• About
  • Advertise
  • Privacy Policy
  • Contact
Android Kenya
  • Home
  • News
  • Apps
  • Gadgets
  • Reviews
  • Deals
  • How To
  • Knowledge Base
No Result
View All Result
  • Home
  • News
  • Apps
  • Gadgets
  • Reviews
  • Deals
  • How To
  • Knowledge Base
No Result
View All Result
Android Kenya
No Result
View All Result
Home News

Watch out for Xenomorph, the latest malware in the Play Store

Naftaly Kariuki by Naftaly Kariuki
March 3, 2022
in News
0
Android devices victims of preinstalled malware, new report shows
FacebookTwitterWhatsApp

The Android ecosystem being open source is a double-edged sword for both developers and users. While it does not restrict developers’ visions in bringing out their creative work in terms of developing applications that add value to people’s lives, you also get hackers whose only aim is to spam users or swindle them out of their money through various schemes.

Google tries its best to sniff out these malware-ridden apps from the Play Store, but there are a few of them that manage to slip through the cracks and are only discovered after they have caused some damage.

The latest of this malware, dubbed Xenomorph has been brought to light by ThreatFabric who also gave it its name as it has ties to another trojan called Alien.

ThreatFabric reports that the trojan has already infected users of 56 different banks in Europe, as well as having more than 50,000 installations on the Google Play Store. There is the possibility of the number of banks that have been affected being higher, as the ThreatFabric team focused on European banks.

To trick unsuspecting users into downloading the trojan, Xenomorph posed as a “Fast Cleaner” application. These kinds of applications aim to improve the speed of devices by removing unused clutter as well as removing battery optimization blocks. But rather than cleaning your phone, the app acted as a gateway to feed a user’s data to the malware.

In their investigations, Threat Fabric found out that the Xenomorph banking trojan is from the Gymdrop dropper family, which is the same dropper family that they discovered delivering a trojan dubbed Alien back in November 2021.

READ:  Safaricom launches 5G Wi-Fi after nearly 2 years of 5G network trials

A dropper is basically a small helper program that facilitates the delivery and installation of malware. They are normally used by malicious people to evade the signatures that antivirus programs use to block or quarantine malicious code.

Xenomorph using the Fast Cleaner app can then use the information it has gathered from your device to gain access to your login credentials for online banking apps. Once it has gathered information that you have a particular banking app on your phone, it will generate an overlay that is very similar to that of the banking app.

If you are not keen, you might think that you are working with the original app, while you are instead providing login credentials and other personal information to the trojan. The trojan will then use the information it has swindled from you to login into the real banking app and wipe your account clean.

ThreatFabric concludes their report by saying the Xenomorph trojan is still in its infancy stage as there are a lot of commands that have been found in the code, but they have not yet been implemented. Should these commands see the light of day, this particular trojan has the potential to be more devastating in terms of the number of platforms it can mimic, and the different ways it can use to scam people.

As always, to keep yourself safe online, only download apps that you really need, read the reviews and only download apps from trusted app stores.

Join our Telegram channel
Previous Post

realme 9i starts selling in Kenya

Next Post

Nokia at MWC 2022: Meet the brand’s 3 new entry-level Android Go smartphones

Related Posts

Xiaomi Mi Home store kenya
News

CA report reveals how your Android phone and smart home gadgets are opening doors for cyber attacks

January 16, 2025
CAK-Kenya
News

CA’s Q3 2024 cybersecurity report warns of surge in Android malware threats

January 16, 2025
Safaricom-CEO-Ndegwa
News

Safaricom awarded top certification in privacy information management amid data-sharing allegations

January 16, 2025
Next Post
Nokia at MWC 2022: Meet the brand’s 3 new entry-level Android Go smartphones

Nokia at MWC 2022: Meet the brand's 3 new entry-level Android Go smartphones

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Subscribe to our newsletter

  • Trending
  • Comments
  • Latest
XAI-Grok

Trend of Grok users digitally undressing women on X sparks backlash

May 5, 2025
Redmi-Note-13-4G

Redmi Note 13 series guaranteed 4 years of Android software updates until 2028

January 30, 2024

Oppo A60 review: Rugged darling

June 10, 2024
Airtel-5G-router

Airtel 5G router’s nighttime network issues: Where does my internet go after 6 pm?

January 16, 2025
XAI-Grok

Trend of Grok users digitally undressing women on X sparks backlash

0
Telegram-Android-Kenya

Telegram rolls out encrypted group calls, business automation, and gift upgrades

0
Oppo-A5-Pro-in-Kenya

Here’s the global average selling price of Android phones vs iPhones in Q1 2025

0
Vivo-X200-Pro

Vivo is Android’s revenue champion in Q1 2025, Samsung and Xiaomi hold ground on shipments

0
XAI-Grok

Trend of Grok users digitally undressing women on X sparks backlash

May 5, 2025
Telegram-Android-Kenya

Telegram rolls out encrypted group calls, business automation, and gift upgrades

May 5, 2025
Oppo-A5-Pro-in-Kenya

Here’s the global average selling price of Android phones vs iPhones in Q1 2025

May 5, 2025
Vivo-X200-Pro

Vivo is Android’s revenue champion in Q1 2025, Samsung and Xiaomi hold ground on shipments

May 5, 2025
  • About
  • Advertise
  • Privacy Policy
  • Contact

© 2025 Android Kenya

No Result
View All Result

© 2025 Android Kenya