/
    Zpět na blog
    Security

    Android under attack


    Android under attack

    This week several security issues have been discovered in Android.

    image

    The first news was the discovery that** spyware called ‘Mandrake’ has been hiding in several apps in the Google Play store since 2022.**

    Bitdefender first documented Mandrake in 2020, with researchers pointing to the malware’s sophisticated spying capabilities and noting that it has been operating in the wild since at least 2016.

    Kaspersky now reports that a new, more obfuscated variant of Mandrake has made its way onto Google Play via five apps.

    These apps remained available for at least a year, while the last one, AirFS, which was the most successful in terms of popularity and infections, was removed at the end of March 2024.

    The total number of app downloads reached 32,000.

    In other news, malware aimed at stealing OTP keys from SMS messages has been discovered in the Google Play store.

    The malicious apps are designed to intercept one-time passwords (OTPs), which are used to authenticate online accounts, in order to commit identity fraud.

    Victims of the campaign have been identified in 113 countries, with India and Russia topping the list, followed by Brazil, Mexico, the US, Ukraine, Spain and Turkey.

    Once installed, the app requests permission to access incoming SMS messages, after which it connects to one of 13 command and control (C2) servers and forwards the stolen SMS messages.

    “The malware remains hidden and constantly monitors new incoming SMS messages,” the researchers said.

    In a third finding, cybersecurity researchers discovered a new Android Remote Access Trojan (RAT) called BingoMod, which not only performs fraudulent money transfers from compromised devices, but also deletes them in an attempt to erase traces of the malware.

    Italian cybersecurity firm Cleafy, which discovered the RAT in late May 2024, said the malware is actively being developed. It attributed the Android Trojan to a likely Romanian-speaking attacker, based on the presence of comments in Romanian in the source code associated with early versions.

    “BingoMod belongs to the modern generation of mobile RAT malware because its remote access capabilities allow attackers to perform account takeovers directly from the infected device,” said researchers Alessandro Strino and Simone Mattia.

    It is worth noting that this technique has also been observed in other Android banking Trojans such as Medusa (aka TangleBot), Copybara and TeaBot (aka Anatsa).

    BingoMod, like BRATA, also uses a self-destruct mechanism designed to remove all evidence of fraudulent transactions from the infected device, making forensic analysis more difficult.

    Some of the identified applications pose as antivirus tools and updates for Google Chrome. Once installed using smishing tactics, the app prompts the user for permissions to access services and uses them to initiate malicious actions.

    © 2026 Patrik Žák. Všechna práva vyhrazena.