August 28, 2019 By David Bisson 2 min read

A PDF creator app potentially served a Trojan to more than 100 million Android users via downloads on the Google Play store.

In summer 2019, the CamScanner – Phone PDF Creator app caught the attention of Kaspersky Lab. The program had generated more than 100 million downloads through the Google Play store, but in July and August, it began to receive negative user reviews suggesting the presence of unwanted features.

Upon a closer look, security researchers discovered that the app used an advertising library that contained a malicious dropper at the time of analysis. This dropper, detected by Kaspersky as Trojan-Dropper.AndroidOS.Necro.n, decrypted and executed malicious code contained within the mutter.zip file in the app’s resources. The dropper then decrypted a configuration file, revealing several locations from which it could download and then execute an additional module as its malicious payload.

After Kaspersky reported its findings to Google, the app was promptly removed from the app marketplace.

Malware Hiding on the Google Play Store

Trojan-Dropper.AndroidOS.Necro.n isn’t the only malware family that’s been found on the Google Play store. In April 2019, for instance, Check Point detected a clicker malware family, dubbed PreAMo, that generated more than 90 million downloads across six apps available on the Play store.

That was just two months before ESET discovered several apps available for download on Google’s official app marketplace that were capable of stealing one-time passwords in SMS-based two-factor authentication (2FA) messages without achieving the proper permissions. And in August 2019, Trend Micro detected adware hidden within 85 photography and gaming apps that had registered a combined total of 8 million downloads on the Google Play store.

How to Defend Against Mobile App Threats

Security professionals can help defend their organizations against threats like Necro.n by following mobile security best practices, which include keeping devices up to date with the latest software patches and restricting app downloads to only trusted developers on official app marketplaces. Companies should also use a unified endpoint management (UEM) tool to monitor all devices for suspicious activity and automatically remediate suspicious behavior.

More from

Cybersecurity dominates concerns among the C-suite, small businesses and the nation

4 min read - Once relegated to the fringes of business operations, cybersecurity has evolved into a front-and-center concern for organizations worldwide. What was once considered a technical issue managed by IT departments has become a boardroom topic of utmost importance. With the rise of sophisticated cyberattacks, the growing use of generative AI by threat actors and massive data breach costs, it is no longer a question of whether cybersecurity matters but how deeply it affects every facet of modern operations.The 2024 Allianz Risk…

Autonomous security for cloud in AWS: Harnessing the power of AI for a secure future

3 min read - As the digital world evolves, businesses increasingly rely on cloud solutions to store data, run operations and manage applications. However, with this growth comes the challenge of ensuring that cloud environments remain secure and compliant with ever-changing regulations. This is where the idea of autonomous security for cloud (ASC) comes into play.Security and compliance aren't just technical buzzwords; they are crucial for businesses of all sizes. With data breaches and cyber threats on the rise, having systems that ensure your…

Adversarial advantage: Using nation-state threat analysis to strengthen U.S. cybersecurity

4 min read - Nation-state adversaries are changing their approach, pivoting from data destruction to prioritizing stealth and espionage. According to the Microsoft 2023 Digital Defense Report, "nation-state attackers are increasing their investments and launching more sophisticated cyberattacks to evade detection and achieve strategic priorities."These actors pose a critical threat to United States infrastructure and protected data, and compromising either resource could put citizens at risk.Thankfully, there's an upside to these malicious efforts: information. By analyzing nation-state tactics, government agencies and private enterprises are…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today