Since Huawei’s devices lost GMS services, the company has been actively developing its own service system. AppGallery is their response. Please provide incentives to attract developers to list on this platform. However, a large-scale malware campaign has broken out on this platform in recent days. More than 190 Trojan applications disguised as games have been installed more than 9 million times. Users are advised to be careful.

Trojan pretending to be a game app on Huawei AppGallery, more than 9 million Android devices infected
According to the latest report from Dr. Web, a modified version of the Cynos malware, a Trojan named “Android.Cynos.7.origin”, was detected. It is used to collect users’ sensitive data. The security research unit has notified Huawei of this and is assisting Huawei in deleting the identified applications from the app store. However, users still need to manually delete the installed parts.

Bad actors hide their malware in Android apps, pretending to be emulators, platformers, arcade games, RTS strategy games, and shooters for Russian, Chinese, and international users, all of which offer ads so users are unlikely to delete them if they like the game. The list of Cynos malware applications is vast, but here are three of the most installed and popular ones:
- Hurry up and hide – 2,000,000 times
- Cat adventures – 427,000 times
- Drive school simulator – 142,000 times

This Cynos Trojan variant can perform various malicious activities, including monitoring SMS text messages and downloading and installing other payloads; some versions are more aggressive and can send advanced SMS, intercept incoming SMS, download and launch additional modules and other applications, etc. The Trojan’s aggressiveness becomes apparent right from the installation stage, as it requests permission to perform activities that are not typically related to gaming, such as making phone calls, detecting the user’s location, etc. If the user grants permission, the malware can leak the following data to a remote server:
- User mobile phone number
- Know your device’s location from GPS, mobile networks and WiFi access points
- Various mobile network parameters, such as network code and country code, etc.
- Various technical specifications on the device
- Various parameters in Trojan application data

due to being alone with190 malicious apps in the listComparison is too cumbersome, and the most direct solution is to use a tool to detect the Cynos Trojan and run through it.
◎Data source:Bleeping Computer
Source: KOCPC Chinese