According to a Microsoft Security blog, Android users are being attacked by malicious software that inadvertently acquires premium subscription services that they did not want or sign up for.
In a report by Microsoft researchers Dimitrios Valsamaras and Sang Shin Jung, the couple detailed the ongoing evolution of “toll fraud software” and the ways in which it attacks Android users and their devices. According to the team, toll fraud software falls into the subcategory of billing fraud “in which malicious applications subscribe users to premium services without their knowledge or consent” and “is one of the types of malware ‘Most common Android’.
Toll fraud works through the wireless application protocol (WAP), which allows consumers to subscribe to paid content and add the charge to their phone bill. Because this attack relies on a mobile network to do the dirty business, malicious software can disconnect you from Wi-Fi or use other means to force you into your mobile network. By connecting to the mobile network, the malicious software will begin subscribing to premium services while hiding any unique passwords (OTPs) sent to verify your identity. This is to keep the targets in the dark so that the subscription is not canceled.
Researchers warn that the evolution of toll fraud malware since its telephone access days poses a dangerous threat. Malicious software can cause victims to receive significant cell phone billing charges. In addition, the affected devices also have a higher risk because the malicious software is able to evade detection and can get a large number of installations before a single variant can be removed.
How does this malware end up on my device in the first place?
This type of attack starts when a user downloads any application that the malware is disguised in the Google Play Store. These Trojan apps often appear in popular categories in the app store, such as personalization (wallpaper and lock screen apps), beauty, editor, communication (messaging and chat apps), photography, and tools (such as antivirus apps). cleaner and fake). Researchers say these apps will ask for permissions that don’t make sense for what’s being done (i.e., a camera or wallpaper app that asks for notifications or SMS listening privileges).
The goal of these apps is to get as many people downloading them as possible. Valsamaras and Shin Jung identified some common ways in which attackers will try to keep their app on the Google Play Store:
-
Load clean versions until the application gets a sufficient number of installations.
-
Update the app to dynamically load malicious code.
-
Separate the malicious stream from the loaded application so that it is not detected for as long as possible.
What can I do to protect myself from malware?
Valsamaras and Shin Jung say that possible malware in the Google Play Store has common features that can be searched before downloading an app. As stated above, some applications will request excessive permissions for programs that do not require these privileges. Other features to look for are applications with user interfaces or similar icons, developer profiles that look fake or with poor grammar and if the application has a lot of bad reviews.
If you think you’ve already downloaded a possible malware application, some common signs include a fast battery drain, connectivity issues, constant overheating, or if your device runs much slower than normal.
The couple also warned not to upload any apps that you can’t officially get from the Google Play Store, as this can increase the risk of infection. Their findings showed that toll fraud malware accounted for 34.8% of the “potentially harmful application (PHA)” installed in the Google Play Store in the first quarter of 2022, just behind spyware. .
According to a Google transparency report, it says most of the facilities come from India, Russia, Mexico, Indonesia and Turkey.