Download more than 620000 times, Google Play Mall found a new Fleckpe malicious subscription application
CTOnews.com May 5 news, Kaspersky said in a recent report, in Google Play Store, found a new type of malware called "Fleckpe". It disguises as a legitimate application and has been downloaded more than 620000 times.
Kaspersky says Fleckpe is mainly aimed at subscribers and makes a profit by charging monthly or one-time subscription fees. Kaspersky says the malware dates back to last year.
Kaspersky found 11 Fleckpe Trojan applications on Google Play, posing as image editors, photo libraries, advanced wallpapers, etc., with the following names attached to CTOnews.com:
Com.impressionism.prozs.app
Com.picture.pictureframe
Com.beauty.slimming.pro
Com.beauty.camera.plus.photoeditor
Com.microclip.vodeoeditor
Com.gif.camera.editor
Com.apps.camera.photos
Com.toolbox.photoeditor
Com.hd.h4ks.wallpaper
Com.draw.graffiti
Com.urox.opixe.nightcamreapro
After the user installs these applications, the malicious application requests access to the notification content to capture subscription confirmation codes for many advanced services.
This payload is responsible for contacting the threat actor's command and control (C2) server to send basic information about newly infected devices, including MCC (mobile country code) and MNC (mobile network code).
C2 responds with a website address, which the Trojan opens in an invisible Web browser window and subscribes to a paid service for the victim.