Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Mobile

10/24/2019
02:45 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

Apple Boots 17 Trojan-Laden Apps From Mobile Store

Malware was designed to carry out click-fraud, Wandera says.

Apple has removed 17 mobile apps from its App Store after a security vendor reported them as infected with malware.

But an unknown number of people who downloaded the free apps continue to be at risk of having their devices being used to quietly carry out ad-fraud related tasks such as continuously clicking on links or opening Web pages without any action on their part.

In a report Thursday, Wandera described the 17 malicious apps it found as containing clicker Trojan malware designed to generate revenues for their developer by fraudulently inflating traffic on pay-per-click websites. An attacker can also use such malware to drain the budgets of rival websites by artificially inflating the amount they owe to an ad network, Wandera said.

The apps were found receiving instructions from a known command-and-control server. Commands from the C2 server included those that could silently load websites, deliver targeted advertising, remotely reconfigure infected devices, and sign up users for expensive services without their knowledge.

The list of infected free apps, which Wandera has published on its website, included productivity, travel, platform utility, restaurant finder, and video-editing apps from India-based AppAspect Technologies. The developer currently appears to have at least 51 apps on Apple's App Store, of which 35 are free.

Michael Covington, vice president of product at Wandera, says the company only tested the free apps. So it is unclear if AppAspect's paid products are similarly infected.

Apple, unlike Google, does not provide any information on download numbers for apps on App Store. As a result, it's hard to determine with any certainty how many people might have downloaded the infected AppAspect software, Covington says. But based on how the India-based developer's Android versions of the same apps have performed, it is safe to assume that a significant number of iOS users have been impacted, he notes.

Wandera discovered nine AppAspect apps for Android on Google's Play Store that are counterparts of the iOS versions. Those apps have nearly 1.1 million installs in total. "Because the developer seems to have spent more time developing on the Apple App Store — with 51 apps on the App Store versus 28 on Google Play — we assume their iOS apps reach even more users," Covington says.

None of the 28 Android apps that AppAspect has on Google's Play Store currently appear infected. However, some of the apps were previously reported as malicious and removed. The developer appears to have uploaded the again to Play without the malware, Wandera said.

Bypassing Security Controls

Both Apple and Google have implemented substantial measures over the years to quickly identify and remove rogue apps from their mobile app stores. Their respective stores continue to be by far the safest location for users to download Android and iOS apps. But the sheer volume of apps being uploaded to these stores and the ingenuity of some developers has resulted in malicious apps frequently getting uploaded anyway.

In Apple's case, the company's app review process is designed more to ensure that iOS apps meet optimal usability and performance standards, Covington says. 

Apple also verifies that developer's API calls as intentioned and often rejects developers that violate the company's rules for how an app should run.

"We believe these [AppAspect] apps bypassed the Apple vetting process because the Trojan developer didn't put any "bad" code directly into the app," Covington notes. "Instead, the [apps were] configured to obtain commands and additional payloads directly from the C&C server, which is outside of Apple's review purview."

Related Content:

This free, all-day online conference offers a look at the latest tools, strategies, and best practices for protecting your organization’s most sensitive data. Click for more information and, to register, here.

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 6/1/2020
Stay-at-Home Orders Coincide With Massive DNS Surge
Robert Lemos, Contributing Writer,  5/27/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: "Well I dont run on MacOS, so I need to take extra precautions"
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-13659
PUBLISHED: 2020-06-02
address_space_map in exec.c in QEMU 4.2.0 can trigger a NULL pointer dereference related to BounceBuffer.
CVE-2020-10703
PUBLISHED: 2020-06-02
A NULL pointer dereference was found in the libvirt API responsible introduced in upstream version 3.10.0, and fixed in libvirt 6.0.0, for fetching a storage pool based on its target path. In more detail, this flaw affects storage pools created without a target path such as network-based pools like ...
CVE-2020-10739
PUBLISHED: 2020-06-02
Istio 1.4.x before 1.4.9 and Istio 1.5.x before 1.5.4 contain the following vulnerability when telemetry v2 is enabled: by sending a specially crafted packet, an attacker could trigger a Null Pointer Exception resulting in a Denial of Service. This could be sent to the ingress gateway or a sidecar, ...
CVE-2020-10136
PUBLISHED: 2020-06-02
Multiple products that implement the IP Encapsulation within IP standard (RFC 2003, STD 1) decapsulate and route IP-in-IP traffic without any validation, which could allow an unauthenticated remote attacker to route arbitrary traffic via an exposed network interface and lead to spoofing, access cont...
CVE-2020-13757
PUBLISHED: 2020-06-01
Python-RSA 4.0 ignores leading '\0' bytes during decryption of ciphertext. This could conceivably have a security-relevant impact, e.g., by helping an attacker to infer that an application uses Python-RSA, or if the length of accepted ciphertext affects application behavior (such as by causing exces...