Security Architecture, Endpoint/Device Security, Endpoint/Device Security, Threat Management, Threat Management, Malware, Endpoint/Device Security, Endpoint/Device Security, Endpoint/Device Security

Holy cybercrime, Batman! Joker malware commits ad fraud, data theft

Two dozen apps that collectively generated over 472,000 downloads from the Google Play store were found to be infected with a new Android malware called Joker, which delivers a payload that perpetrates both ad fraud and data theft, a research firm has reported.

Joker's second-stage malware is a .dex (Dalvik Executable) file capable of stealing victims' SMS messages, contact lists and device information. It also secretly interacts with advertisement websites to generate fake clicks as well as sign up infected victims with premium service subscriptions that they didn't ask for, according to CSIS malware analyst Aleksejs Kuprins, writing in his company's tech blog.

The malware requests these unauthorized subscriptions are "by automating the necessary interaction with the premium offer's webpage, entering the operator's offer code, then waiting for a SMS message with a confirmation code and extracting it using regular expressions," Kuprins writes. "Finally, the Joker submits the extracted code to the offer's webpage, in order to authorize the premium subscription.

Kuprins notes that Google was aware of the malicious apps and has been active in extricating the malicious apps from its store, removing all 24 "without any note from us."

Joker only downloads the malicious payload if the infected device contains a SIM card from one of 37 countries coded into the apps. In its post, CSIS identifies the countries as Australia, Austria, Belgium, Brazil, China, Cyprus, Egypt, France, Germany, Ghana, Greece, Honduras, India, Indonesia, Ireland, Italy, Kuwait, Malaysia, Myanmar, Netherlands, Norway, Poland, Portugal, Qatar, Republic of Argentina, Serbia, Singapore, Slovenia, Spain, Sweden, Switzerland, Thailand, Turkey, Ukraine, United Arab Emirates, United Kingdom and the U.S.

Although the U.S. is one of the 37 countries targeted, most of the apps contain additional instructions that prevent the malware from executing in the U.S., and Canada for that matter.

CSIS reports that the core payload is "small and silent," using minimal Java code and generating a limited footprint, all in hopes of avoiding unwanted attention. It receives, code and commands over HTTP, running the code via JavaScript-to-Java callbacks to defend against static analysis.

The malware's code comments and the user interface of its C2 panel are both written in Chinese, an observation that offers a possible clue as to attack attribution.

Bradley Barth

As director of multimedia content strategy at CyberRisk Alliance, Bradley Barth develops content for online conferences, webcasts, podcasts video/multimedia projects — often serving as moderator or host. For nearly six years, he wrote and reported for SC Media as deputy editor and, before that, senior reporter. He was previously a program executive with the tech-focused PR firm Voxus. Past journalistic experience includes stints as business editor at Executive Technology, a staff writer at New York Sportscene and a freelance journalist covering travel and entertainment. In his spare time, Bradley also writes screenplays.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms and Conditions and Privacy Policy.