Cyber Security News

A New Set of Malicious Apps Distributing the Notorious Joker Malware

There have recently been reports that the Google Play Store has become a safe home for trojanized applications distributing Joker malware to the Android devices that are compromised.

A large number of cybercriminals earn their income from fraud in the charge of billing. A number of Trojans are currently known to secretly subscribe users to paid services through mobile devices.

The apps have been continually iterated to find gaps in Google’s app defenses and have managed to slip into the app store unnoticed despite ongoing efforts on the part of Google.

It is common for trojanized apps to impersonate their removed counterparts by appearing as:- 

  • Messaging apps
  • Health trackers
  • PDF scanners

As soon as these applications have been installed, they will request certain permissions to access text messages. Once done, then they make the users subscribe to the premium services and charge them.

Jocker: Text Message Thief

Various Trojan programs in the Trojan.AndroidOS.Jocker family can intercept SMS codes and circumvent anti-fraud resolutions. When trojanized apps are used in order to accomplish their original purposes, the user might not suspect that the apps are malicious.

The Trojan watches whether the program has gone live on Google Play to bypass the vetting process. When the app is stalling at the vetting phase, the malicious payload remains dormant.

There is an endless stream of trojanized apps being removed from the store each and every day, yet there are still new ones continuously flooding it to replace them.

Most Attacked Countries

The most frequently attacked users by Jocker were in Saudi Arabia (21.20%) between January 2021 and March 2022. While among the top countries, Poland ranks second (8.98%), followed by Germany (6.01%).

Here below we have listed the top 10 countries attacked by Joker:-

  • Saudi Arabia (21.20%)
  • Poland (8.98%)
  • Germany (6.01%)
  • Malaysia (5.71%)
  • The United Arab Emirates (5.50%)
  • Switzerland (5.10%)
  • South Africa (4.12%)
  • Austria (3.96%)
  • Russia (3.53%)
  • China (2.91%)

Joker-infected Apps

As of the end of February 2022, Kaspersky had detected Joker infection in three applications, and here they are mentioned below:-

  • Style Message (com.stylelacat.messagearound),
  • Blood Pressure App (blood.maodig.raise.bloodrate.monitorapp.plus.tracker.tool.health)
  • Camera PDF Scanner (com.jiao.hdcam.docscanner)

Subscription trojans have previously appeared on app marketplaces, but this is not the first time we have seen them. For example, an aggressive money-making scheme known as GriftHorse was announced in September 2021 by Zimperium.

Although it is advisable to download apps through official app stores, it is also recommended to review the following checks:-

  • Read the reviews
  • Check the legitimacy of the developers
  • Terms of use
  • Permissions requested

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago