Automatically translated.View original post

Found app on Google Play. Insert malware.

Found App on Google Play Insert Malware Bird Extension Sneak Down Malware Suck Anasta Money Down Bait Machine

According to a report by the website Cyber Security News, a research team from Securelist, a subsidiary of Kaspersky's anti-virus software developer (Anti-Virus), detected the return of malware of the victim's money-sucking type, or the Banking Trojan, named Anatsa, in a fake application disguised as an application for reading document files in PDF. These applications served as a loader to help retrieve the real malware (payload) of Anatsa malware onto the victim's machine. This malware outbreak via a fake app on Google Play was called not the first, but It has been the news many times, along with other malware, that has raised doubts about the standards of application moderation on the platform. Anatsa malware has the ability to store financial information, including important information, on the victim's machine so that the financial crimes of victim-directed hackers can be more easily executed.

The process of embedding malware will start with the victim downloading the fake application. In the foreground, the fake application will look like a normal application. There is no fault until the app bounce the deception to the victim to believe that it needs to be updated before it can be used. If the victim approves, it will lead to downloading the malware payload and installing it on the machine. According to the research team, the behavior of the Loader has been collected by the SDK or Software Development Kits. The data will include important data such as the origin of The app downloaded by the victim sends it back to the control server (C2 or Command and Control) so that the hacker decides whether to send the payload to the victim. This is a method called victim-selective malware or Selective Delivery that makes it harder for not all downloaded applications to be screened by the app store team.

In addition, the research team has also detected an interesting statistic: in Kaspersky's 1.99 million malware blocking statistics, up to 30.77% of the total blocking of Banking Trojan has been detected. There are also 93,574 packages associated with such malware types in the quarter. And although the numbers of such packages are gradually decreasing, this does not mean that the danger is decreasing, because the remaining packages are focused on development, update, more insidious capabilities, and malware is transmitted more closely. Maybe it's more dangerous than a lot of packages.

# Trending # lemon 8 diary # googleplay # freedomhack # Malware

9/6 Edited to

... Read moreจากประสบการณ์ส่วนตัวที่เคยติดตั้งแอปพลิเคชันจาก Google Play และเจอปัญหาแอปปลอมบ้าง ทำให้ผมเห็นความสำคัญของการตรวจสอบแอปก่อนดาวน์โหลดเป็นอย่างมาก หนึ่งในไอเท็มที่ผมใช้ตรวจสอบง่ายๆ คือการดูรีวิวและดาวน์โหลดจำนวนมากเพื่อประเมินความน่าเชื่อถือ รวมถึงการอ่านคำอนุญาต (permissions) ที่แอปขอด้วยครับ มัลแวร์นกต่อ (Loader) ที่แอบมาพร้อมกับแอปปลอมนี้เป็นภัยที่น่ากังวลเพราะไม่ได้ติดตั้งมัลแวร์โดยตรง แต่จะดาวน์โหลดมัลแวร์หลักอย่าง Anatsa เฉพาะกับเหยื่อที่ผ่านเกณฑ์เท่านั้น เรียกว่า "การส่งมัลแวร์แบบคัดเลือกเหยื่อ" ที่ทำให้อัปโหลดบนแอปสโตร์ได้โดยไม่ถูกระงับง่ายๆ จุดสำคัญที่ทำให้มัลแวร์นี้แพร่หลายคือ แอปปลอมมักมาในรูปแบบแอปที่คนใช้บ่อย เช่น แอปอ่านไฟล์ PDF หรือแอปยูทิลิตี้ ที่ผู้ใช้มักจะไม่สงสัยว่ามีมัลแวร์แฝงอยู่ เพื่อป้องกันตัวเอง ผมแนะนำให้ผู้ใช้: - ดาวน์โหลดแอปจากผู้พัฒนาที่น่าเชื่อถือ มีรีวิวและดาวน์โหลดเยอะ - ระวังการขออนุญาตผิดปกติ เช่น ขอสิทธิ์ที่ไม่เกี่ยวข้องกับหน้าที่ของแอป - อย่าอนุมัติการอัปเดตหรือดาวน์โหลดส่วนเสริมภายในแอปที่ดูไม่น่าไว้ใจ - ใช้แอนตี้ไวรัสที่มีความสามารถตรวจจับมัลแวร์บนมือถือ นอกจากนี้ ควรอัปเดตระบบปฏิบัติการและแอปของเราตลอดเวลาเพื่อช่วยป้องกันช่องโหว่ที่มัลแวร์อาจใช้เจาะระบบ ในเชิงเทคนิคมัลแวร์นกต่อใช้ SDK เพื่อรวบรวมข้อมูลเครื่องและส่งไปยังเซิร์ฟเวอร์ควบคุม ทำให้แฮกเกอร์สามารถเลือกส่ง Payload ที่ร้ายแรงขึ้นได้ตามเป้าหมาย จากสถิติที่ทีมวิจัย Kaspersky พบ พบว่ามีการบล็อกมัลแวร์ Banking Trojan สูงถึง 30.77% และแพ็คเกจมัลแวร์มากกว่า 93,000 แพ็คเกจในไตรมาส ทำให้เห็นว่ายังต้องเฝ้าระวังภัยคุกคามนี้อย่างใกล้ชิด สำหรับใครที่สงสัยแอปใด ควรตรวจสอบข้อมูลบนเว็บไซต์ความปลอดภัย หรือสอบถามผู้เชี่ยวชาญเพื่อความมั่นใจครับ สรุปแล้ว การดาวน์โหลดแอปบน Google Play ควรมีความระมัดระวังอย่างสูง ไม่ควรไว้ใจแค่เพียงชื่อหรือรูปลักษณ์ของแอปและควรใช้เครื่องมือเสริมตรวจสอบเสมอ เพื่อปกป้องข้อมูลส่วนตัวและทรัพย์สินทางดิจิทัลจากมัลแวร์ที่แฝงมาในรูปแบบที่ทันสมัยและซับซ้อนขึ้นเรื่อยๆ