McAfee gets serious and alerts Google about 16 applications that, together, accumulate more than 20 million downloads and are distributing malware among their users.
The security company McAfee has alerted about malicious activity in 16 applications that could make Android devices who installed them to see how the battery of the smartphone was drastically reduced while consuming more data than normal. In total they already add more than 20 million downloads.
As for malware, once installed hidden in the app, it downloads an additional code without even realizing it and that encourages you to carry out advertising fraud. In other words, when you had one of the infected applications on your smartphone, they came to you messages via firebase (property of Google) indicating to open web pages in the background and clicking links to increase visits.
Subsequently, the malware imitated the behavior by performing automatic clicks or, in the case of other applications, hidden adware services were running (a form of malware that hides on your device and shows you ads), blasting your battery and data.
“This can cause huge network traffic and consume power without the user being aware of it while generating profit for the threat actor behind this malware”explains McAfee’s SangRyol Ryu.
package name | SHA256 | Yam | downloaded |
com.hantor.CozyCamera | a84d51b9d7ae675c38e260b293498db071b1dfb08400b4f65ae51bcda94b253e | High Speed Camera | 10,000,000+ |
com.james.SmartTaskManager | 00c0164d787db2ad6ff4eeebbc0752fcd773e7bf016ea74886da3eeceaefcf76 | SmartTaskManager | 5,000,000+ |
kr.caramel.flash_plus | b675404c7e835febe7c6c703b238fb23d67e9bd0df1af0d6d2ff5ddf35923fb3 | Flash light+ | 1,000,000+ |
com.smh.memocalendar | 65794d45aa5c486029593a2d12580746582b47f0725f2f002f0f9c4fd1faf92c | 달력메모장 | 1,000,000+ |
com.joysoft.wordBook | 82723816760f762b18179f3c500c70f210bbad712b0a6dfbfba8d0d77753db8d | K-Dictionary | 1,000,000+ |
com.kmshack.BusanBus | b252f742b8b7ba2fa7a7aa78206271747bcf046817a553e82bd999dc580beabb | BusanBus | 1,000,000+ |
com.candlencom.candleprotest | a2447364d1338b73a6272ba8028e2524a8f54897ad5495521e4fab9c0fd4df6d | Flash light+ | 500,000+ |
com.movinapp.quicknote | a3f484c7aad0c49e50f52d24d3456298e01cd51595c693e0545a7c6c42e460a6 | QuickNote | 500,000+ |
com.smartwho.SmartCurrencyConverter | a8a744c6aa9443bd5e00f81a504efad3b76841bbb33c40933c2d72423d5da19c | Currency Converter | 500,000+ |
com.joysoft.barcode | 809752e24aa08f74fce52368c05b082fe2198a291b4c765669b2266105a33c94 | joycode | 100,000+ |
com.joysoft.ezdica | 262ad45c077902d603d88d3f6a44fced9905df501e529adc8f57a1358b454040 | EzDica | 100,000+ |
com.schedulezero.instapp | 1caf0f6ca01dd36ba44c9e53879238cb46ebb525cb91f7e6c34275c4490b86d7 | Instagram Profile Downloader | 100,000+ |
com.meek.tingboard | 78351c605cfd02e1e5066834755d5a57505ce69ca7d5a1995db5f7d5e47c9da1 | ez-notes | 100,000+ |
com.candlencom.flashlite | 4dd39479dd98124fd126d5abac9d0a751bd942b541b4df40cb70088c3f3d49f8 | 손전등 | 1,000+ |
com.doubleline.calcul | 309db11c2977988a1961f8a8dbfc892cf668d7a4c2b52d45d77862adbb1fd3eb | 계산기 | 100+ |
com.dev.imagevault | bf1d8ce2deda2e598ee808ded71c3b804704ab6262ab8e2f2e20e6c89c1b3143 | Flash light+ | 100+ |
As for these 16 applications, which you have above, note that they were related to basic aspects such as the flashlight, the camera, the QR reading and the measurement conversions, something that we all have on our mobiles, although yes, several are of Korean origin. Nevertheless, one of them, located in the top 1 and called High-Speed Camera, has already gathered more than 10 million downloads.
Note that to hide fraudulent behavior, the applications waited about an hour after installation before executing the entire process.
How to know if your smartphone has been hacked
Smartphones, just like laptops and desktops, can be hacked, that much is clear to all of us. However, in the case of smartphones there are some key signs so that you at least suspect that something strange is going on.
1. Yes the performance of your smartphone has been affected recentlyyou can’t load web pages properly or you have to restart your phone to make it work faster, then your device might be hacked
2. If you notice unknown popups (pop-ups) and suspicious while browsing popular websites like Google, Twitter or Facebook, be very careful because it is possible that your phone has been infected with adware.
3. If applications you use daily, such as WhatsApp or Instagram, you see that have started to freeze, become unresponsive, or just shut down without explanationyour device may have run out of memory due to malicious software.
4. On the other hand, suspiciously high data or battery consumption, it means that an infected device is more than likely communicating with a malicious server to download more malware to update itself, or to steal private user data.
Returning to the previous topic, in a statement a Google spokesman pointed out that all apps reported by McAfee had been removed. Of course, it is quite strange that 20 million installations in total have been sneaked into just 16 applications, if users are supposedly protected with Google Play Protect, which blocks these apps on devices Android.
George is Digismak’s reported cum editor with 13 years of experience in Journalism