These malware-infected apps for Android could secretly run up your phone bill

Android owners might want to check their phones. A cyber security company has discovered a handful of apps that embed Joker malware on Android phones. So far, over 100,000 people have installed the software.

Pradeo, in a blog post Tuesday, warned users to immediately delete “Smart SMS Messages,” “Blood Pressure Monitor,” “Voice Languages Translator,” and “Quick Text SMS” from their devices. (Google has already removed all four of the apps from the Google Play store.)

Joker is a type of “fleeceware,” which subscribes infected devices to unwanted paid services. It also sends SMS messages and makes calls to premium numbers without the phone owner’s knowledge, running up a big phone bill, of which the hackers take a cut. The practice is also referred to as “toll fraud.”  

“By using as little code as possible and thoroughly hiding it, Joker generates a very discreet footprint that can be tricky to detect. In the last three years, the malware was found hiding in thousands of apps,” Pradeo wrote. “Victims only notice the fraud when receiving their mobile phone invoice, potentially weeks after it started.”

The company says it has found Joker in at least 11 other Android apps recently—even as Congress considers a bill that would force Apple and Google to let apps circumvent their marketplaces in a practice called “sideloading.” In every case, the apps are programmed to install other applications on infected phones, which could add even more dangerous malware.

Joker, sometimes called Jocker, has been around for a while, but its footprint has been growing lately. Researchers from security firm Kaspersky say the malware has become advanced enough that it can bypass bot-detection mechanisms on paid service sites.

Once you’ve installed an app infected with the malware, it will request access to text messages and/or notifications, whichever makes sense depending on the type of app it’s hiding within. Kaspersky notes that by gaining access to notifications, it can intercept confirmation codes received in the text of messages, letting it subscribe to a paid service without the user being aware.

Microsoft, last week, published an extensive warning about Joker and other sorts of malware that contribute to toll fraud: “Toll fraud has been one of the most prevalent types of Android malware in Google Play Store since 2017, when families like Joker and their variants made their first appearance. It accounted for 34.8% of installed Potentially Harmful Application (PHA) from the Google Play Store in the first quarter of 2022, ranking second only to spyware.”

In their Google Play listings, the weaponized apps Pradeo discovered looked legitimate enough. The company, though, says there are a few steps users can take to protect themselves against future downloads with Joker hidden in the code.

First, take a look at the developer’s account. If they have only one app, tread with extreme caution. (Once an app is banned, the hacker will simply open a new developer account.) Also, look for red flags with the privacy policy. If it’s hosted on a Google Doc or Google Site page, that’s a warning sign. If it uses a template or is especially short, steer clear. And if it doesn’t disclose the full extent of the activities the app can perform, walk away.

Of course, this also requires you to read the privacy policy before you install the app, something very few people do.

https://www.fastcompany.com/90766706/joker-malware-google-play-android?partner=rss&utm_source=rss&utm_medium=feed&utm_campaign=rss+fastcompany&utm_content=rss

Établi 3y | 6 juil. 2022, 13:22:14


Connectez-vous pour ajouter un commentaire

Autres messages de ce groupe

Feeling lonely? X cofounder Ev Williams has an app for that.

When Twitter cofounder and Medium founder Evan “Ev” Williams was planning his 50th birthday party, he didn’t know who to invite. Having spent more of his life building and scaling tech

18 avr. 2025, 23:30:05 | Fast company - tech
A TikToker sues Roblox for using her viral Charli XCX dance without permission

If you thought you’d heard the last of the viral “Apple” dance, think again. The TikToker behind it is now suing Roblox over its unauthorized use.

Last year, during the height of Brat su

18 avr. 2025, 18:50:08 | Fast company - tech
What to know about Jared Birchall, Elon Musk’s right-hand man

A Wall Street Journal report this week gave an extensive look into how Elon Musk, the

18 avr. 2025, 16:40:03 | Fast company - tech
Netflix beats first quarter forecast, revealing it hasn’t been touched by Trump’s tariffs, yet

Netflix fared better than analysts anticipated during the first thr

18 avr. 2025, 14:20:07 | Fast company - tech
Why are AI companies so bad at naming their models?

Six hours after OpenAI’s launch of GPT-4.1, Sam Altman was already apologizing. 

This time, it wasn’t about

18 avr. 2025, 09:40:03 | Fast company - tech
TikTok is obsessed with this investor who bought 30 floors of a Chicago skyscraper

One of the more unique takes on the POV trend on TikTok: “POV: You bought a 100-year-old skyscraper . . . ”

For those unlikely to ever own a skyscraper themselves, TikTok’s Skyscraper Gu

18 avr. 2025, 05:10:03 | Fast company - tech
Instagram launches ‘Blend’ to share personalized Reels with friends

When it comes to sharing Instagram Reels with friends, the process of three taps to get a Reel from A to B can feel surprisingly tedious. Now, Instagram has addressed that issue with its latest fe

17 avr. 2025, 22:10:04 | Fast company - tech