New Android Trojan Masquerades Google Play Store App
Cisco Talos researchers said that the trojan seems to be in the final stages of testing. This trojan is using the Xamarin environment for mobile applications.
Researchers at Cisco Talos have discovered a new trojan that labels "Google Play Marketplace" and icon is looking same as Google play store app.
The researchers observed that the trojan is having almost all the access from the installed android device. It has the capability to load plugins from another source and injects the new .NET code in the device.
Every mobile user should be aware of these kinds of issues. This Trojan loads the Malicious Scripts at the runtime and gives reverse connection to the attacker. When it is activated, the trojan starts executing the multiple tasks will try to establish a connection to the attacker by its own commands.
HIGHLIGHTS
The Trojan is said to be extremely Powerful
Its "design of code and execution" an uncommonly high level because of run-time loading the scripts".
This is done by requesting all privileges on the device and asks the user to allow the trojan in device setting. Cisco Talos researchers said that the trojan seems to be in the final stages of testing. This trojan is using the Xamarin environment for mobile applications. The main DLL with the name "Reznov.DLL." and it has one root class called "eClient," which is the main class of the Trojan. The second DLL called 'eCommon.DLL, the "eCommon" file contains support code and structures. Its code is platform independent.
Manish Kumawat, director, Cryptus Cyber Security Pvt Ltd, an organisation that provides Cyber Security Services, Corporate Trainings to the government and private organizations, said that a new android mobile trojan has discovered that masquerades the Google Play Store app, when the Trojan installed in the android device its name will be shown ‘Google Play Marketplace’ and icon is looking same as Google Play Store.
Almost all Mobile Trojans can access users confidential information from the android device like users geo locations, keystrokes, stored credit card details in the browsers, phone calls recording, and many more. On the internet, there are millions of websites which are having trojans in their website to infect users mobile device so that they can access confidential information. Users should not visit a malicious website on the internet.