet, which reportedly cost $1-2 billion to develop.

Application Security

Virtualization technology giant VMware on Tuesday shipped urgent updates to fix a trio of security problems in multiple software products, including a virtual machine...

Malware & Threats

Apple’s cat-and-mouse struggles with zero-day exploits on its flagship iOS platform is showing no signs of slowing down.

Mobile & Wireless

Samsung smartphone users warned about CVE-2023-21492, an ASLR bypass vulnerability exploited in the wild, likely by a spyware vendor.

Malware & Threats

Unpatched and unprotected VMware ESXi servers worldwide have been targeted in a ransomware attack exploiting a vulnerability patched in 2021.