Mandrake Spyware Returns: Hidden in Google Play Apps for Two Years, Evading Detection
by duytol - Tuesday July 30, 2024 at 03:06 PM
#1
A new variant of the Mandrake spyware has been discovered on Google Play, hiding in legitimate-looking apps related to cryptocurrency, astronomy, and utility tools. This spyware has been active since 2016, with its latest version evading detection through advanced obfuscation and evasion techniques.

Mandrake was found in five applications, which were available on Google Play from 2022 to 2024, amassing over 32,000 downloads. The apps were downloaded primarily in countries like Canada, Germany, Italy, Mexico, Spain, Peru, and the UK. The spyware uses a complex multi-stage infection process involving native libraries to bypass Google Play's security checks. It requests permissions for activities such as screen recording, data collection, and command execution, allowing it to perform various malicious actions on infected devices.

The spyware's evasion techniques include using obfuscated native libraries, certificate pinning for secure communication, and extensive checks to detect if it's running on a rooted device or within an emulated environment. The malware can also mimic Google Play notifications to trick users into installing additional malicious APKs.

Although the identified malicious apps have been removed from Google Play, the threat remains, and users are advised to install apps only from reputable publishers, check user reviews, and avoid granting unnecessary permissions. Google Play Protect has been enhanced to combat such threats, providing automatic protection against known malware versions.

For more details, you can refer to the articles on The Hacker News, IT-Online, and Bleeping Computer.
Reply
#2
Oh well time to never ever install an app again :/
Reply
#3
And yet, the original spyware still remains: Google Play.
Reply
#4
Google Play is a spyware itself, as mentioned above. The telemetry volume of this app is crazy
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  ShinyHunters sent Google an extortion demand; Shiny comments on current activities lulagain 5 163 5 hours ago
Last Post: hqxdxt
  Google suffers data breach in ongoing Salesforce data theft attacks by the @ShinyHunt lulagain 1 129 08-07-2025, 10:19 PM
Last Post: Inexorable_Baer
  EU age verification app to ban any Android system not licensed by Google empelempe 1 219 07-28-2025, 06:33 AM
Last Post: jokecoffin
  Skype to Shut 14 Years After Microsoft’s $8.5 Billion Purchase lulagain 0 395 03-01-2025, 02:30 PM
Last Post: lulagain
  Google’s new policy tracks all your devices with no opt-out coolbe 0 388 02-24-2025, 12:00 AM
Last Post: coolbe

Forum Jump:


 Users browsing this thread: