Hackers now use a combination of malicious applications and brand impersonation to steal passwords and other sensitive data from unsuspecting Android users.
As reported by Hacker NewsA new malware campaign has been detected online in which malicious Android apps impersonate Google, Instagram, Snapchat, WhatsApp, X and other popular online services in an attempt to collect contacts, text messages, call logs and, of course, vulnerable Android passwords. The telephones.
Although security researchers from SonicWall’s Capture Labs team know a lot about this new campaign so far, they’re not quite sure how the malicious apps used in it end up in the system. best android phones. However, these fake applications could spread on phishing sitesvia emails or text messages or may even come included with pirated software.
While we’ll likely learn more about the intricacies of this campaign and the hackers behind it once SonicWall does, in the meantime, here’s everything you need to know to avoid getting a nasty malware infection on your own Android phone. as a result of a malicious infection. application.
From fake app to fake login pages

According to a blog post From SonicWall, once the malicious app used to distribute this malware is installed on the victim’s phone, it uses famous Android app icons from popular apps and online services to hide in plain sight.
When the malicious app is opened for the first time, which could easily happen by mistake as it poses as another app, it requests access to two permissions: Android Accessibility Service and device administrator permission. If a potential victim grants the app access to these sensitive permissions, it can take control of their phone and steal sensitive data without their knowledge.
The malicious application in question establishes a connection with a hacker-controlled command and control (DC) server from which you receive additional instructions. For example, the malicious app can be used to read messages, read call logs, access notification data, send messages, and worst of all, open Malicious web pages in the victim’s browser for phishing purposes.
Basically, the way this malicious application and the malware it contains obtains victims’ credentials is by taking them to fake login pages for sites like Instagram, PayPal, Netflix, Microsoft, WordPress, LinkedIn, ProtonMail, Yahoo and more. They are then asked to enter their username and password, which are stored and then transmitted to the hackers behind this campaign.
From there, they can take over your online accounts and commit fraud or even identity theft whether one of these services contains sufficient sensitive personal information. For example, if they obtain a victim’s Microsoft credentials and use OneDrive to store copies of their driver’s license, passport, or even their Social Security number (a terrible idea, but some people still do it), hackers could cause serious problems.
How to stay safe from Android malware

Since we’re not entirely sure how this particular malware-filled app spreads, the best I can do is give you some general guidance when it comes to protecting yourself from Android malware.
Google has taken many precautions over the years to significantly decrease the chances of malicious apps ending up in Play store. However, you still need to be careful when downloading any new app on your Android phone. You want to check the ratings and reviews of an app and, if possible, look for a video review online so you can watch the app in question.
However, typically with malicious applications, they are often downloaded to the victim’s smartphone. Surprisingly, this is usually done by the victim themselves after being forced to do so by a hacker, scammer, or some other type of cybercriminal. That’s why you should be very careful when someone tells you to install an app in a text message, email, or on social media. If the app is not available on an app store of its own and must be downloaded as an APK file and then installed manually, this is a big red flag and should be avoided at all costs.
First of all, to prevent malicious apps from being installed on your Android phone, you need to make sure that Protect Google Play is enabled as this pre-installed security app scans all your existing apps and any new ones you download for malware. However, if you want to be very careful, you should also consider running one of the the best antivirus apps for Android together with him.
We may not know more about this particular campaign, but at least now you know that malicious apps can change their icons to hide in plain sight. Sometimes they do this by impersonating system apps like contacts or settings or, in this case, impersonating popular apps using their logos and names. However, since campaigns like this can be so effective, we likely won’t see hackers abandon this tactic from their arsenal anytime soon.
- Wpeeper malware for Android adds a backdoor to your phone to steal your data
- Here’s another great reason to avoid online content and software piracy.
- Scammers trick Android users with fake antivirus app that can empty bank accounts