Malicious viruses in the Google Play Store are really constantly being exposed almost every few months. Recently, a foreign network security company discovered that 4 Android Apps contain a very scary new malicious virus. It does not steal your data, but directly steals your money. It will invade the online banking app on your phone and transfer the money in the deposit through the program. One of them has been installed more than 50,000 times.

4 Android Apps were found to contain SharkBot malicious virus
Recently, the British network security company NCC Group released a report. Recently, a new SharkBot Trojan virus has appeared. It was first reported by Cleafy It was discovered at the end of October 2021 that it has no connection with other bank-related malicious viruses, such as Flubot, Cerberus/Alien, Oscorp, etc. SharkBot has some complex and dangerous functions, such as the Automatic Transfer System (ATS), which allows attackers to transfer money out of the victim’s bank account without human intervention.
The NCC stated that when a user installs an App containing the SharkBot virus, it will detect bank-related applications and perform an “overlay attack” if necessary. A page that looks like a banking problem will pop up, asking you to enter your login credentials. At the same time, a keylogger will be activated to record everything the user enters and send it to the attacker’s server. In addition, the virus can intercept and hide SMS messages and other incoming notifications. Representatives said that even if the bank sends immediate account abnormality notifications, users may not receive them, which is really scary. The NCC report has a complete analysis of the SharkBot operation process and program code. Those who are interested in learning more can goClick here to jump to NCC to read。

And why is such a dangerous virus listed on the Play Store? The NCC also briefly stated that most of these Apps containing the SharkBot virus will disguise themselves as anti-virus software to trick users into downloading and installing it. Then, after the user downloads it, the App will ask to download updates to obtain full functionality (which contains malicious viruses), and then start trying to steal the user’s bank account.

Currently, the following four Android Apps have been found to contain the SharkBot malicious virus:
- Antivirus Super Cleaner (1000+ installations)
- Alpha Antivirus Cleaner (5,000+ installations)
- Atom Clean-Booster antivirus (500+ installations)
- Powerful Cleaner antivirus (50,000+ installs)
The total adds up to less than 60,000 times, so the good news is that at least not many people installed it by mistake, and these apps have been removed from the Play Store. As for whether anyone had money stolen from the bank, it is not clear, and it was not specifically mentioned in the report. In any case, if you are someone who regularly installs antivirus and cleans related apps on the Play Store, it’s best to check it out.
Source: KOCPC Chinese
