Application security, Malware

More payloads distributed through Android dropper apps

Powered by Android operating system OS software logo icon on a smartphone tablet mobile phone device display screen macro, extreme closeup detail, nobody Android apps

Illicit actors have begun utilizing dropper apps to deploy SMS stealers and spyware payloads in addition to banking trojans following Google's measures to prevent app sideloading in select countries, The Hacker News reports.

Attacks involving the RewardDropMiner dropper involved the distribution of malicious apps impersonating Indian and other Asian banking or government tools that facilitated spyware and Monero cryptominer distribution without triggering Google Play Protect's defenses, according to an analysis from ThreatFabric. Similar evasion of Google Protect is also possible with the BrokewellDropper, HiddenCatDropper, SecuriDropper, TiramisuDropper, and Zombinder dropper variants. "By encapsulating even basic payloads inside a dropper, they gain a protective shell that can evade today's checks while staying flexible enough to swap payloads and pivot campaigns tomorrow," said ThreatFabric researchers. Such findings follow a Bitdefender Labs report detailing the deployment of an updated Brokewell banking trojan through a purportedly freemium version of the TradingView app promoted in nefarious Facebook ads.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds