Four third-party app stores for Android have apps with a malicious component that seeks root access to devices, according to Trend Micro.
The security company found 1,163 Android application packages containing the malware, which it calls ANDROIDOS_ LIBSKIN.A, wrote Jordan Pan, a mobile threats analyst with Trend. The malware obtains root access to the phone, the highest level of access and privilege.
The apps containing the component were downloaded across 169 countries between Jan. 29 and Feb. 1 from marketplaces called Aptoide, Mobogenie, mobile9 and 9apps.
"We have already contacted these stores and informed them about these threats, but as of this writing, we have yet to receive any confirmation from their end," Pan wrote.
Security experts have long advised that people steer away from third-party apps stores, which may not have the same quality control as Google's Play store. Google vets the apps that are allowed on its store, although malicious ones sometimes slip in.
The malicious component found by Trend is wrapped into legitimate applications, such as games or music streaming apps. The malware can download other apps to a phone without a user's knowledge, Pan wrote.
"These secretly downloaded apps will then present themselves as ads luring users to download other apps from time to time," he wrote. "It can also be used to collect user data."
When pop-up ads begin appearing, it's not clear to the phone's user what app is generating the ads.
"The popups lure users into clicking unwanted apps," Pan wrote. "Clicking on the ads may not necessarily lead the user to the respective app or site."
The malware also collects a variety of data, including the device ID, network, other apps that are running on the device and more.
Next read this:
- Top 9 challenges IT leaders will face in 2020
- Top 5 strategic priorities for CIOs in 2020
- 7 'crackpot' technologies that might transform IT
- 8 technologies that will disrupt business in 2020
- 7 questions CIOs should ask before taking a new job
- 7 ways to position IT for success in 2020
- The 9 new rules of IT leadership
- 20 ways to kill your IT career (without knowing it)
- IT manager’s survival guide: 11 ways to thrive in the years ahead
- CIO resumes: 6 best practices and 4 strong examples
- 4 KPIs IT should ditch (and what to measure instead)