Close up of a smartphone screen with the Play Store Logo in focus
© East pop/Shutterstock.com
No AI-generated content: this article is written and researched by humans
Table of contents

One of the techniques malicious actors employ to bypass Google’s Play Store security checks is versioning, where a benign version of an app is uploaded to the Play Store and is later updated with malicious code when users install it, Google’s latest Threat Horizons report revealed.

The report, prepared by Google’s Global Cybersecurity Action Team (GCAT), reveals how malicious actors use this sneaky technique to get their apps on the Play Store without raising any alarms and appear trustworthy to users.

“Campaigns using versioning commonly target users’ credentials, data, and finances,” the report said.

Despite Google blocking about 1.43 million dangerous apps from the Play Store in 2022 alone, security researchers still find malware posing as legitimate apps, leading to criticisms and calls for improved security controls.

The Threat Horizons report also casts a wide lens on the broader landscape of cyber threats, underlining complex challenges in the digital ecosystem. “Supply chain threats can be introduced in several locations of the software development lifecycle,” it notes.

How Versioning Works

The report highlighted SharkBot, an Android banking Trojan spread using this technique.

“The variants of SharkBot that appeared on Google Play had reduced functionality, a common tactic threat actors use to help their apps look less suspicious to Play Store detection systems,” the report said. “Once a user downloaded the app, the app would download a full version of the malware.”

This is just one instance of an app that attempts to evade security detection using versioning. In June, Doctor Web found Android spyware on the Play Store disguised as a marketing software development kit. The Trojan SDK, found in 101 apps and downloaded 421 million times, used versioning to slip through Google’s security radar.

Versioning depends on threat actors uploading malicious code to apps on the Play Store from third-party servers to enable malicious activity. Google’s guidelines prohibit developers from altering or updating apps outside the official Google Play update mechanism. However, threat actors use dynamic code loading (DCL) to add malicious code to their apps.

In a report published in April, Kaspersky revealed that criminals charge up to $20k on the dark web to “trojanize” apps on the Play Store by loading malicious code on them using “Google Play loaders.”

How to Avoid Downloading Malicious Apps on the Play Store

In response to these findings, Google has emphasized the importance of continuous assessments of mobile app behavior. The tech giant recommends leveraging machine learning and artificial intelligence to detect anomalous patterns and urges companies to collaborate with app stores and industry stakeholders to share intelligence.

“The best way to avoid downloading malware to your Android device is to make sure that you only install applications from trusted sources such as the Google Play Store,” Google said, adding that users must “ensure that the applications allowed are only from known and reputable developers.”

It’s important to only download apps from trusted, keep your device updated with the latest security patches, and use antivirus software that offers real-time protection to detect potentially malicious apps.

If you suspect an app on your device might be malware, refer to our comprehensive Android malware removal guide to learn how to detect and eradicate potential threats from your device.

Follow us on Twitter, Threads, and Mastodon for more news!

Leave a comment