Malware Worming Its Way Into Clones of Popular Apps: McAfee Labs

Advertisement
By Agence France-Presse | Updated: 24 June 2014 11:52 IST
Malicious software is increasingly making its way into mobile phones through "cloned" versions of popular apps, and software weaknesses in legitimate ones, security researchers said Tuesday.

McAfee Labs said in its quarterly threat assessment that weaknesses in app security is becoming a growing problem for owners of mobile devices.

In some cases, cybercriminals can take advantage of the popularity of an app by creating a clone, which can extract personal data or even allow an attack to gain control of the device.

Advertisement

This was the case with "Flappy Birds," a mobile game which saw a meteoric rise but was later withdrawn by its creator.

McAfee Labs sampled 300 Flappy Bird clones and found that almost 80 percent contained malware.

Advertisement

"Some of the behavior we found includes making calls without the user's permission; sending, recording, and receiving SMS messages; extracting contact data; and tracking geolocation. In the worst cases, the malware gained root access, which allows uninhibited control of anything on the mobile device including confidential business information," the report said.

The McAfee report said some legitimate apps have security flaws which can be exploited by hackers.

Advertisement

The researchers said they discovered an Android trojan "which exploits an encryption method weakness in the popular messaging app WhatsApp" and then steals conversations and pictures stored on the device.

"Although this vulnerability has now been fixed, we can easily imagine cybercriminals continuing to look for other flaws in this well-known app," the report said.

Advertisement

Digital pickpockets
The researchers also said they identified malware can steal money from a digital wallet.

One of the malware programs identified "is disguised as an update for Adobe Flash Player or another legitimate utility app," and can take over a digital wallet to send a money transfer to the attacker's server.

"Mobile malware has recently started to use legitimate apps and services, in addition to a platform's standard features, to circumvent conventional surveillance by app stores and security products," the McAfee report said.

"Consequently, protecting only the underlying platform is no longer sufficient. We believe that developers need to protect their apps and services from unauthorized and malicious use."

McAfee's Vincent Weafer said people may be lulled into a false sense of security about mobile apps.

"We tend to trust the names we know on the Internet," Weafer said.

"The year 2014 has already given us ample evidence that mobile malware developers are playing on these inclinations, to manipulate the familiar, legitimate features in the mobile apps and services we recognize and trust."
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Tecno Pova 8 to Launch in India With 8,000mAh Battery on This Day
  2. Xiaomi Pad 8 Price Increased: Here's How Much It Costs Now
  3. From iOS 27 to Revamped Siri, What to Expect from WWDC 2026
  1. Sahara Meteorite May Be Fragment of a Lost Moon-Sized World, Study Suggests
  2. OpenAI Introduces Smarter ChatGPT Memory, Adds Dreaming Architecture
  3. Tecno Pova 8 India Launch Date Announced; Battery Size, Design, Colour Options Teased
  4. Samsung Reportedly Starts Internal Testing of Android 17-Based One UI 9 for Galaxy S25 Series
  5. Bybit Lists Western Union’s USDPT Stablecoin for Trading and Transfers
  6. Xiaomi Pad 8 Price Hiked in India: Here’s How Much It Costs Now
  7. Instagram Reels Influencing Nearly Half of Purchase Decisions in India, Meta Study Claims
  8. OnePlus Turbo 6X, OnePlus Turbo 6X Pro Colour Options, Price Range, Key Specifications Teased
  9. Sattendru Maarudhu Vaanilai Now Streaming Online: Where to Watch Jai’s Romantic Thriller Movie
  10. Asics GEL-Kayano 33 Launched in India With New Stability Tech, FluidSupport System
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.