Trojan in 60+ Google Play Store Games Hides Inside Images

Researchers at Dr. Web have discovered a new Trojan lurking inside over 60 games in the Google Play store. The games are being distributed by more than 30 developers, including Conexagon Studio,...
Blog rating:1 out of5 with2 ratings

Trojan in 60+ Google Play Store Games Hides Inside Images

by NewsEditor_ on January 29th, 2016 in Industry and Security News.

Researchers at Dr. Web have discovered a new Trojan lurking inside over 60 games in the Google Play store. The games are being distributed by more than 30 developers, including Conexagon Studio, Fun Color Games and BILLAPPS. The main purpose of the Trojan, dubbed Android.Xiny.19.origin, is to create a backdoor on the affected mobile device to download and run additional malicious programs at the cybercriminal’s command. The Trojan appears to do this in the background as the user plays the affected game. 

Once installed, this virus collects the following information about the mobile device: the IMEI and MAC addresses (unique device identifiers), the operating system version, the current language, and mobile network provider name. Additionally, the Trojan also gathers information about the accessibility of memory cards and, in addition to downloading and installing additional malware, it can also delete applications without the user’s knowledge if root access is available on the infected device. It can also, less maliciously, be used to display advertisements.

The researchers report that, “To masquerade the malicious program, virus makers hid it in specially created images by applying steganography.” Steganography is the technique of embedding malicious computer code into media, in this case pictures, to hide the infection from antivirus programs. In the case of Android.Xiny.19.origin, the code embedded in the images retrieves a hidden file and then executes it. The technique of steganography dates back to ancient Greece, when people wrote secret messages on wood and covered them with beeswax so that the recipient could discover them by removing the layer of wax.

At the time of this writing, the affected games are still available in the Google Play store. 

Average: 1 (2 votes)

Facebook Comments Box

x

Our best antivirus yet!

Fresh new look. Faster scanning. Better protection.

Enjoy unique new features, lightning fast scans and a simple yet beautiful new look in our best antivirus yet!

For a quicker, lighter and more secure experience, download the all new adaware antivirus 12 now!

Download adaware antivirus 12
No thanks, continue to lavasoft.com
close x

Discover the new adaware antivirus 12

Our best antivirus yet

Download Now