Cybersecurity researchers have discovered yet another piece of wormable Android malware—but this time downloadable directly from the official Google Play Store—that’s capable of propagating via WhatsApp messages.
Disguised as a rogue Netflix app under the name of “FlixOnline,” the malware comes with features that allow it to automatically reply to a victim’s incoming WhatsApp messages with a payload received from a command-and-control (C&C) server.
“The application is actually designed to monitor the user’s WhatsApp notifications, and to send automatic replies to the user’s incoming messages using content that it receives from a remote C&C server,” Check Point researchers said in an analysis published today.
Besides masquerading as a Netflix app, the malicious “FlixOnline” app also requests intrusive permissions that allow it to create fake Login screens for other apps, with the goal of stealing credentials and gain access to all notifications received on the device, using it to hide WhatsApp notifications from the user and automatically reply with a specially-crafted payload received from the C&C server.
“The malware’s technique is fairly new and innovative,” said Aviran Hazum, manager of mobile intelligence at Check Point. “The technique here is to hijack the connection to WhatsApp by capturing notifications, along with the ability to take predefined actions, like ‘dismiss’ or ‘reply’ via the Notification Manager.”
A successful infection could allow the malware to spread further via malicious links, steal data from users’ WhatsApp accounts, propagate malicious messages to users’ WhatsApp contacts and groups, and even extort users by threatening to leak sensitive WhatsApp data or conversations.
The app has since been purged from the Play Store, but not before attracting a total of 500 downloads over the course of two months.
FlixOnline also marks the second time a malicious app has been caught using WhatsApp to spread the malware. In January 2021, ESET researcher Lukas Stefanko disclosed a fake Huawei Mobile app that employed the same modus operandi to perform the wormable attack.
What’s more, the message displayed to users upon opening the apps is the same — “We need your permission to access the application. It will help app (sic) to provide better functionality” — suggesting the two apps could either be the work of the same attacker or that the authors of FlixOnline drew inspiration from the Huawei Mobile app.
“The fact that the malware was able to be disguised so easily and ultimately bypass Play Store’s protections raises some serious red flags,” Hazum said. “Although we stopped one campaign of the malware, the malware family is likely here to stay. The malware may return hidden in a different app.”
“Users should be wary of download links or attachments that they receive via WhatsApp or other messaging apps, even when they appear to come from trusted contacts or messaging groups,” Hazum added.
//l&&!o&&(jQuery.ajax({url:”https://thehackernews.com/feeds/posts/default?alt=json-in-script&max-results=4″,type:”get”,cache:!1,dataType:”jsonp”,success:function(e){for(var t=””,r=””,s=0;s<e.feed.entry.length;s++){for(var a=0;a<e.feed.entry[s].link.length;a++)if("alternate"==e.feed.entry[s].link[a].rel){t=e.feed.entry[s].link[a].href;break}if("content"in e.feed.entry[s])var n=e.feed.entry[s].content.$t;else n="summary"in e.feed.entry[s]?e.feed.entry[s].summary.$t:"";100<(n=n.replace(/]*>/g,””)).length&&(n=n.substring(0,90));var l=e.feed.entry[s].title.$t;l=l.substring(0,50);var o=e.feed.entry[s].media$thumbnail.url.replace(//s72-c-e100/,”/s260-e100″);o=o.replace(/http://1.bp.blogspot.com/|http://2.bp.blogspot.com/|http://3.bp.blogspot.com/|http://4.bp.blogspot.com/|https://1.bp.blogspot.com/|https://2.bp.blogspot.com/|https://3.bp.blogspot.com/|https://4.bp.blogspot.com//,”https://thehackernews.com/images/”),r+=’
“}r+=””,document.getElementById(“result”).innerHTML=r}}),e=window,t=document,r=”script”,s=”stackSonar”,e.StackSonarObject=s,e[s]=e[s]||function(){(e[s].q=e[s].q||[]).push(arguments)},e[s].l=1*new Date,a=t.createElement(r),n=t.getElementsByTagName(r)[0],a.async=1,a.src=”https://www.stack-sonar.c/ping.js”,n.parentNode.insertBefore(a,n),stackSonar(“stack-connect”,”233″),o=!0)})});
//]]>
https://platform.twitter.com/widgets.js
NordVPN’s birthday is here with 3-years of VPN + up to 3-years more at $125.50
Wells Fargo patent troll case has finance world all aquiver so Barclays, TD Bank sign up to Open Invention Network
‘O.J. Made in America’ Is a Masterful Feat of Editing
US Arrests Suspect Who Wanted To Blow Up AWS Data Center
Shopee Indonesia denies claims of underpaid in-house couriers going on strike
BRATA Malware Poses as Android Security Scanners on Google Play Store
Japan To Start Releasing Fukushima Water Into Sea In 2 Years
NHS COVID-19 app update blocked by Apple, Google over location privacy fears