Mandrake Spyware Returns: Hidden in Google Play Apps for Two Years, Evading Detection
by duytol - Tuesday July 30, 2024 at 03:06 PM
#1
A new variant of the Mandrake spyware has been discovered on Google Play, hiding in legitimate-looking apps related to cryptocurrency, astronomy, and utility tools. This spyware has been active since 2016, with its latest version evading detection through advanced obfuscation and evasion techniques.

Mandrake was found in five applications, which were available on Google Play from 2022 to 2024, amassing over 32,000 downloads. The apps were downloaded primarily in countries like Canada, Germany, Italy, Mexico, Spain, Peru, and the UK. The spyware uses a complex multi-stage infection process involving native libraries to bypass Google Play's security checks. It requests permissions for activities such as screen recording, data collection, and command execution, allowing it to perform various malicious actions on infected devices.

The spyware's evasion techniques include using obfuscated native libraries, certificate pinning for secure communication, and extensive checks to detect if it's running on a rooted device or within an emulated environment. The malware can also mimic Google Play notifications to trick users into installing additional malicious APKs.

Although the identified malicious apps have been removed from Google Play, the threat remains, and users are advised to install apps only from reputable publishers, check user reviews, and avoid granting unnecessary permissions. Google Play Protect has been enhanced to combat such threats, providing automatic protection against known malware versions.

For more details, you can refer to the articles on The Hacker News, IT-Online, and Bleeping Computer.
Reply
#2
Oh well time to never ever install an app again :/
Reply
#3
And yet, the original spyware still remains: Google Play.
Reply
#4
Google Play is a spyware itself, as mentioned above. The telemetry volume of this app is crazy
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Corruptiion of PLN [Indonesia] - 2025 Investigation Viral LordZeroDay 26 2,128 7 hours ago
Last Post: sang_seniman
  gaming omgijkl 0 68 9 hours ago
Last Post: omgijkl
  Technical Analysis: CVE-2026-41940 – cPanel/WHM Authentication Bypass Tr28 0 269 May 11, 2026, 10:52 PM
Last Post: Tr28
  Zara data breach exposed personal information of 197,000 people namenonamen 2 225 May 11, 2026, 07:49 PM
Last Post: skipqer
  CYBERSECURITY GUIDE: UNDERSTANDING THE PAN-OS VULNERABILITY (CVE-2026-0300) Tr28 0 183 May 11, 2026, 11:54 AM
Last Post: Tr28

Forum Jump:


 Users browsing this forum: 1 Guest(s)