New Android Malware Disguising Itself as Nintendo Emulator Games: Report

Advertisement
By NDTV Correspondent | Updated: 10 July 2015 18:41 IST
A new Android malware has been discovered that disguises itself as Nintendo Entertainment System (NES) emulator games. Reported by researchers at Palo Alto Networks, the malware family named "Gunpoder" was observed in 49 unique samples across three different variants.

The new malware is said to target Android users in at least 13 different countries including India, Iraq, Thailand, Indonesia, South Africa, Russia, France, Mexico, Brazil, Saudi Arabia, Italy, the United States, and Spain. The researchers pointed out one interesting observation of "Gunpoder" that this malware only propagated among users outside of China.

Further, the researchers stressed that the findings highlighted the fine line between adware, which is usually skipped by antivirus software, and malware, which is hostile software with malicious tendency.

Advertisement

(Also see: Android Apps Connect to a Shocking Number of Advertisement Sites: Study)

The report notes that the samples of "Gunpoder" were uploaded to VirusTotal in November last year, and was marked as either benign or adware by all antivirus engines.

Advertisement

"While researching the sample, we observed that while it contained many characteristics of adware, and indeed embeds a popular adware library within it, a number of overtly malicious activities were also discovered, which we believe characterizes this family as being malware," notes Palo Alto Networks report.

According to researchers, the "Gunpoder" malware family can collect sensitive information from users; propagate itself through SMS message; potentially push fraudulent advertisements, and has ability to execute additional payloads.

Advertisement

Highlighting how the malware packaged itself into an emulator, the report adds, "Gunpoder samples embed malicious code within popular Nintendo Entertainment System (NES) emulator games, which are based on an open source game framework. Palo Alto Networks has witnessed a trend of malware authors re-packaging open source Android applications with malicious code. Gunpoder makes use of this technique, which makes it difficult to distinguish malicious code when performing static analysis."

Detailing how the malware worked, the report added that soon after installation, the malware presented a declaring statement (when opened for the first time) explicitly notifying users that the app has ad-support and can allow the advertising library to collect information from the device. Once the app is launched, it will ask users to pay for a lifelong license of the game via a pop up dialog.

Advertisement

(Also see: Android Apps With Millions of Downloads on Google Play Contain Adware: Avast)

"If the user clicks the 'Great! Certainly!' button, a payment dialog will pop up, including PayPal, Skrill, Xsolla (the transaction link is no longer active) and CYPay. Users need to register a new PayPal or Skrill account or log in in to their existing account to pay $0.29 or $0.49. The CYPay supports offline gift voucher redeeming. Additionally, this payment dialog will pop up when users click the "Cheats" option within this app. In fact, the malware author added this malicious payment function into this 'Cheats' option, which is free in the original app," explains the report.

Even if users skip the payment dialog, the malware can propagate messages that will be sent out - if users pause the main activity of the malware, and second, if payment is declined then it will share a "fun game" link which will be a variant of this malware family.

"Interestingly enough, the Gunpoder sample will detect the country of the user. If the user is not located in China, this app will automatically send an SMS message, which contains a variant downloading link, to random selected friends in the background," adds report.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Adware, Android, Android Apps, Apps, Malware
Advertisement

Related Stories

Popular Mobile Brands
  1. iPhone 17 Won't Start After Battery Runs Out? Apple Says iOS 26.5.1 Fixes It
  2. Sony Bravia 7II 4K TVs With Cognitive Processor XR Debut in India
  3. Moto G37 Power Review: Covers All the Bases and More
  4. Apple's First Foldable iPhone May Get White Colourway, VC Cooling
  5. MSI's First RTX Spark Laptop Targets AI Workloads, Creators and Developers
  6. Hisense Launches U7SE 144Hz ULED Mini-LED TV Series in India
  7. Nothing Ear 3a, CMF Buds Neo Visit Regulatory Databases, Might Launch Soon
  8. Apple Brings New Wallpaper, Apple Music Playlist Ahead of WWDC 2026
  1. Nothing Ear 3a, CMF Buds Neo Spotted on Regulatory Databases Ahead of Anticipated Debut
  2. Samsung Galaxy Z Fold 8, Galaxy Z Fold 8 Ultra Could Feature Vastly Different Designs, Leaked Dummy Units Suggest
  3. Hisense U7SE 144Hz ULED Mini-LED TV Series With Up to 100-Inch Screens Launched in India: Price, Features
  4. Vivo Y500 Surfaces on Bluetooth SIG Database With Multiple Model Numbers, Could Launch Soon
  5. Asus Ascent QN10 Mini PC With Snapdragon X2 Elite Chipset Showcased at Computex 2026
  6. MSI Showcases New Katana, Venture Laptops and Crosshair A16 HX MLG Edition at Computex 2026
  7. Acer TravelMate P6 14 AI and P2 Spin 14 Unveiled, Acer TravelMate X2 15 and X2 14 Tag Along
  8. Sony Bravia 7II 4K TVs Launched in India With Cognitive Processor XR, Dolby Vision: Price, Features
  9. Asus TUF 16 (2026) Gaming Laptop Unveiled Alongside ExpertBook B5 Flip G2 (2026) at Computex 2026
  10. Asus Zenbook 14, Vivobook S14, Vivobook S16, Vivobook S14 Flip and Vivobook S16 Flip Launched at Computex 2026
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.