Over 11 million Android devices were infected by the new variant of the Necro Trojan malware, which was distributed through fake versions of popular apps and games on the Google Play store and unofficial app sources. The malware employed obfuscation and steganography to evade detection, executing malicious actions such as displaying invisible ads, downloading/executing files, and creating unauthorized subscriptions to paid services. The widespread impact of the infection emphasizes the malware's adaptability and potential for financial and reputational damage to affected users.
Source: https://securityaffairs.com/168898/malware/new-necro-trojan-apps-11m-downloads.html
TPRM report: https://scoringcyber.rankiteo.com/company/google-play
"id": "goo000093024",
"linkid": "google-play",
"type": "Cyber Attack",
"date": "9/2024",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization’s existence"
{'affected_entities': [{'customers_affected': '11 million',
'industry': 'Technology',
'location': 'Global',
'name': 'Google',
'type': 'Company'}],
'attack_vector': ['Fake Apps', 'Unofficial App Sources'],
'description': 'Over 11 million Android devices were infected by the new '
'variant of the Necro Trojan malware, which was distributed '
'through fake versions of popular apps and games on the Google '
'Play store and unofficial app sources. The malware employed '
'obfuscation and steganography to evade detection, executing '
'malicious actions such as displaying invisible ads, '
'downloading/executing files, and creating unauthorized '
'subscriptions to paid services. The widespread impact of the '
"infection emphasizes the malware's adaptability and potential "
'for financial and reputational damage to affected users.',
'impact': {'brand_reputation_impact': 'High',
'systems_affected': 'Android Devices'},
'initial_access_broker': {'entry_point': ['Google Play Store',
'Unofficial App Sources']},
'motivation': ['Financial Gain', 'Data Theft'],
'title': 'Necro Trojan Malware Infection',
'type': 'Malware Infection',
'vulnerability_exploited': ['Obfuscation Techniques', 'Steganography']}