Android Malware Found Embedded In APKPure Store Application

Android Malware Found Embedded In APKPure Store Application

Security researchers found malware embedded within the official application of APKPure, a popular third-party Android app store and an alternative to Google’s official Play Store.

Android users use the application to install apps and games hosted on APKPure’s platform, supposedly identical to those available through the Play Store.

The malware was discovered by Kaspersky and Dr.Web malware analysts embedded within an advertisement SDK included with APKPure version 3.7.18.

As they discovered, it looks like a variant of the Triada trojan first spotted by Kaspersky in 2016 [12], capable of spamming users of infected devices with ads and deliver additional malware.

Also Read: PDPA Singapore Guidelines: 16 Key Concepts For Your Business

APKPure interface

“The identified malicious code embedded in APKPure operates in the following way: upon launch of the application, the payload is decrypted and launched,” Kaspersky said. “It then collects information about the user device and sends it to the C&C server.”

“Then, a Trojan is loaded that has much in common with the notorious Triada malware, in that it can perform a range of actions – from displaying and clicking ads to signing up for paid subscriptions and downloading other malware.”

Next, depending on its operators’ instructions and monetizing scheme (ads or pay-per-install), it will:

  • show ads every time the Android device is unlocked,
  • repeatedly open web pages containing ads,
  • click the ads to sign up for paid subscriptions,
  • install other payloads or potentially malicious software without the users’ consent.

The damage inflicted by this trojan varies depending on the Android version running on the compromised devices, ranging from being signed up for paid subscriptions and seeing intrusive ads on current versions to having unremovable malware like xHelper deployed on the system partition.

Device information collected by the malware (Kaspersky)

While no official download stats are available for the APKPure app, Kaspersky says that it has so far blocked the malware on the devices of 9,380 Android users running its security solutions on their devices.

Both Kaspersky and Dr.Web reported their findings to APKPure’s developers, who have released APKPure 3.17.19 today without the malicious code.

Indicators of compromise, including APKpure app, payload, and malware sample hashes, are available at the end of Kaspersky’s report.

Also Read: Data Protection Officer Singapore | 10 FAQs

BleepingComputer has reached out to APKPure’s development team for more information but has not heard back.

Privacy Ninja

Recent Posts

Enhancing Website Security: The Importance of Efficient Access Controls

Importance of Efficient Access Controls that every Organisation in Singapore should take note of. Enhancing…

2 weeks ago

Prioritizing Security Measures When Launching Webpage

Prioritizing Security Measures When Launching a Webpage That Every Organisation in Singapore should take note…

2 weeks ago

The Importance of Regularly Changing Passwords for Enhanced Online Security

Importance of Regularly Changing Passwords for Enhance Online Security that every Organisation in Singapore should…

3 weeks ago

Mitigating Human Errors in Organizations: A Comprehensive Approach to Data Protection and Operational Integrity

Comprehensive Approach to Data Protection and Operational Integrity that every Organsiation in Singapore should know…

3 weeks ago

The Importance of Pre-Launch Testing in IT Systems Implementation

Here's the importance of Pre-Launch Testing in IT Systems Implementation for Organisations in Singapore. The…

4 weeks ago

Understanding Liability in IT Vendor Relationships

Understanding Liability in IT Vendor Relationships that every Organisation in Singapore should look at. Understanding…

1 month ago