Sharkbot Malware Swims Back To Google Play To Bite New Victims, Delete These Apps Now

Share:

A nasty bit of Android malware previously lurking on the Google Play Store has returned with additional capabilities. Known as SharkBot, the malware is designed to steal user login credentials, particularly credentials used to access financial applications. The malware has also been found to initiate money transfers directly on compromised devices.

SharkBot abuses accessibility permissions in multiple ways to conduct its malicious undertaking. The malware can steal user credentials by logging text entered into login fields. In the case that a user’s account is protected by SMS two-factor authentication (2FA), SharkBot can bypass this protection by reading SMS messages to steal authentication codes. The malware is also capable of overlaying fake login screens directly over targeted financial apps. The fake login screens appear legitimate but actually steal entered user credentials. Additionally, threat actors can use SharkBot to remotely control infected devices. All of these capabilities are scary enough, but a new version of SharkBot has entered the wild with the further ability to steal user session cookies.

Play Store listings for two apps recently found to include the SharkBotDropper (source: Fox IT)

Threat actors distribute the malware by submitting apps to the Google Play Store that come packaged with a malware dropper utility. Once an unsuspecting user installs one of these apps, the dropper reaches out to a command-and-control (C2) server and downloads the full SharkBot malware payload. Previous versions of the SharkBotDropper abused accessibility services to automatically install the malware payload. However, researchers at Fox IT recently found a new version of the dropper that prompts users to install the malware themselves, falsely informing users that the APK file contains an app update.

The researchers found two apps on the Google Play Store that contain this updated malware dropper: Mister Phone Cleaner and Kylhavy Mobile Security. Between them, the two apps have a total of 60,000 downloads. As of the time of writing, Google appears to have removed the Kylhavy Mobile Security app from the Play Store but hasn’t yet delisted Mister Phone Cleaner. Hopefully, Google will remove the latter app shortly, but removing an app from the Play Store won’t remove it from affected users’ devices. Those with these malicious apps already installed on their devices will need to manually remove the apps themselves.

https://hothardware.com/news/sharkbot-malware-back-google-play-delete-these-apps-now

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
11:46 pm, Jul 8, 2025
weather icon 17°C
L: 15° | H: 19°
broken clouds
Humidity: 61 %
Pressure: 1020 mb
Wind: 3 mph W
Wind Gust: 3 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 71%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:53 am
Sunset: 9:17 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 10:00 pm
weather icon
15° | 19°°C 0.18 mm 18% 7 mph 61 % 1022 mb 0 mm/h
Thu Jul 10 10:00 pm
weather icon
18° | 29°°C 0 mm 0% 9 mph 73 % 1023 mb 0 mm/h
Fri Jul 11 10:00 pm
weather icon
19° | 30°°C 0 mm 0% 8 mph 64 % 1022 mb 0 mm/h
Sat Jul 12 10:00 pm
weather icon
19° | 30°°C 0 mm 0% 10 mph 66 % 1019 mb 0 mm/h
Sun Jul 13 10:00 pm
weather icon
18° | 31°°C 0 mm 0% 9 mph 69 % 1017 mb 0 mm/h
Tomorrow 1:00 am
weather icon
16° | 17°°C 0 mm 0% 3 mph 61 % 1020 mb 0 mm/h
Tomorrow 4:00 am
weather icon
15° | 16°°C 0 mm 0% 3 mph 58 % 1020 mb 0 mm/h
Tomorrow 7:00 am
weather icon
17° | 17°°C 0 mm 0% 5 mph 57 % 1021 mb 0 mm/h
Tomorrow 10:00 am
weather icon
22° | 22°°C 0 mm 0% 5 mph 57 % 1021 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
23° | 23°°C 0 mm 0% 6 mph 55 % 1022 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
25° | 25°°C 0.18 mm 18% 7 mph 45 % 1021 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
25° | 25°°C 0 mm 0% 7 mph 44 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
23° | 23°°C 0 mm 0% 3 mph 53 % 1022 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,901.94
0.78%
Ethereum(ETH)
€2,224.88
2.88%
Tether(USDT)
€0.85
0.01%
XRP(XRP)
€1.96
1.48%
Solana(SOL)
€128.90
2.05%
USDC(USDC)
€0.85
-0.01%
Dogecoin(DOGE)
€0.145726
2.39%
Shiba Inu(SHIB)
€0.000010
2.68%
Pepe(PEPE)
€0.000009
3.63%
Scroll to Top