BadNews for Android users: New malware disguises itself as an ad network

Advertisement
By Anupam Saxena | Updated: 22 April 2013 12:25 IST
Mobile security company Lookout claims to have discovered BadNews, a new malware family that's affecting Android apps.

The company found the malware in 32 apps across four different developer accounts in the Google Play store. Talking about it in a blogpost, Lookout mentioned that the affected apps have been downloaded between 2,000,000 - 9,000,000 times. Google has removed all the apps and suspended accounts of the specific developers, as per Lookout.

Half of the affected apps were found to be in Russian and AlphaSMS, an SMS fraud malware that was also being pushed by BadNews is found to be involved in committing premium rate SMS fraud in the Russian Federation and neighbouring countries such as the Ukraine, Belarus, Armenia and Kazakhstan. The apps that feature the malware range from Russian dictionary apps to popular games to even innocent ones like apps offering salad recipes.

BadNews works by disguising as an ad network and later pushes malware to the user's device after an affected app is installed. It sends fake news messages, prompts users to install apps and sends sensitive information such as the user's phone number and device ID to its Command and Control server.

Following initial activation, the BadNews contacts its server every four hours for new instructions while sending sensitive information such as the device's phone number and its serial number (IMEI) to the server. The server replies with instructions including displaying (fake) news to users, and asking them to install new app updates. The app updates are new malware apps disguised with names of popular apps like Skype.

The malware acts as a challenge to the people who filter apps for malware at the Play Store as it's not directly included in the app and comes into existence after the app connects to the malware server.

However, Lookout mentions that it is not clear whether some or all of these apps were launched with the intent of spreading the BadNews malware or developers were caught unaware as they included code to earn money thinking that BadNews was just an ad network for monetization, as it's disguised as a fraudulent monetization SDK.

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Ray-Ban Meta Gen 2 Glassses Are Now Available in India
  2. Redmi Note 15 5G Series Price, Key Features Leak Hints at Global Debut
  3. Vivo X300 Launched in India With MediaTek Dimensity 9500 SoC at This Price
  4. Mrs Deshpande OTT Release: When, Where to Watch Madhuri Dixit's Serial Killer Mystery
  5. Poco C85 5G Teased to Launch in India Soon With These Features
  6. Amar Subramanya to Replace John Giannandrea as Apple's VP of AI
  7. ESA Picks German Astronaut for Europe's First-Ever Lunar-Orbit Trip
  1. Redmi 15C 5G Launching Today: Know Price in India, Features and Specifications
  2. Gemini App to Get a Major Design Upgrade, Could Soon Be Launched on macOS
  3. NASA’s Perseverance Records First-Ever Mini-Lightning on Mars
  4. Germany to Send First European Astronaut Around the Moon on Artemis Mission
  5. Indian Team Finds 53 Massive Quasars Blasting Jets Millions of Light-Years Long
  6. Mrs Deshpande OTT Release: When, Where to Watch Madhuri Dixit's Serial Killer Mystery
  7. Wake Up Dead Man: A Knives Out Mystery OTT Release: When, Where to Watch the Daniel Craig Whodunit
  8. Fire Force Season 3 Release Date: When, Where to Watch the Shonen Anime's Final Arc
  9. Thamma Is Now Available on Amazon Prime: How to Watch Ayushmann Khurrana's Horror Comedy
  10. The Great Shamsuddin Family OTT Release: When, Where to Watch the Peepli Live Director's Comedy Drama
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.