//
you're reading...
Apps, Malwares

Rogue Instagram and Angry Birds Space for Android Spotted

After posing as Angry Birds Space, a malware known as ANDROIDOS_SMSBOXER.A poseses as Instagram for Android app. Trendmicro discovered a spoofed webpage containing a rogue version of Instagram. The said webpage mimics Instagram‘s legitimate download page. The red squares indicate clickable links that lead to the download:

For your reference, below is a screenshot of the site hosting the legitimate app:

Jonathan Beltran also uncovered a rogue version of Angry Birds Space. Similar to the fake Instagram app, the webpage hosting this rogue app is hosted on a Russian site.

Both the rogue Instagram and Angry Birds Space are detected as ANDROIDOS_SMSBOXER.A. Based on our initial analysis, the malware will ask users to permit the sending of a query using short numbers to supposedly activate the app. In reality, this malware sends a message to specific numbers. The rogue app also connects to specific sites, to possibly download other files onto the device.

For the past few days, TrendMicro has been seeing several other Russian domains hosting fake webpages posing as download pages for some popular Android apps. Some of the apps used in this scheme include Fruit Ninja, Temple Run and Talking Tom Cat. Users are advised to remain cautious before downloading Android apps, specially those hosted on third-party app stores.

Source: TrendMicro blog

Discussion

No comments yet.

Leave a comment