Close Menu
CrafficCraffic
  • Home
  • News
    • Internet
    • Gaming
  • Tech
    • Hardware
    • Gaming Tech
    • Mobile Phones
    • Software
  • Science
    • Astronomy
    • Discoveries
    • Psychology
  • Entertainment
    • Anime
    • Reviews
    • Spotlight
    • WWE
Facebook X (Twitter) Instagram
CrafficCraffic
  • Home
  • News
    • Internet
    • Gaming
  • Tech
    • Hardware
    • Gaming Tech
    • Mobile Phones
    • Software
  • Science
    • Astronomy
    • Discoveries
    • Psychology
  • Entertainment
    • Anime
    • Reviews
    • Spotlight
    • WWE
Facebook X (Twitter) Instagram
CrafficCraffic
Home » Google Play Store removes 11 Joker malware-infected apps; uninstall them now.
Internet

Google Play Store removes 11 Joker malware-infected apps; uninstall them now.

Rahul BhardwajBy Rahul BhardwajJuly 11, 2020Updated:July 11, 20201 Comment3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Joker malware on play store
Share
Facebook Twitter LinkedIn Pinterest Email

At the end of last year, we saw the Joker malware surface and spread like a wildfire. A new variant of the Joker Dropper and Premium Dialer spyware in the Google Play Store has been discovered in the recent report from the Check Point researchers. They were found hiding inside seemingly legitimate applications. This new updated Joker malware can download additional malware to the user, which in effect subscribes to a number of premium services without their consent.

Infected Apps

Meanwhile, Google has pulled 11 devices from the Play Store that have been compromised with the infamous Joker malware. Applications include

Infected apps in play store 1

com.imagecompress.android, com.relax.relaxation.androidsms, com.cheery.message.sendsms (two separate instances), com.peason.lovinglovemessage, com.contact.withme.texts, com.hmvoice.friendsms, com.file.recovefiles, com. LPlocker.lockapps, com.remindme.alram, com.training.memorygame

Joker malware: everything you should know

Researchers have said that with small changes to its code, the Joker malware will get past the Play Store’s security and check barriers. This time along the Joker malware has adopted an old technique from the conventional PC threat landscape to avoid Google detection. The newly modified Joker virus uses two main components to subscribe to premium services for users of apps. The following components are: Notification Listener service and dynamic dex file loaded from the C&C server.

To minimize the code of the Joker, the developer hid the code by dynamically loading it to the dex file, while at the same time, ensuring that it was fully loaded when it was triggered. The code within the dex file is encoded as Base64 encoded strings, which start decoding and loading as soon as the victim opens the affected apps.

The original Joker malware communicated with C&C, and then downloaded the dynamic dex file that was loaded as casses.dex. However, the new modified version of the code is embedded in another zone, with the classes.dex file loading a new payload. The malware is triggered by the creation of a new object that communicates with C&C.

How to Fix it

Since the payload is encoded in Base 64 strings, the only thing the actor had to do to conceal the file was to set the C&C server to return “false” to the status code if the tests were running.

Joker malware on Play Store

Check all of your software carefully and see if they’re from a non-trusted developer. When you feel like you have downloaded an infected file, you can delete it immediately. You should check your mobile and credit card bills for any problems. If you have any conversation with the bank and unsubscribe from these charges. Finally , it is recommended that users install an antivirus software on their smartphones to avoid infections.

Internet Malware
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleCAPCOM Reveals It’s Digital Sales Percentage
Next Article Sony invests $250 million in ‘Fortnite’ developer Epic Games
Rahul Bhardwaj

Related Posts

Internet

Is Facebook Marketplace Safe For You?

February 2, 2022
Internet

Telegram adds new Features which makes it better than Whatsapp

January 5, 2022
Internet

Reddit files to lay hold of the firm public

December 16, 2021
View 1 Comment

1 Comment

  1. Pingback: BlackRock: Android Malware - Craffic

Leave A Reply Cancel Reply

At Craffic we ensure delivering quality content to our readers as they are giving us their precious time to engage with our content. And Craffic was a vision of a group of school friends and they've made it possible by learning the basics of strategies used in the media culture. ‎ ‎ ‎‎ ‎ ‎

Quick Access
  • About Us
  • Contact us
  • Terms of Use
  • Privacy Policy
Facebook X (Twitter) Instagram Pinterest
© 2025 Craffic. Designed by StackX Solutions.

Type above and press Enter to search. Press Esc to cancel.