Google Removes 6 Apps Posing as Antivirus Apps, Used to Infect Phones With Sharkbot Malware

The apps accumulated a total of 15,000 downloads on the Google Play store before they were removed.

Advertisement
By David Delima | Updated: 8 April 2022 19:23 IST
Highlights
  • Sharkbot is a malware used to steal Android users’ credentials
  • The fake antivirus apps were used to download malicious payloads
  • Sharkbot is designed to target users in specific regions with geofencing

The researchers suggest that users should only download antivirus apps from reputed publishers

Photo Credit: Pexels/ Sora Shizamaki

Google has reportedly removed six apps infected with the Sharkbot bank stealer malware from the Google Play store. The apps were downloaded 15,000 times before they were ejected from the store. All six apps were designed to pose as antivirus solutions for Android smartphones and were designed to select targets using a geofencing feature, stealing their login credentials for various websites and services. These infected applications were reportedly used to target users in Italy and the United Kingdom.

According to a blog post by Check Point Research, six Android applications pretending to be genuine antivirus apps on the Google Play store were identified as “droppers” for the Sharkbot malware. Sharkbot is an Android Stealer that is used to infect devices and steal login credentials and payment details from unsuspecting users. After a dropper application is installed, it can be used to download a malicious payload and infect a user's device — evading detection from on the Play Store.

The six malicious applications that were removed from the Play Store
Photo Credit: Check Point Research

Advertisement

The Sharkbot malware used by the six fraudulent antivirus applications also used a ‘geofencing' feature that is used to target victims in specific regions. According to the team at Check Point Research, the Sharkbot malware is designed to identify and ignore users from China, India, Romania, Russia, Ukraine, or Belarus. The malware is reportedly capable of detecting when it is being run in a sandbox and stops execution and shuts down to prevent analysis.

Advertisement

Check Point Research identified six applications from three developer accounts — Zbynek Adamcik, Adelmio Pagnotto, and Bingo Like Inc. The team also cites statistics from AppBrain that reveals that the six applications were downloaded a total of 15,000 times before they were removed. Some of the applications from these developers are still available in third party markets, despite having been removed from Google Play.

Four malicious apps were discovered on February 25 and reported to Google on March 3. The applications were removed from the Play Store on March 9, according to Check Point Research. Meanwhile, two more Sharkbot dropper apps were discovered on March 15 and March 22 — both were reportedly removed on March 27.

Advertisement

The researchers stated that the apps had been downloaded 15,000 times before they were removed
Photo Credit: Check Point Research

Advertisement

The researchers also outlined a total of 22 commands used by the Sharkbot malware, including requesting permissions for SMS, downloading java code and installation files, updating local databases and configurations, uninstalling applications, harvesting contacts, disabling battery optimisation (to run in the background), and sending push notifications, listening for notifications. Notably, the Sharkbot malware can also ask for accessibility permissions, allowing it to see the contents of the screen and perform actions on the user's behalf.

According to the team at Check Point Research, users can stay safe from malware masquerading as legitimate software by only installing applications from trusted and verified publishers. If users find an application by a new publisher (with few downloads and reviews), it is better to look for a trusted alternative. Users can also report seemingly suspicious behaviour to Google, according to the researchers.


Gaana CEO and Spotify's India chief join us on Orbital, the Gadgets 360 podcast, to discuss India's unique music streaming landscape. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. Poco Pad X1, Pad M1 Launched With Snapdragon Chips At This Price
  2. Raju Weds Rambai OTT Release Date Reportedly Leaked Online
  3. iQOO 15 Launch Today: From Price to Features, Everything You Need to Know
  4. Poco F8 Pro Vs Realme GT 8 Pro Vs Xiaomi 17 Pro: Prices, Specifications Compared
  5. iQOO 15 Launched in India With Snapdragon 8 Elite Gen 5 SoC at This Price
  6. Poco F8 Ultra Launched With Snapdragon 8 Elite Gen 5 Alongside F8 Pro
  7. Realme P4x 5G, Watch 5 to Launch in India on This Date
  8. Redmi 15C 5G Could Launch Soon in India at This Price
  9. Poco F8 Series Launch Today: Know Price, Specs and More
  10. After ChatGPT, Copilot AI Chatbot is Leaving WhatsApp Next Year
  1. Nvidia CEO Jensen Huang Says Company Managers Using Less AI Are Insane: Report
  2. OnePlus Ace 6 Turbo Tipped to Launch Next Year With a Snapdragon Chip, 9,000mAh Battery
  3. Xbox November 2025 Update Brings Gaming Copilot, Full Screen Experience Expansion and Cloud Upgrades
  4. Redmi Pad 2 Pro, Redmi Buds 8 Pro Could Launch in China Soon
  5. Mass Jathara OTT Release Date: When and Where to Watch Ravi Teja Starrer Online?
  6. Raju Weds Rambai OTT Release Date Reportedly Leaked Online: When and Where to Watch Akhil Raj and Tejaswi Rao Starrer Online?
  7. Aukaat Ke Bahar OTT Release Revealed: Where to Watch Elvish Yadav Starrer Series Online?
  8. Microsoft Joins AI Shopping War, Brings New Features to Copilot in Edge Browser
  9. Death Stranding 2: On the Beach PC Port Leaks, Gets ESRB Rating
  10. Poco Pad X1 Launched With Snapdragon 7+ Gen 3 Chipset, 8,850mAh Battery, Alongside Pad M1: Price, Specifications
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.