this post was submitted on 23 Sep 2024
59 points (100.0% liked)

Cybersecurity

5539 readers
111 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected]

Notable mention to [email protected]

founded 1 year ago
MODERATORS
top 4 comments
sorted by: hot top controversial new old
[–] [email protected] 15 points 3 weeks ago (1 children)

Boy, I'm so glad Google doesn't want us sideloading apps, I fee so much safer using play. (Yes, that's sarcasm)

[–] [email protected] 3 points 3 weeks ago

I mean, it was side loaded too. "Spotiplus" was infected with it apparently, but I do agree that Google allows so much malware on the store its crazy!

[–] [email protected] 6 points 3 weeks ago (1 children)

The infected apps are at the end.

The researchers found Necro in two Google Play apps. One was Wuta Camera, an app with 10 million downloads to date. Wuta Camera versions 6.3.2.148 through 6.3.6.148 contained the malicious SDK that infects apps. The app has since been updated to remove the malicious component. A separate app with roughly 1 million downloads—known as Max Browser—was also infected. That app is no longer available in Google Play.

The researchers also found Necro infecting a variety of Android apps available in alternative marketplaces. Those apps typically billed themselves as modified versions of legitimate apps such as Spotify, Minecraft, WhatsApp, Stumble Guys, Car Parking Multiplayer, and Melon Sandbox.

People who are concerned they may be infected by Necro should check their devices for the presence of indicators of compromise listed at the end of this writeup.

[–] [email protected] 1 points 3 weeks ago