Skip to content
General

Scary Android malware targets hundreds of popular apps

By Maria Santos
3 min read
Android Updates
Android Updates
In this article (5)

Another day, another major Android threat discovered by security researchers as it lurks in the shadows in anticipation of its time in the mischievous limelight. In a way, this BlackRock malware detected and rigorously documented by the folks over at ThreatFabric can be considered even scarier and more dangerous than the Joker virus that made headlines recently or other similar security vulnerabilities found to stem from largely shady apps in the past.

That’s because BlackRock was exposed as targeting a long list of reputable and crazy popular Android apps, including everything from PayPal to Gmail, Yahoo Mail, Uber, Netflix, eBay, Amazon, Telegram, WhatsApp, Twitter, Snapchat, Skype, Instagram, Facebook, YouTube, Reddit, TikTok, Tumblr, Pinterest, Tinder, Grindr, and even Google’s own Play Store. In total, we’re talking no less than 337 potential victims.

For many people, that might be pretty much everything they use on their mobile devices on a regular basis, so obviously, the solution to this problem is not to delete all these apps and seek less popular alternatives. Instead, you should merely be careful about what you install and especially where you install your apps and updates from.

As you can imagine, the aforementioned apps, social networking, communication, and dating services are not dangerous by themselves, rather being targeted precisely due to their worldwide success and mass appeal by a banking Trojan that hasn’t managed to slip through Google’s Play Store filters yet.

In other words, you have nothing to worry about, at least as far as this particular virus is concerned, if you download everything from an official source. The danger surfaces when you’re prompted to install “Google updates” from third-party sources, which is a massive red flag.

Unfortunately, it’s not entirely clear what you can do to clean your phone of the BlackRock malware if you fall prey to such a vicious and insidious attack that will quickly spread across your system without leaving a trace. That’s because the Trojan will prevent most antivirus programs from starting in addition to phishing everything from your financial information to social media usernames and passwords.

That’s because the Trojan will prevent most antivirus programs from starting in addition to phishing everything from your financial information to social media usernames and passwords.

Naturally, the main goal is to steal credit card details, but various app credentials will also do for the bad actors behind BlackRock, and you can expect your text messages to be hijacked as well.

While far from new or innovative at its core, this chilling banking Trojan does a few things differently from its forerunners, dubbed LokiBot, MysteryBot, Parasite, and Xerxes. Instead of adding new features and increasing its complexity, which is usually the case in this dark and malevolent world, BlackRock is actually keeping things simpler than ever, with a focus on the most “useful” functions in terms of stealing personal information.

What is expanded compared to previous banking malware is the target list, with an unusually high number of “trending” social and dating apps joining the typical group of financial services from institutions located in the US, as well as Australia, Canada, and various European countries.

Basically, BlackRock is casting a wider net than any of its predecessors, making sure pretty much no one that uses an Android phone nowadays is safe, no matter where you live, what device you use, how you like to connect with friends and make new ones, or what online banking channel you prefer.

Still, the simplest, safest, and most foolproof way to stay protected from this type of threat remains to never rely on a third-party app store, as well as install a reliable antivirus solution before suspecting a cyberattack, and periodically check your app permissions, as well as your credit card statements for any unauthorized or shady transactions.

Questions & Answers

Q.

What kind of information does the BlackRock malware attempt to steal from users?

A.

The malware primarily aims to steal credit card details. It also targets financial information, social media usernames and passwords, various app credentials, and can hijack text messages from a user's device.

Q.

How can Android users protect themselves from being infected by the BlackRock malware?

A.

Users should only install apps and updates from official sources like the Google Play Store, avoiding third-party installations. It is also advised to use a reliable antivirus solution and regularly check app permissions and credit card statements.

Q.

How does BlackRock differ from previous banking Trojans mentioned in the article?

A.

Unlike its predecessors, BlackRock simplifies its functions, focusing on essential information theft rather than increasing complexity. Its key difference is a significantly expanded target list, including many social and dating apps alongside financial services.

Q.

What indicates a user might be installing the BlackRock malware instead of a legitimate update?

A.

A major warning sign is being prompted to install 'Google updates' from third-party sources. The malware has not managed to get through Google's Play Store filters, so official downloads are safe from this particular threat.

Reader pulse

How concerned are you about this Android threat?

16,372 votes so far

Weekly Briefing

Asia's retail intelligence, in your inbox

Tuesday, Thursday and a Saturday Weekly Wrap: the retail stories, numbers and moves that mattered across Asia. Nothing else, and you can unsubscribe in one click.

  • Top industry moves and market shifts
  • Weekly data-driven analysis from across Asia
  • Tuesday, Thursday and the Saturday Weekly Wrap

Read by retail operators, investors and brand teams across Asia.

Protected by a quick human check. No spam, ever. Unsubscribe in one click.

SecureGDPR ready