• About Us
King of Computer Media
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
King of Computer Media
No Result
View All Result

Home - Anti-Virus Software and Internet Security - Fleckpe subscription malware discovered on Google Play Store, has been installed more than 600,000 times

Fleckpe subscription malware discovered on Google Play Store, has been installed more than 600,000 times

Claire by Claire
May 5, 2023 - Updated on August 4, 2026
in Anti-Virus Software and Internet Security

We have always advocated that the safest thing is to download and install apps from the official Android Play Store. Google has also added many security measures to the Play Store, but it is always difficult to guard against the evil deeds of unscrupulous people. Recently, security researchers discovered a long-lurking malware called “Fleckpe” in the Play Store that can silently steal your money.

Image source: Kaspersky

Fleckpe subscription malware discovered on Google Play Store, has been installed more than 600,000 times

Kaspersky security researchers discovered, the latest member of the malware field, Fleckpe, generates unauthorized fees by subscribing to premium services in applications behind users’ backs. This malicious behavior is as famous as Jocker, Harly and other Android malware. Fleckap is built into seemingly normal applications and secretly helps you subscribe to premium services for a monthly or one-time fee, extracting money from subscriptions you did not authorize.

Google 宣布調整 Play 商店評分方式,把市場與不同類型設備納入考量 - 電腦王阿達

When you install an app that contains Fleckpe, the malicious app requests access to the notification content required to capture subscription confirmation codes on many premium services. When the Fleckpe application is launched, it decodes and executes a hidden payload containing malicious code. This payload is responsible for contacting the threat actor’s command and control (C2) server to send basic information about the newly infected device, including the MCC (Mobile Country Code) and MNC (Mobile Network Code). The C2 responds with a website address, which the Trojan opens in an invisible web browser window and subscribes the victim to premium services. If a confirmation code is required, the malware retrieves it from the device’s notifications and presents it to a hidden screen to complete the subscription. The app still provides victims with the promised functionality, hiding the true purpose and reducing the likelihood of arousing suspicion.

Block notification content (Image source: Kaspersky)

Kaspersky monitoring data shows that the Trojan has been active since last year, but it was only recently discovered and documented. Kaspersky discovered 11 Fleckpe Trojan applications on Google Play, which pretended to be image editors, photo galleries, premium wallpapers, etc., and were distributed under the following names, with a total of approximately 620,000 installations:

  • com.impressionism.prozs.app
  • com.picture.pictureframe
  • com.beauty.slimming.pro
  • com.beauty.camera.plus.photoeditor
  • com.microclip.vodeoeditor
  • com.gif.camera.editor
  • com.apps.camera.photos
  • com.toolbox.photoeditor
  • com.hd.h4ks.wallpaper
  • com.draw.graffiti
  • com.urox.opixe.nightcamreapro
Image source: Kaspersky

Kaspersky said that at the time of publishing this security research, all of the above-mentioned apps have been removed from the Play Store, but malicious actors may have deployed other apps that have not yet been discovered, so the actual number of installations may be higher. Android users who have installed the above-mentioned apps are advised to delete them immediately and scan their phones thoroughly with a reliable anti-virus software to eradicate any remnants of malicious code still hidden in the device.

Image source: Kaspersky

While not as dangerous as spyware or data-stealing malware, subscription Trojans can still generate unauthorized payments, collect sensitive information about infected device users, and potentially serve as entry points for more powerful payloads. To protect against these threats, Android users are advised to only download apps from trusted sources and developers, and to pay attention to the permissions requested by the app during the installation process.

 

Source: KOCPC Chinese

Tags: appGoogleInternet securitymalwarePlay storesubscription

Recent Posts

  • The Xiaomi Pad 8S Pro has passed network access certification and will debut with the self-developed XRING O3 chip.
  • The entire Google Pixel 11 lineup has been leaked! Official promotional renders of the Pixel 11 Pro XL have also surfaced
  • Are Chinese phone battery capacities falsely labeled? A brief look at the “capacity locking” phenomenon in Chinese silicon-carbon batteries.
  • NCC is leaderless, recklessly sending out national-level alert messages!?
  • What does “QR” in QR Code mean?

Recent Comments

No comments to show.
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology

No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology