Android Malware Using Fake App to Spread Via WhatsApp Discovered on Google Play: Check Point Research

The Android app spreading the malware was downloaded from Google Play nearly 500 times over the course of two months, before it went offline.

Advertisement
By Jagmeet Singh | Updated: 7 April 2021 19:08 IST
Highlights
  • Check Point Research reported the Android malware
  • WhatsApp notifications were monitored by the malware hidden in an app
  • Google Play pulled the FlixOnline app that contained the malware

The Android malware found by the researchers was of “wormable” nature

Photo Credit: Pixabay/ andrekheren

A new Android malware has been discovered that existed as an app on Google Play and is claimed to spread via WhatsApp conversations. Called FlixOnline, the app pretended to allow users to view global Netflix content. It was, however, designed to monitor the user's WhatsApp notifications and send automatic replies to their incoming messages with the content it receives from the hacker. Google pulled the app immediately from the Play store after the company was reached out to. However, it was downloaded hundreds of times before it got removed.

Researchers at threat intelligence firm Check Point Research discovered the FlixOnline app on Google Play. When the app is downloaded from the Play store and installed, the underlying malware starts a service that requests “Overlay,” “Battery Optimisation Ignore,” and “Notification” permissions, the researchers said in a press note.

The purpose of obtaining those permissions is believed to allow the malicious app to create new windows on top of other apps, stop the malware from being shut down by the device's battery optimisation routine, and gain access to all notifications.

Advertisement

Instead of enabling any legitimate service, the FlixOnline app monitors the user's WhatsApp notifications and sends an auto-reply message to all WhatsApp conversations that lures victims with free access to Netflix. The message also contains a link that could allow hackers to gain user information.

Advertisement

The “wormable” malware, which means that it can spread by itself, could spread further via malicious links and could even extort users by threatening to send sensitive WhatsApp data or conversations to all their contacts.

Check Point Research notified Google about the existence of the FlixOnline app and the details of its research. Google quickly removed the app from the Play store upon receiving the details. However, the researchers found that the app was downloaded nearly 500 times over the course of two months, before it went offline.

Advertisement

The researchers also believe that while the particular app in question was removed from Google Play after it was reported, the malware could return through another similar app in the future.

“The fact that the malware was able to be disguised so easily and ultimately bypass Play Store's protections raises some serious red flags. Although we stopped one campaign of the malware, the malware family is likely here to stay. The malware may return hidden in a different app,” said Aviran Hazum, Manager of Mobile Intelligence at Check Point, in a prepared quote.

Advertisement

The affected users are advised to remove the malicious app from their device and change their passwords.

It is important to note while the malware variant available through the FlixOnline app was designed to spread via WhatsApp, the instant messaging app doesn't include any particular loophole that allowed the circulation of malicious content. Instead, the researchers found that it was Google Play that wasn't able to restrict access to the app at first glance — despite using a mix of automated tools and preloaded protections including Play Protect.


What is the best phone under Rs. 15,000 in India right now? We discussed this on Orbital, the Gadgets 360 podcast. Later (starting at 27:54), we speak to OK Computer creators Neil Pagedar and Pooja Shetty. Orbital is available on Apple Podcasts, Google Podcasts, Spotify, and wherever you get your podcasts.

Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Apple's iPhone 18 Pro, iPhone Fold May Feature a Relocated Selfie Camera
  2. OnePlus 15R With 7,400mAh Battery, Snapdragon 8 Gen 5 Debuts at This Price
  3. Xiaomi 17 Ultra With Leica-Tuned Cameras Confirmed to Launch Soon
  4. OnePlus Pad Go 2 Launched in India With 10,050mAh Battery, 5G Connectivity
  5. OnePlus Watch Lite With Up to 10 Days Battery Life Launched: See Price
  6. OnePlus 15s Visits BIS Certification Website; Could Launch in India Soon
  7. OnePlus 15R Review
  8. Vivo V70 Stops By US FCC Database Along With RAM and Storage Details
  9. Dhurandhar OTT Release Date: What We Know So Far
  10. Infinix Xpad Edge With 13.2-Inch Display, 8,000mAh Battery Launched
  1. Apple Allows Third-Party App Stores, Relaxes Payment Restrictions in Japan to Comply With MSCA Act
  2. Hogwarts Legacy Has Sold 40 Million Copies, Warner Bros. Games Announces
  3. OnePlus 15s Listing on BIS Certification Website Hints at Imminent Launch in India
  4. Infinix Xpad Edge Launched With 13.2-Inch Display, 8,000mAh Battery: Price, Specifications
  5. Ethirneechal Thodargiradhu Now Streaming on SunNXT: What You Need to Know
  6. The Villainess Is Adored by the Prince of the Neighbor Kingdom OTT Release Date: Know When and Where to Watch This Japanese Anime Series Online
  7. Easygoing Defense by the Optimistic Lord Anime to Stream on Crunchyroll in January 2026
  8. Eko OTT Release Reportedly Revealed: When and Where to Watch it Online?
  9. Pornhub User Data Reportedly Stolen by Hacker Group ShinyHunters, Threaten to Expose
  10. Apple's Foldable iPhone Bears Resemblance to iPad Mini in Leaked CAD Renders
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.