The recently popular invitation-only audio chat application Clubhouse has continued to receive attention after Tesla boss Musk posted about the application on Twitter. Unfortunately, it is only launched on iOS, which makes many Android users regret it. Recently, security researchers have discovered a new malicious application disguised as the Android version of Clubhouse. Don’t be fooled easily.

Trojanized Android app disguised as Clubhouse, don’t be fooled
ESET Revealed a recent discovery that an Android application is copying Clubhouse’s services and uses a common Google Play download icon on its official website to mislead users into believing that the download links on the webpage are legitimate and trustworthy. Once downloaded and executed, a BlackRock Trojan APK capable of broadly stealing personal data is installed on the phone.

▲The left side is a fake Clubhouse webpage, from the URL to the download button; the right side is the genuine Clubhouse page for everyone to compare.
The BlackRock Trojan was discovered in May 2020 and can be traced to Xerxes and LokiBot, the latter of which had its code leaked online a year ago. Trojans can intercept and tamper with text messages, hide notifications, redirect users to the phone’s home screen and remotely lock them when they try to run anti-virus software. In terms of data theft, BlackRock can not only steal information and text messages from devices and operating systems. ESET stated that the malware can steal content from no less than 458 online services. When an unsuspecting victim opens the application he wants to use, an overlay attack will be performed. This overlay will require the user to provide permission. Once you agree, it is equivalent to providing the malware with operating rights. Its target services include Facebook, Amazon, Netflix, Twitter and various financial, retail and virtual currency exchange platforms.

ESET said that the popular 2FA SMS two-factor authentication may not necessarily work if infected with this Trojan, because the Trojan can intercept SMS messages and also ask users to activate accessibility services, effectively giving criminals more permissions to control the device. Although fake Google download buttons are an easy way for users to confuse them into downloading, as long as users insist on downloading apps from the Google Play Store, personal risks can be greatly reduced. In addition, they should keep their device firmware updated, pay attention to the permissions new apps ask for from you at all times, and check the security of their mobile phones.
◎Data source:ESET
Source: KOCPC Chinese