Technology

#Researcher discovered new app malware on Google Play that steals your money

“Researcher discovered new app malware on Google Play that steals your money”

Maxime Ingrao, security researcher at cybersecurity company Evina, has discovered a new malware family that can infect Android apps on Google Play.

It’s named Autolycos — from the homonymous Greek mythological figure, known for his mastery in thievery and deceit. And that’s exactly what the malware does.

Since June 2021, Ingrao has identified eight infected apps on Play Store — downloaded over three million times.

How does Autolycos work?

Greetings, tech nerd!

Are you into gadgets? And apps? And other cool tech stuff? Then this weekly newsletter is for you.

According to Evina’s report, the main goals of Autolycos is to subscribe users to premium Direct Carrier Billing (DCB) services, without their knowledge or consent.

Unlike the Joker malware that launches an invisible browser and uses Webview, Autolycus launches fraud attempts by executing http requests without using a browser.

For some steps, it can execute the urls on a remote browser and embed the results in the http requests.

Here’s how Autolycos is able to access a verification PIN code by reading a phone’s notifications:

Autolycos malware
Close

Please allow ads on our site

Please consider supporting us by disabling your ad blocker!