City
Epaper

Cybercriminals sell malicious Google Play apps for up to $20K using Darknet: Report

By IANS | Updated: April 11, 2023 19:15 IST

New Delhi, April 11 While analysing offers of malicious apps on Google Play for sale on the Darknet, ...

Open in App

New Delhi, April 11 While analysing offers of malicious apps on Google Play for sale on the Darknet, experts have discovered that malicious mobile apps and store developer accounts are being sold for up to $20,000, a new report showed on Tuesday.

Every year a wide range of malicious apps are deleted on Google Play only after victims have been infected. Cybercriminals gather on the Darknet to buy and sell Google Play malicious apps, and additionally functions to upgrade and even advertise their creations, according to the cybersecurity firm Kaspersky.

"On Darknet, we found messages from cybercriminals complaining how it is now much harder for them to upload their malicious apps to official stores. However, this also means that they will now come up with much more sophisticated circumvention schemes, so users should stay alert and carefully check which apps they are downloading," said Alisa Kulishenko, security expert at Kaspersky.

Moreover, the report mentioned, there are various Darknet offers for different needs and customers with different budgets, just like there are legitimate forums for selling goods.

Cybercriminals require a Google Play account and a malicious downloader code (Google Play Loader) to publish a malicious app, while a developer account can be purchased for as little as $200 and sometimes as little as $60.

Malicious loaders range in price from $2,000 to $20,000, depending on the complexity of the malware, the novelty and prevalence of malicious code, and the additional functions.

Most often, the malware being distributed is suggested to be hidden under cryptocurrency trackers, financial apps, QR-code scanners and even dating apps.

The report further said that for an additional fee, cybercriminals can obfuscate the application code, making it more difficult to detect by cybersecurity solutions.

Many attackers offer to buy installs to increase the number of downloads of a malicious app, directing traffic through Google ads and attracting more users to download the app.

Further, the report showed that Darknet sellers can also offer to publish the malicious app for the buyer so they do not directly interact with Google Play, but can still remotely receive all of the victims' detected data.


shs/uk/

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Tags: Alisa kulishenkogoogleKasperskyWord on macWho dgMicrosoft incUs google & youtubeSk duaDan patelBacPrivate institutes
Open in App

Related Stories

TechnologyGoogle Layoffs: Indian Employees in Hyderabad and Bengaluru Likely to Be Affected

CricketIPL 2025: Google Doodle Celebrates Beginning of Indian Premier League Season 18

LifestyleNowruz 2025: Google Doodle Celebrates Persian New Year to Mark Spring Season

TechnologyGoogle Celebrates March 2025 Final Half Moon With Doodle Game, Challenges Users Knowledge About Lunar Cycle

Social ViralNap Time at Work? Google’s Gurugram Office Lets Employees Sleep on the Job (Watch Video)

Technology Realted Stories

Technology75 pc of Indian businesses localise data as AI becomes core to strategy: Report

TechnologyPunjab starts first-of-its-kind B.Tech programme

TechnologyDynamic curriculum, continuous evolution of training modules key to stay relevant: Jitendra Singh

TechnologySEBI reviewing derivatives rules to protect retail investors: Tuhin Kanta Pandey

TechnologyIndia’s GCCs record robust rise in women staffers at senior levels