Necro Trojan Detected in Google Play Apps and Modded Versions of Spotify, WhatsApp

The Necro trojan malware was spotted in two apps on the Google Play store that have since been taken down by the company.

Advertisement
Written by Akash Dutta, Edited by David Delima | Updated: 24 September 2024 20:06 IST
Highlights
  • The Necro trojan was also found in modded APKs of popular apps
  • In one app, researchers found the payload was spread via an image module
  • Similar malware was found in the CamScanner app in Google Play in 2019

Researchers found that the malware is targeting users in Russia, Brazil, Vietnam, Ecuador, and Mexico

Photo Credit: Pixabay/ @neotam

Some Google Play apps and unofficial mods of popular apps are being targeted by attackers to spread a dangerous malware, according to security researchers. The purported Necro trojan is capable of logging keystrokes, stealing sensitive information, installing additional malware, and remote execution of commands. Two apps in the Google Play app store have been spotted with this malware. Further, modded (modified) Android application packages (APKs) of apps such as Spotify, WhatsApp, and games like Minecraft were also detected distributing the trojan.

Google Play Apps, Modded APKs Used to Spread Necro Trojan

The first time a trojan from the Necro family was spotted was in 2019 when the malware infected the popular PDF maker app CamScanner. The official version of the app in Google Play with more than 100 million downloads posted a risk to users, but a security patch fixed the issue at the time.

According to a post by Kaspersky researchers, a new version of the Necro trojan has now been spotted in two Google Play apps. The first is the Wuta Camera app which has been downloaded more than 10 million times, and the second is Max Browser with more than a million downloads. The researchers have confirmed that Google took down the infected apps after Kaspersky reached out to the company.

Advertisement

The main issue stems from a large number of unofficial 'modded' versions of popular apps, which are found hosted on a large number of third-party websites. Users can mistakenly download and install them on their Android devices, infecting them in the process. Some of the APKs with the malware spotted by researchers include modified versions of Spotify, WhatsApp, Minecraft, Stumble Guys, Car Parking Multiplayer, and Melon Sandbox — these modded versions promise users access to features that typically require a paid subscription.

Advertisement

Interestingly, it appears the attackers are using a range of methods to target users. For instance, the Spotify mod contained an SDK which displayed multiple advertising modules, as per the researchers. A command-and-control (C&C) server was being used to deploy the trojan payload if the user accidentally touched the image-based module.

Similarly, in the WhatsApp mod, it was found that the attackers had overwritten Google's Firebase Remote Config cloud service to use it as the C&C server. Ultimately, interacting with the module would deploy and execute the same payload.

Advertisement

Once deployed, the malware could “download executable files, install third-party applications, and open arbitrary links in invisible WebView windows to execute JavaScript code,” highlighted the Kaspersky post. Further, it could also subscribe to expensive paid services without the user knowing.

While the apps in Google Play have already been taken down, users are urged to be careful while downloading Android apps from third-party sources. In case they do not trust the marketplace, they should refrain from downloading or installing any app or files.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. RAM Crisis 2026: 16GB Phones Out, 4GB Models Making a Comeback
  2. Lenovo Idea Tab Plus Launched in India With 10,200mah Battery: Details
  3. OnePlus 15R Storage Options Leaked: Here's How Much It Might Cost in India
  4. Pixel 10 Series Gets Price Cuts During Google's End of Year Sale: See Offers
  5. MacBook Air (2025) With M4 Chip Available at This Discounted Price
  6. Redmi Note 15 5G Chipset Revealed Ahead of January 6 India Launch
  7. Mrs Deshpande OTT Release Date: Madhuri Dixit's Starrere to Premiere on This Date
  8. Logitech MX Master 4 Launches in India With These Features
  9. Oppo Reno 15c With Snapdragon 7 Gen 4 SoC Launched at This Price
  10. Vivo S50, S50 Pro Mini With Snapdragon Chips Launched at These Prices
  1. OnePlus Turbo Series Confirmed to Launch Soon With the ‘Strongest Battery’ in the Segment
  2. Realme Narzo 90, Realme Narzo 90x 5G Launching Today: Know Price in India, Features, Specifications and More
  3. Webb Telescope Discovers Hidden Atmosphere on Molten Super-Earth TOI-561 b Despite Extreme Heat
  4. Astronomers Watch a Dormant Neutron Star Reignite After a Decade of Silence
  5. Predictive Forecasting Tools Can Boost the Success of Clean Energy Investments Worldwide
  6. Chinese Spacecraft Nearly Slammed Into Starlink Satellite, SpaceX Reveals
  7. Clocks on Mars Run Faster Than on Earth, New Study Finds
  8. The Hunting Wives Out on OTT: Know Everything About This American Thriller Mystery Series
  9. All Her Fault Now Streaming on JioHotstar: Know Everything About This Thriller Series
  10. Wednesday Season 3 Set for July 2027 on Netflix: Jenna Ortega Returns as the Iconic Addams Heir
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.