App Eating Android Malware Infects 100,000 Chinese Phones

A piece of fresh Android malware has been spotted sneakily buying up apps and giving thouasnds of Chinese users some big bill shocks.

Security firm TrustGo said 100,000 devices were infected with MMarketPay.A, which has been found disguised as several real applications, including one purportedly from Weibo, the Chinese version of Twitter. It has managed to get itself on to nine different third-party Android markets too

Its main aim when it gets onto an unsuspected phone is to surreptitiously buy up apps on China Mobile’s Mobile Market.

Dude, where’s my money?

MMarketPay.A silently replicates the process of purchasing apps from the Mobile Market. When doing so, it intercepts the verification code sent by Mobile Market servers when a purchase is requested. If a CAPTCHA crops up looking for human input, it is referred to a remote server for the attackers to get around it. Then the app is downloaded and the unwitting user charged.

The Mobile Market also offers paid video content, which the malware can also force victims to pay for.

“This sophisticated new malware could cause unexpected high phone bills,” TrustGo said in a blog post. “TrustGo recommends customers only download apps from trusted app stores and download a mobile security app which can scan malware in real-time.”

Android remains the most targeted of all mobile operating systems. Just last week, Google denied reports a botnet had infected a portion of its users, although two security researchers still believed the malicious network was built on malware that was resident on Android devices.

A US researcher also created a rootkit that could hide Android apps and upload fake ones to steal people’s data.

Are you a security boff? Try our quiz!

Thomas Brewster

Tom Brewster is TechWeek Europe's Security Correspondent. He has also been named BT Information Security Journalist of the Year in 2012 and 2013.

Recent Posts

Apple Slashes iPhone Prices In China

Amid intense competition from Huawei and others, Apple has again slashed the price of its…

8 hours ago

Bitcoin ‘Creator’ Craig Wright Repeatedly Lied, Rules UK Judge

Damning ruling by British judge, after he rules that self-proclaimed bitcoin inventor lied 'repeatedly' to…

8 hours ago

Julian Assange Granted Right To Challenge US Extradiction Order

High Court rules Wikileaks founder Julian Assange can appeal against extradition to the US, despite…

10 hours ago

Tesla Layoffs Continue With Another 600 Jobs In California

Regulatory filing last week shows Elon Musk's Tesla is cutting another 600 jobs in California,…

11 hours ago

UK Regulator Declines To Investigate Microsoft’s Mistral AI Deal

Weeks after seeking feedback on Microsoft's partnership with Mistral AI, UK regulator says it does…

14 hours ago

UK AI Safety Institute To Open Office In US

Seeking collaboration on AI regulation, UK's AI Safety Institute to cross Atlantic and will open…

15 hours ago