{"id":199279,"date":"2020-02-08T02:00:31","date_gmt":"2020-02-07T23:00:31","guid":{"rendered":"http:\/\/ww-vb.mine.nu\/w108\/delete-these-nasty-android-apps-that-can-log-in-to-your-google-and-facebook-accounts-right-now-bgr\/"},"modified":"2020-02-08T02:00:31","modified_gmt":"2020-02-07T23:00:31","slug":"delete-these-nasty-android-apps-that-can-log-in-to-your-google-and-facebook-accounts-right-now-bgr","status":"publish","type":"post","link":"https:\/\/hameed.nwar.uk\/sa\/delete-these-nasty-android-apps-that-can-log-in-to-your-google-and-facebook-accounts-right-now-bgr\/","title":{"rendered":"Delete these nasty Android apps that can log in to your Google and Facebook accounts right now \u2013 BGR"},"content":{"rendered":"<p> [ad_1]<br \/>\n<\/p>\n<div>\n<p><span style=\"font-weight:400;\">No sooner did we report on Wednesday the presence of a new batch of scammy Android apps that had to be removed from the Google Play Store (but not before racking up some 382 million downloads), than yet another wave of such apps has emerged to be aware of. And to remove from your phone, if you have any of them.<\/span><\/p>\n<p><span style=\"font-weight:400;\">Two separate teams of researchers uncovered a pair of nasty apps and Android activity, some of which is among the worst we\u2019ve seen. First, a new batch of nine apps (since removed from the Google Play Store after racking up about 470,000 downloads) comes via a report from <\/span><span style=\"font-weight:400;\">Trend Micro<\/span><span style=\"font-weight:400;\"> that pinpoints a number of sinister purposes for this collection of apps that disguise themselves as seemingly anodyne utilities, with names like Rocket Cleaner and LinkWorldVPN. However, the Trend Micro researchers warn that the apps do everything from quietly connect to servers to download up to 3,000 pieces of malware \u2014 and that some can even log in to the unaware users\u2019 Facebook and Google accounts for ad fraud purposes.<\/span><\/p>\n<p>The apps in question include the following:<\/p>\n<ul>\n<li>Shoot Clean\u2013Junk Cleaner, Phone Booster, CPU Cooler<\/li>\n<li>Super Clean Lite \u2014 Booster, Clean &amp; CPU Cooler<\/li>\n<li>Super Clean \u2014 Phone Booster, Junk Cleaner &amp; CPU Cooler<\/li>\n<li>Quick Games \u2014 H5 Game Center<\/li>\n<li>Rocket Cleaner<\/li>\n<li>Rocket Cleaner Lite<\/li>\n<li>Speed Clean \u2014 Phone Booster, Junk Cleaner &amp; App Manager<\/li>\n<li>LinkWorldVPN<\/li>\n<li>H5 gamebox<\/li>\n<\/ul>\n<p><span style=\"font-weight:400;\">The Trend Micro report suggests these apps originated from China, and that once a user installed them they connected to a server to do things like posting fake reviews and logging into the accounts we noted above. Additionally, they could get users to unwittingly disable the Play Protect Android malware scanner, among other nefarious acts.<\/span><\/p>\n<p>The apps have been removed from the Google Play Store, but definitely make sure to delete any of these if you still have them on one of your devices.<\/p>\n<p><span style=\"font-weight:400;\">Researchers from the <\/span><span style=\"font-weight:400;\">Cofense Phishing Defense Center<\/span><span style=\"font-weight:400;\">, meanwhile, have also uncovered a separate but even more sinister effort \u2014 a phishing campaign targeting Android devices with unsigned Android applications allowed on the device. <\/span><span style=\"font-weight:400;\">According to a new report from the center, this is an effort to infect devices with Anubis, \u201ca particularly nasty piece of malware that was originally used for cyber espionage and retooled as a banking trojan.\u00a0<\/span><\/p>\n<p><span style=\"font-weight:400;\">\u201cAnubis can completely hijack an Android mobile device, steal data, record phone calls, and even hold the device to ransom by encrypting the victim\u2019s personal files. With mobile devices increasingly used in the corporate environment, thanks to the popularity of BYOD policies, this malware has the potential to cause serious harm, mostly to consumers, and businesses that allow the installation of unsigned applications.\u201d<\/span><\/p>\n<p><span style=\"font-weight:400;\">This malicious campaign presents users with an email that includes an attachment pretending to be an invoice. When the user opens the attachment, they\u2019re shown a screen asking them to enable \u201cGoogle Play Protect.\u201d After clicking OK, however, that approval instead grants the app a number of secret, very bad approvals \u2014 while also, ironically, actually disabling the real Google Play Protect.<\/span><\/p>\n<p><span style=\"font-weight:400;\">Other capabilities that are thus enabled include the ability to capture screenshots, change administration settings, record audio, steal contact lists and lock the device. As if that wasn\u2019t enough, there\u2019s also a ransomware component to this effort. A Cofense researcher told <em>Ars Technica<\/em> that a ransomware module can be added via this campaign and enabled remotely once an attacker has taken everything they want from the phone and decided to simply encrypt it for ransom.<\/span><\/p>\n<p>Check the Cofense report here for a list of apps this campaign targets (it\u2019s quite a long list). \u201cUsers who have configured their Android mobile device to receive work-related emails and allow installation of unsigned applications face the most risk of compromise,\u201d the report concludes.<\/p>\n<p>\u201cWith the increased use of Android phones in business environments, it is important to defend against these threats by ensuring devices are kept current with the latest updates. Limiting app installations on corporate devices, as well as ensuring that applications are created by trusted developers on official marketplaces, can help in reducing the risk of infection as well.\u201d<\/p>\n<p>\n\t<span class=\"description img-caption\"><span class=\"source\">Image Source: PixieMe\/Shutterstock<\/span><\/span><\/p>\n<div class=\"author-bio\">\n<div class=\"author-bio-image-container with-avatar\">\n\t\t<img decoding=\"async\" src=\"http:\/\/ww-vb.mine.nu\/w108\/wp-content\/uploads\/2020\/02\/1580530133_630_All-four-major-US-wireless-carriers-are-suffering-outages-right.png\" height=\"52px\" width=\"47px\"\/><\/div>\n<p>\n\t\tAndy is a reporter in Memphis who also contributes to outlets like Fast Company and The Guardian. When he\u2019s not writing about technology, he can be found hunched protectively over his burgeoning collection of vinyl, as well as nursing his Whovianism and bingeing on a variety of TV shows you probably don\u2019t like.\t<\/p>\n<\/div><\/div>\n<p><script>\n!function(f,b,e,v,n,t,s)\n{if(f.fbq)return;n=f.fbq=function(){n.callMethod?\nn.callMethod.apply(n,arguments):n.queue.push(arguments)};\nif(!f._fbq)f._fbq=n;n.push=n;n.loaded=!0;n.version='2.0';\nn.queue=[];t=b.createElement(e);t.async=!0;\nt.src=v;s=b.getElementsByTagName(e)[0];\ns.parentNode.insertBefore(t,s)}(window,document,'script',\n'https:\/\/connect.facebook.net\/en_US\/fbevents.js');\nfbq('init', '2048158068807929');\nfbq('track', 'ViewContent');\n<\/script><br \/>\n<br \/>[ad_2]<br \/>\n<br \/><a href=\"https:\/\/bgr.com\/2020\/02\/07\/android-apps-removed-from-google-play-store-470000-downloads\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[ad_1] No sooner did we report on Wednesday the presence of a new batch of scammy Android apps that had to be removed from the Google Play Store (but not before racking up some 382 million downloads), than yet another wave of such apps has emerged to be aware of. And to remove from your &hellip;<\/p>\n","protected":false},"author":1,"featured_media":199280,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[],"class_list":["post-199279","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tie-tech"],"_links":{"self":[{"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/posts\/199279","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/comments?post=199279"}],"version-history":[{"count":0,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/posts\/199279\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/media\/199280"}],"wp:attachment":[{"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/media?parent=199279"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/categories?post=199279"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/tags?post=199279"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}