Photo Showing User Accessing Google Play Store
© PixieMe/Shutterstock.com
No AI-generated content: this article is written and researched by humans
Table of contents

Researchers have discovered an Android spyware module disguised as a marketing software development kit (SDK). In a report on Monday, Doctor Web said it found the trojan SDK in 101 apps, which have a total of about 421 million downloads. Some of these apps are available on Google’s Play Store.

The spyware — “Android.Spy.SpinOk” — collects and transmits user data and executes other malicious functions, Doctor Web said. The report warned that “hundreds of millions of users are at risk of becoming victims of cyber espionage.”

SpinOK’s Spyware Features

The marketing SDK used to transmit this spyware purports to help increase users’ interest and engagement with apps by introducing mini-games and prizes. However, when users install the app, it connects to a C&C (hacker-controlled) server and transmits “a large amount of technical information” to the threat actor. This data allows the threat actor to adjust the app’s “operating routine” to avoid detection.

The spyware ignores device proxy settings to hide its network connections and displays advertising banners using URLs from the hacker-controlled server. Ultimately, this creates a window that allows the threat actor to access victims’ private data and even copy or change clipboard contents.

The list of Play Store apps that contain this malware includes Biugo, Noizz, Cashzine, InstaCash, Mega Win Slots, Novelah, and Holiday Solitaire Party. These apps span different categories. While some of these apps have been taken down from the Play Store, others are still up.

Doctor Web has a full list of all 101 apps that contain this trojan SDK.

Protecting Your Device from Malware

With an estimated 3.5 million apps, Google Play Store is the world’s largest app store. It’s also a top target for cybercriminals.

“According to statistics, every fifth program [app] for Android contains a vulnerability (or, in other words, a “loophole”) that lets cybercriminals successfully introduce Trojans onto mobile devices and manipulate them into doing whatever actions they need them to,” Doctor Web noted.

This report comes just weeks after Kaspersky revealed that criminals charge up to $20,000 to “trojanize” Play Store apps. This is one of the most popular services on dark web marketplaces.

“It is usually difficult for developers to understand whether a particular SDK is malicious or whether it contains potentially dangerous functions,” Doctor Web told VPNOverview. “In this regard, we can recommend using well-established systems with a good reputation. However, even in these cases, there is always a risk of encountering a threat.”

We recommend looking through the list of apps that contain SpinOK and ensuring you don’t have any of them installed on your device. It’s important to assess every app you download critically to reduce your chances of falling victim to other malicious Play Store apps. Read about the developer and be wary of apps that require invasive device permissions to operate. Also, keep your device up to date and use a solid antivirus solution.

Interested in learning more about spyware? Here’s how to tell if your phone is being monitored.

Leave a comment