Google Play Hit by More Ztorg-Based Android Malware, Says Kaspersky Labs

Advertisement
By Shubham Verma | Updated: 22 June 2017 18:24 IST
Highlights
  • Google has removed Magic Browser and Noise Detector apps
  • These apps belonged to the Ztorg Trojan family of Android malwares
  • Kaspersky researcher spotted these apps and their attack course

In a bid to increase security on its Android platform, Google has reportedly removed more Android apps from its Google Play store for the second time this month. Google has taken strict action against two malicious apps - Magic Browser and Noise Detector - acting as conduits for attackers to remotely 'root' control the infected devices after a researcher from Kaspersky Lab pointed out the threat in his report. The Android malware carried by these apps belongs to the Ztorg Trojan family, which is notoriously known for bypassing Google's safety controls to root infected Android devices.

In a report published on Kaspersky Lab's Securelist website, senior researcher Roman Unuchek presents extensive analysis on the new Ztorg-based malware. Kaspersky Lab says Ztorg malware bypassed Google's malware checks almost 100 times since September last year, and the malware family is best known for gaining 'root' privileges of infected devices to completely control them. Ztorg apps like Privacy Lock and a false Pokemon Go guide raked in huge download numbers before they were recognised as malicious and deleted from Google Play.

Coming to the current batch of apps, the first one is Magic Browser that pretended to be a Chrome browser alternative in Google Play. It was published on May 15 and had been downloaded over 50,000 times before it was finally removed. The other app is Noise Detector that was meant to allow users to measure the decibel level of sounds and had more than 10,000 downloads before its removal.

Advertisement

Both the apps, as we mentioned, belonged to the Ztorg Trojan family, but didn't root affected devices before their removal. Unuchek says the app had the Ztorg digital fingerprint, and speculates that the developers may soon have added the root ability if the apps hadn't been removed.

Advertisement

Unuchek says the Magic Browser app was being used by developers to either test or use malicious text messaging functions. The Magic Browser could send premium text messages to infected phone numbers and leave no traces behind by even deleting the incoming messages and muting the notification sound. "In total, the Magic browser app tries to send SMS from 11 different places in its code. Cybercriminals are doing this in order to be able to send SMS from different Android versions and devices. Furthermore, I was able to find another modification of the Trojan-SMS.AndroidOS.Ztorg that is trying to send an SMS via the "am" command, although this approach should not work," reads Unuchek's report.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus 15R, OnePlus 15R Ace Edition Launch Today: All You Need to Know
  2. Realme 16 Pro+ 5G Listed on Certification Website With These Specifications
  3. Apple's iPhone 18 Pro, iPhone Fold May Feature a Relocated Selfie Camera
  4. OnePlus 15, Nord CE 5 Prices Slashed During Community Sale: See Offers
  5. Dhurandhar OTT Release Date: What We Know So Far
  6. Google Pay Brings Its First Co-Branded UPI-Powered Digital Credit Card
  7. Samsung Expands Micro RGB TVs in More Display Sizes Ahead of CES 2026
  8. Xiaomi 17 Ultra Surfaces on Regulatory Websites, Might Launch Soon
  9. Google Labs' New AI Agent Will Help You Better Organise Your Day
  10. Vivo V70 Stops By US FCC Database Along With RAM and Storage Details
  1. Flex By Google Pay: Google Partners With Axis Bank to Introduce UPI-Powered, Digital Credit Card
  2. Warner Bros. Plans to Reject Paramount Bid on Funding, Terms
  3. Amazon Pay Adds Support for Biometric Authentication for UPI Payments in India
  4. The Pitt Season 2 OTT Release Date Revealed: Know When and Where to Watch it Online
  5. iPhone 18 Pro, iPhone Fold to Feature Relocated Selfie Camera; iPhone 17e to Offer MagSafe Support: Report
  6. Development on The Elder Scrolls 6 Is 'Progressing Really Well', Says Bethesda Director Todd Howard
  7. Meta’s New Open-Source SAM Audio AI Model Can Isolate Sounds From Audio Mixtures
  8. Vivo V70 Stops By US FCC Database; Listing Reveals RAM and Storage Specifications
  9. Taskaree: The Smuggler’s Web OTT Release Date: When and Where to Watch Emraan Hashmi's Intense Crime Thriller
  10. Home Town Streaming Now Online: Know Where to Watch This American Reality Show
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.