Malware in Google Play Store Apps
Here’s a summary of the key information from the provided text:
New Malware Variant: A new variant of the Anatsa malware is being distributed, featuring a keylogger.
Evasion Techniques: The malware employs several techniques to avoid detection:
APK ZIP Obfuscator: Uses a common Android APK ZIP obfuscator.
Corrupted Archive: Hides files within a corrupted ZIP archive with invalid compression and encryption flags, hindering static analysis.
dynamic Dropping: Conceals its payload within a JSON file that is dropped and deleted at runtime.
Permission Requirement: The malware needs elevated permissions to operate, but attackers disguise it within seemingly legitimate apps.
joker Remains a Threat: The Joker malware, active since 2020 and specializing in SMS-based credential harvesting, is still prevalent, accounting for 25% of detected infections.
Third-Party App Stores Riskier: App stores operated by third parties are generally considered more perilous than those run by Google or Apple.In essence,the article highlights the ongoing sophistication of Android malware and the challenges in detecting it,particularly through the use of obfuscation and evasion techniques. It also emphasizes the continued threat posed by established malware like Joker.
