U1 News
  • Home
  • World
  • U.S.
  • Business
  • Technology
  • Science
  • Entertainment
  • Sport
  • Health
Global News

Israel targets Hezbollah commander in Beirut strike after deadly Golan Heights attack

July 30, 2024

Taylor Swift speaks out after Southport mass stabbing at dance class

July 30, 2024

3 girls killed in stabbing at Taylor Swift-themed UK dance class. 7 people still critically wounded

July 30, 2024
Facebook Twitter Instagram
Trending
  • Left-handedness linked to autism, schizophrenia in major neurological study
  • Heart health unexpectedly affected by shingles vaccine
  • Doctors remove spinal cancer through eye socket in revolutionary surgery
  • Laundry done at home by healthcare workers may spread superbugs, says new study
  • Longevity and organ function predicted in new ‘body clock’ tool
  • ‘Magic mushrooms’ may offer major relief for Parkinson’s patients, study shows
  • DeSantis signs MAHA-approved fluoridated water bill into law
  • Alarming fungus could invade parts of the US, researchers warn
Saturday, May 10
U1 News
  • Home
  • World

    Israel targets Hezbollah commander in Beirut strike after deadly Golan Heights attack

    July 30, 2024

    Taylor Swift speaks out after Southport mass stabbing at dance class

    July 30, 2024

    3 girls killed in stabbing at Taylor Swift-themed UK dance class. 7 people still critically wounded

    July 30, 2024

    Kerala, India, hit by landslides, killing at least 99

    July 30, 2024

    Taylor Swift ‘in shock’ after horrific UK stabbing, as police say 3rd child dies

    July 30, 2024
  • U.S.

    Biden criticises ‘extreme’ Supreme Court in push for reform

    July 30, 2024

    FBI details shooter’s search history before Trump assassination attempt

    July 30, 2024

    Reps. Mike Kelly, Jason Crow to lead task force on Trump rally shooting

    July 29, 2024

    Biden to call for major Supreme Court reforms, including term limits, at Civil Rights Act event Monday

    July 29, 2024

    Sonya Massey’s death revives pain for Breonna Taylor, Floyd activists

    July 29, 2024
  • Business

    AMD stock jumps on earnings beat driven by AI chip sales

    July 30, 2024

    Amazon is responsible for dangerous products sold on its site, federal agency rules

    July 30, 2024

    Microsoft investigating new outages of services after global CrowdStrike chaos

    July 30, 2024

    S&P 500, Nasdaq Tumble as Chip Stocks Slide Ahead of Big Tech Earnings

    July 30, 2024

    American consumers feeling more confident in July as expectations of future improve

    July 30, 2024
  • Technology

    Apple says Safari protects your privacy. We fact checked those claims.

    July 30, 2024

    GameStop Dunks On Xbox 360 Store Closing And Gets Savaged

    July 30, 2024

    Logitech has an idea for a “forever mouse” that requires a subscription

    July 30, 2024

    Friend: a new digital companion for the AI age

    July 30, 2024

    London Sports Mod Community Devolves Into War

    July 30, 2024
  • Science

    NASA’s Lunar Gateway has a big visiting vehicles problem

    August 1, 2024

    Boeing’s Cursed ISS Mission May Finally Make It Back to Earth

    July 30, 2024

    Should you floss before or after you brush your teeth?

    July 30, 2024

    Ancient swimming sea bug ‘taco’ had mandibles, new fossils show

    July 30, 2024

    NASA’s DART asteroid impact mission revealed ages of twin space rock targets (images)

    July 30, 2024
  • Entertainment

    Richard Gadd Backs Netflix to Get ‘Baby Reindeer’ Lawsuit Dismissed

    July 30, 2024

    Batman: Caped Crusader review: a pulpy throwback to DC’s Golden Age

    July 30, 2024

    Channing Tatum Praises Ryan Reynolds For Taking Gamble On Gambit

    July 30, 2024

    ‘Star Wars Outlaws’ somehow made me fall in love with Star Wars again

    July 30, 2024

    Great Scott and O’Brien’s Pub find new life in Allston

    July 30, 2024
  • Sport

    How Snoop Dogg became a fixture of the Paris Olympics

    July 30, 2024

    Team USA’s Coco Gauff exits Olympics singles tournament with a third-round loss : NPR

    July 30, 2024

    French police investigating abuse targeting Olympic opening ceremony DJ over ‘Last Supper’ scene

    July 30, 2024

    French DJ Takes Legal Action

    July 30, 2024

    Why BYU’s Jimmer Fredette is at the 2024 Paris Olympics

    July 30, 2024
  • Health

    Left-handedness linked to autism, schizophrenia in major neurological study

    May 10, 2025

    Heart health unexpectedly affected by shingles vaccine

    May 9, 2025

    Doctors remove spinal cancer through eye socket in revolutionary surgery

    May 9, 2025

    Laundry done at home by healthcare workers may spread superbugs, says new study

    May 8, 2025

    Longevity and organ function predicted in new ‘body clock’ tool

    May 7, 2025
U1 News
Home»Technology»Android spyware ‘Mandrake’ hidden in apps on Google Play since 2022
Technology

Android spyware ‘Mandrake’ hidden in apps on Google Play since 2022

u1news-staffBy u1news-staffJuly 30, 2024No Comments4 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Image 2.jpg
Share
Facebook Twitter LinkedIn Pinterest Email

A new version of the Android spyware “Mandrake” has been discovered in five applications that have been downloaded 32,000 times from Google Play, the platform’s official app store.

Bitdefender First documented Researchers discovered Mandrake in 2020, highlighting the malware’s advanced espionage capabilities and noting that it had been in the wild since at least 2016.


Kaspersky Lab reports that a new variant of Mandrake has been discovered that is more obfuscated and evasive. Sneaking into Google Play Through five apps submitted to the store in 2022.

These apps were available for at least a year, but the last one, the most successful in terms of popularity and infections, AirFS, was removed at the end of March 2024.

AirFS on Google Play
Source: Kaspersky

Kaspersky identified five apps that carry Mandrake:

  • Air FS – File Sharing over Wi-Fi by it9042 (downloaded 30,305 times between April 28, 2022 and March 15, 2024)
  • Astro Explorer by shevabad (downloaded 718 times between May 30, 2022 and June 6, 2023)
  • amber by kodaslda (downloaded 19 times between February 27, 2022 and August 19, 2023)
  • Cryptopulse by shevabad (downloaded 790 times between November 2, 2022 and June 6, 2023)
  • Brain Matrix By kodaslda (downloaded 259 times between April 27, 2022 and June 6, 2023)

According to the cybersecurity firm, most of the downloads came from Canada, Germany, Italy, Mexico, Spain, Peru and the UK.

Four apps that drop Mandrake malware onto victim devices
Source: Kaspersky

Avoiding detection

Unlike typical Android malware that places malicious logic in an app’s DEX files, Mandrake hides its initial stages in a native library “libopencv_dnn.so” that is highly obfuscated using OLLVM.

Once the malicious app is installed, the library exports a function that decrypts the second stage loader DEX from the assets folder and loads it into memory.

The second stage loads a second native library, “libopencv_java3.so”, which requests permissions to draw the overlay and decrypts certificates for secure communication with the command and control (C2) server.

Once communication is established with the C2, the app sends a device profile and, if deemed appropriate, receives the core Mandrake components (stage 3).

Once the core components are activated, the Mandrake spyware is able to carry out a variety of malicious activities, including data collection, screen recording and monitoring, command execution, simulating user swipes and taps, file management, and app installation.

In particular, threat actors can trick users into installing unsafe files through a seemingly trustworthy process by displaying notifications that mimic Google Play, further encouraging users to install malicious APKs.

According to Kaspersky, the malware Session-based installation method How to get around installation restrictions on Android 13 (and above) APKs from unofficial sources.

Like other Android malware, Mandrake operates stealthily by asking the user for permission to run in the background and hiding the dropper app icon on the victim’s device.

The latest version of the malware also comes with batter-evasion capabilities, and now specifically checks for the presence of Frida, a dynamic instrumentation toolkit popular among security analysts.

It also checks the root status of the device and searches for specific binaries associated with it, checks if the system partition is mounted as read-only, and checks if development settings and ADB are enabled on the device.

The Mandrake threat remains, and although the five apps identified by Kaspersky as droppers are no longer available on Google Play, the malware may return via new apps that are harder to detect.

Android users are advised to only install apps from trusted sources, review user comments before installation, avoid allowing dangerous permission requests that may be unrelated to the app’s functionality, and ensure that Play Protect is always enabled.

Google released the following statement about the malicious apps found on Google Play:

“Google Play Protect is continuously improved with each app identified. We’re constantly enhancing its capabilities, including live threat detection to combat obfuscation and anti-evasion techniques,” Google told BleepingComputer.

“Android users are automatically protected from known versions of this malware by Google Play Protect, which is enabled by default on Android devices with Google Play Services. Google Play Protect can warn users or block apps known to exhibit malicious behavior, even if they come from sources other than Play.”

Android apps Google Hidden Mandrake Play spyware
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
u1news-staff
u1news-staff
  • Website

Related Posts

Apple says Safari protects your privacy. We fact checked those claims.

July 30, 2024

GameStop Dunks On Xbox 360 Store Closing And Gets Savaged

July 30, 2024

Logitech has an idea for a “forever mouse” that requires a subscription

July 30, 2024

Friend: a new digital companion for the AI age

July 30, 2024
Add A Comment

Leave A Reply Cancel Reply

Latest Posts

Left-handedness linked to autism, schizophrenia in major neurological study

May 10, 2025

Heart health unexpectedly affected by shingles vaccine

May 9, 2025

Doctors remove spinal cancer through eye socket in revolutionary surgery

May 9, 2025

Laundry done at home by healthcare workers may spread superbugs, says new study

May 8, 2025
Unites States

Biden criticises ‘extreme’ Supreme Court in push for reform

July 30, 2024

FBI details shooter’s search history before Trump assassination attempt

July 30, 2024

Reps. Mike Kelly, Jason Crow to lead task force on Trump rally shooting

July 29, 2024

Subscribe to Updates

Get the latest sports news from SportsSite about soccer, football and tennis.

Copyright ©️ All rights reserved. | U1 News
  • Home
  • About Us
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.