Malicious ad library SDK spotted in 800 Android apps.
Malicious ad library SDK spotted in 800 Android apps.

Trend Micro researchers spotted more than 800 Android applications available on the Google Play Store embedded with the software development kit (SDK) of the information-stealing ad library dubbed “Xavier.”

The trojan is designed to steal and leak a user's information silently and so far has been downloaded millions of times, according to a June 13 blog post. So far, approximately 75 apps have since removed the trojan from their code.

The majority of downloads came from countries in Southeast Asia such as Vietnam 23.27 percent, Philippines 19.14 percent , and Indonesia 8.23 percent, with fewer downloads from the U.S. and Europe.

Unique features of the trojan include its embedded malicious behavior that downloads codes from a remote server and the great lengths to it goes to protect itself from being detected through the use of methods such as String encryption, Internet data encryption, and emulator detection, researchers said in the post.

Xavier is difficult to detect because of a self-protect mechanism that allows it to escape both static and dynamic analysis and also uses encryption, Internet data encryption, and emulator detection. The trojan also has the ability to download and execute other malicious codes making it even more dangerous.

The malware family has been around for more than two years and is a member of the AdDown family. The latest version has since evolved to use a more timed code structure, remove APK installation, remove root check, encryption data with TEA and added mechanism to escape dynamic detection

 Researchers said the best way to avoid infection of malware hiding in trusted sources, such as Google Play, is to pay attention to the reviews and not download or install applications from unknown sources.