A handful of malware-filled Android apps has, once again, been removed from the Google Play Store, and they were all taking advantage of the latest trend in malware design: masquerading as innocent clones of useful apps to escape initial detection by Google, and transforming into crappy malware once people started downloading and using them.
The good news? The apps in question didn’t appear to have a ton of downloads. Thousands, at best, rather than millions, so odds are pretty high that you haven’t heard of any of the affected apps. Whoever was responsible for the attack, however, set them all up under different developers, so there’s no commonality there to look for.
Aside from the app names, which we’ll list in a second, the only other unifying characteristics are that the attacker used the same developer email for each—“email@example.com”—and all the apps link to the same privacy page online (“https://gohhas.github.io,” followed by the name of the app).
If you have any of these apps still installed on your Android, it’s time to ditch them:
- Cake VPN
- Pacific VPN
- QR/Barcode Scanner MAX
- Music Player
As for how said malware works, Check Point Research has a great write-up:
Check Point Research (CPR) recently discovered a new Dropper spreading via the official Google Play store, which downloads and installs the AlienBot Banker and MRAT.
This Dropper, dubbed Clast82, utilizes a series of techniques to avoid detection by Google Play Protect detection, completes the evaluation period successfully, and changes the payload dropped from a non-malicious payload to the AlienBot Banker and MRAT.
The AlienBot malware family is a Malware-as-a-Service (MaaS) for Android devices that allows a remote attacker, at a first step, to inject malicious code into legitimate financial applications. The attacker obtains access to victims’ accounts, and eventually completely controls their device. Upon taking control of a device, the attacker has the ability to control certain functions just as if he was holding the device physically, like installing a new application on the device, or even control it with TeamViewer.
Though odds are low, if you installed any of these shady apps on your device, I recommend grabbing Malwarebytes and giving yourself a good (free) scan. While you’re at it, change the password for any financial accounts related to apps you’ve installed on your Android. If Malwarebytes doesn’t find anything on your device, you have two choices: tough it out and hope for the best, or be extra security-minded and factory-reset your device, reinstalling everything from scratch.
I’m not sure which option I’d go with, and I haven’t been able to find much information about AlienBot or MRAT removal. You can consider installing one or two other scanning apps to see if they pick up anything (F-Secure, or even Avast), and if everyone was in agreement that there was nothing wrong, you could let it be—after triple-confirming via the aforementioned “Apps & notifications” screen > Special app access that there weren’t any weirdly named apps enjoying administrative permissions on your device.