New Phishing Apps Discovered on Google Play Store

Risk:
high
Damage:
high
Platform(s):
Google
Advisory ID:
ngCERT-2023-0004
Version:
N/A
CVE:
N/A
Published:
January 30, 2023

Summary


Several phishing apps have recently been discovered on the Google Play Store. These apps can be games or investment services; however, they are designed to steal sensitive user information. The apps have been downloaded 450, 000 times in total.

Description & Consequence


While some of the malicious apps have been removed, others are still active on the store. Below are the affected apps:

  1. Golden Hunt
  2. Reflector
  3. Seven Golden Wolf Blackjack
  4. Unlimited Score
  5. Big Decisions
  6. Jewel Sea
  7. Lux Fruits Game
  8. Lucky Clover
  9. King Blitz
  10. Lucky Hammer

 

After installing and opening the app, it will contact a remote server which will reply with instructions on what to do. These instructions typically include phishing pages that will be displayed to unsuspecting users in an attempt to collect their sensitive information.

Phishing can result in data loss and/or other personally identifiable information (PII) being used against the victim. In most cases, the information obtained through phishing is used to compromise a user's online account in order to cause further harm, such as transferring funds from a bank account, using a social media account to commit fraud, and so on.

Solution


If any of the aforementioned apps were installed from the Google Play Store, they should be deleted immediately! Here are some additional precautions to take:

  1. Refrain from downloading shady apps even from official stores like Google Play by performing due diligence on apps one wishes to download.
  2. Use up-to-date anti-virus software to scan your device regularly.
  3. Do not give out sensitive information through untrusted platforms.

Reference


Revision


Related Articles