Podec Trojan Can Trick CAPTCHA Into Thinking It Is Human

Long-heralded as the main avenue of protection against cybercriminals trying to steal personal details, it seems that CAPTCHA security systems may not be a reliable failsafe after all.

Kaspersky Labs has uncovered evidence of a Trojan that has developed a technique to convince CAPTCHA it is a person in order to subscribe thousands of infected Android users to premium-rate services.

Called Podec, it has so far mainly been seen in Russia, targeting Android device users primarily through the country’s popular social network, VKontakte, and signing them up to premium-rate services.

Crafty

First detected in late 2014 and updated since then, Podec automatically forwards CAPTCHA requests to a real-time online human translation service that converts the image to text. The service, Antigate.com, uses image-to-text recognition software to recognise the CAPTCHA text in a matter of second, with the details then relayed back to the malware code to proceed with its execution.

Users are first drawn in to Podec by downloading supposedly cracked versions of popular computer games such as Minecraft Pocket Edition, which appear on Vkontake group pages.

Upon infection, the malware requests administrator privileges that, once granted, make it impossible to delete or halt the execution of the malware. Podec is also able to protect itself from detection using obfuscation and an “expensive legitimate code protector” to prevent any analysis of its code.

Podec can also bypass the Advice on Charge system, which notifies users about the price of a service and requires authorisation before payment.

“Podec marks a new and dangerous phase in the evolution of mobile malware. It is devious and sophisticated,” said Victor Chebyshev, non-intel research group manager at Kaspersky Lab.

“The social engineering tools used in its distribution, the commercial-grade protector used to conceal the malicious code and the complicated process of extortion achieved by passing the CAPTCHA test – all lead us to suspect that this Trojan is being developed by a team of Android developers specialising in fraud and illegal monetisation. It is clear that Podec is being further developed, possibly with new targets and goals in mind and we urge users to be wary of links and offers that sound too good to be true.”

Are you a security pro? Try our quiz!

Mike Moore

Michael Moore joined TechWeek Europe in January 2014 as a trainee before graduating to Reporter later that year. He covers a wide range of topics, including but not limited to mobile devices, wearable tech, the Internet of Things, and financial technology.

Recent Posts

Russia Accused Of Cyberattack On Germany’s Ruling Party, Defence Firms

German foreign minister warns Russia will face consequences for “absolutely intolerable” cyberattack on ruling party,…

18 hours ago

Alphabet Axes Hundreds Of Staff From ‘Core’ Organisation

Google is reportedly laying off at least 200 staff from its “Core” organisation, including key…

19 hours ago

Apple Announces Record Share Buyback, Amid iPhone Sales Decline

Investor appeasement? Apple unveils huge $110 billion share buyback program, as sales of iPhone decline…

23 hours ago

Tesla Backs Away From Gigacasting Manufacturing – Report

Tesla retreats from pioneering gigacasting manufacturing process, amid cost cutting and challenges at EV giant

2 days ago

US Urges No AI Control Of Nuclear Weapons

No skynet please. After the US, UK and France pledge human only control of nuclear…

2 days ago