Sharkbot Malware Swims Back To Google Play To Bite New Victims, Delete These Apps Now

Teilen:

A nasty bit of Android malware previously lurking on the Google Play Store has returned with additional capabilities. Known as SharkBot, the malware is designed to steal user login credentials, particularly credentials used to access financial applications. The malware has also been found to initiate money transfers directly on compromised devices.

SharkBot abuses accessibility permissions in multiple ways to conduct its malicious undertaking. The malware can steal user credentials by logging text entered into login fields. In the case that a user’s account is protected by SMS two-factor authentication (2FA), SharkBot can bypass this protection by reading SMS messages to steal authentication codes. The malware is also capable of overlaying fake login screens directly over targeted financial apps. The fake login screens appear legitimate but actually steal entered user credentials. Additionally, threat actors can use SharkBot to remotely control infected devices. All of these capabilities are scary enough, but a new version of SharkBot has entered the wild with the further ability to steal user session cookies.

Play Store listings for two apps recently found to include the SharkBotDropper (source: Fox IT)

Threat actors distribute the malware by submitting apps to the Google Play Store that come packaged with a malware dropper utility. Once an unsuspecting user installs one of these apps, the dropper reaches out to a command-and-control (C2) server and downloads the full SharkBot malware payload. Previous versions of the SharkBotDropper abused accessibility services to automatically install the malware payload. However, researchers at Fox IT recently found a new version of the dropper that prompts users to install the malware themselves, falsely informing users that the APK file contains an app update.

The researchers found two apps on the Google Play Store that contain this updated malware dropper: Mister Phone Cleaner and Kylhavy Mobile Security. Between them, the two apps have a total of 60,000 downloads. As of the time of writing, Google appears to have removed the Kylhavy Mobile Security app from the Play Store but hasn’t yet delisted Mister Phone Cleaner. Hopefully, Google will remove the latter app shortly, but removing an app from the Play Store won’t remove it from affected users’ devices. Those with these malicious apps already installed on their devices will need to manually remove the apps themselves.

https://hothardware.com/news/sharkbot-malware-back-google-play-delete-these-apps-now

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
11:22 pm, Juli 8, 2025
Wetter-Symbol 17°C
L: 16° | H: 19°
overcast clouds
Luftfeuchtigkeit: 58 %
Druck: 1019 mb
Wind: 1 mph NW
Windböe: 1 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 90%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:53 am
Sonnenuntergang: 9:17 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Tomorrow 10:00 pm
Wetter-Symbol
16° | 19°°C 0.18 mm 18% 7 mph 57 % 1022 mb 0 mm/h
Do. Juli 10 10:00 pm
Wetter-Symbol
18° | 29°°C 0 mm 0% 9 mph 73 % 1023 mb 0 mm/h
Fr. Juli 11 10:00 pm
Wetter-Symbol
19° | 30°°C 0 mm 0% 8 mph 64 % 1022 mb 0 mm/h
Sa. Juli 12 10:00 pm
Wetter-Symbol
19° | 30°°C 0 mm 0% 10 mph 66 % 1019 mb 0 mm/h
So. Juli 13 10:00 pm
Wetter-Symbol
18° | 31°°C 0 mm 0% 9 mph 69 % 1017 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
17° | 17°°C 0 mm 0% 3 mph 55 % 1019 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
15° | 16°°C 0 mm 0% 3 mph 54 % 1020 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
17° | 17°°C 0 mm 0% 5 mph 56 % 1021 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
22° | 22°°C 0 mm 0% 5 mph 57 % 1021 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
23° | 23°°C 0 mm 0% 6 mph 55 % 1022 mb 0 mm/h
Tomorrow 4:00 pm
Wetter-Symbol
25° | 25°°C 0.18 mm 18% 7 mph 45 % 1021 mb 0 mm/h
Tomorrow 7:00 pm
Wetter-Symbol
25° | 25°°C 0 mm 0% 7 mph 44 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
23° | 23°°C 0 mm 0% 3 mph 53 % 1022 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,860.99
0.69%
Ethereum(ETH)
€2,222.10
2.70%
Fesseln(USDT)
€0.85
0.01%
XRP(XRP)
€1.97
1.44%
Solana(SOL)
€128.66
1.70%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.145616
2.25%
Shiba Inu(SHIB)
€0.000010
2.61%
Pepe(PEPE)
€0.000009
3.53%
Nach oben scrollen