• About
  • Advertise
  • Privacy Policy
  • Contact
Android Kenya
  • Home
  • News
  • Apps
  • Gadgets
  • Reviews
  • Deals
  • How To
  • Knowledge Base
No Result
View All Result
  • Home
  • News
  • Apps
  • Gadgets
  • Reviews
  • Deals
  • How To
  • Knowledge Base
No Result
View All Result
Android Kenya
No Result
View All Result
Home News

Watch out for Xenomorph, the latest malware in the Play Store

Naftaly Kariuki by Naftaly Kariuki
March 3, 2022
in News
0
Android devices victims of preinstalled malware, new report shows
FacebookTwitterWhatsApp

The Android ecosystem being open source is a double-edged sword for both developers and users. While it does not restrict developers’ visions in bringing out their creative work in terms of developing applications that add value to people’s lives, you also get hackers whose only aim is to spam users or swindle them out of their money through various schemes.

Google tries its best to sniff out these malware-ridden apps from the Play Store, but there are a few of them that manage to slip through the cracks and are only discovered after they have caused some damage.

The latest of this malware, dubbed Xenomorph has been brought to light by ThreatFabric who also gave it its name as it has ties to another trojan called Alien.

ThreatFabric reports that the trojan has already infected users of 56 different banks in Europe, as well as having more than 50,000 installations on the Google Play Store. There is the possibility of the number of banks that have been affected being higher, as the ThreatFabric team focused on European banks.

To trick unsuspecting users into downloading the trojan, Xenomorph posed as a “Fast Cleaner” application. These kinds of applications aim to improve the speed of devices by removing unused clutter as well as removing battery optimization blocks. But rather than cleaning your phone, the app acted as a gateway to feed a user’s data to the malware.

In their investigations, Threat Fabric found out that the Xenomorph banking trojan is from the Gymdrop dropper family, which is the same dropper family that they discovered delivering a trojan dubbed Alien back in November 2021.

READ:  Google Authenticator codes now sync across devices

A dropper is basically a small helper program that facilitates the delivery and installation of malware. They are normally used by malicious people to evade the signatures that antivirus programs use to block or quarantine malicious code.

Xenomorph using the Fast Cleaner app can then use the information it has gathered from your device to gain access to your login credentials for online banking apps. Once it has gathered information that you have a particular banking app on your phone, it will generate an overlay that is very similar to that of the banking app.

If you are not keen, you might think that you are working with the original app, while you are instead providing login credentials and other personal information to the trojan. The trojan will then use the information it has swindled from you to login into the real banking app and wipe your account clean.

ThreatFabric concludes their report by saying the Xenomorph trojan is still in its infancy stage as there are a lot of commands that have been found in the code, but they have not yet been implemented. Should these commands see the light of day, this particular trojan has the potential to be more devastating in terms of the number of platforms it can mimic, and the different ways it can use to scam people.

As always, to keep yourself safe online, only download apps that you really need, read the reviews and only download apps from trusted app stores.

Join our Telegram channel
Previous Post

realme 9i starts selling in Kenya

Next Post

Nokia at MWC 2022: Meet the brand’s 3 new entry-level Android Go smartphones

Related Posts

Xiaomi Mi Home store kenya
News

CA report reveals how your Android phone and smart home gadgets are opening doors for cyber attacks

January 16, 2025
CAK-Kenya
News

CA’s Q3 2024 cybersecurity report warns of surge in Android malware threats

January 16, 2025
Safaricom-CEO-Ndegwa
News

Safaricom awarded top certification in privacy information management amid data-sharing allegations

January 16, 2025
Next Post
Nokia at MWC 2022: Meet the brand’s 3 new entry-level Android Go smartphones

Nokia at MWC 2022: Meet the brand's 3 new entry-level Android Go smartphones

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Subscribe to our newsletter

  • Trending
  • Comments
  • Latest
Kenya-Power

Kenya Power’s MyPower app gets a major upgrade

January 16, 2025

Oppo A60 review: Rugged darling

June 10, 2024
Oppo Reno8 T review: High praise

Oppo Reno8 T review: High praise

February 28, 2023
Samsung Galaxy S26 series

Rumoured Samsung Galaxy S27 Pro Could Render the Plus Useless

April 6, 2026
Samsung Galaxy S26 series

Rumoured Samsung Galaxy S27 Pro Could Render the Plus Useless

0
BREAKING: Samsung Announces Galaxy S26 Series

Samsung Adds AirDrop Support to Select Galaxy Devices

0
Nothing Phone 4a Pro

Nothing Phone 4a Pro Breaks Cover With Its Most Striking Design Yet

0
WhatsApp Working on Premium Subscription Plan Called WhatsApp Plus

WhatsApp Working on Premium Subscription Plan Called WhatsApp Plus

0
Samsung Galaxy S26 series

Rumoured Samsung Galaxy S27 Pro Could Render the Plus Useless

April 6, 2026
BREAKING: Samsung Announces Galaxy S26 Series

Samsung Adds AirDrop Support to Select Galaxy Devices

March 23, 2026
Nothing Phone 4a Pro

Nothing Phone 4a Pro Breaks Cover With Its Most Striking Design Yet

March 5, 2026
WhatsApp Working on Premium Subscription Plan Called WhatsApp Plus

WhatsApp Working on Premium Subscription Plan Called WhatsApp Plus

March 5, 2026
  • About
  • Advertise
  • Privacy Policy
  • Contact

© 2025 Android Kenya

No Result
View All Result

© 2025 Android Kenya