A new version of the Necro malware loader infected 11 million Android devices via malicious advertising SDKs in legitimate apps and modified versions of popular software. The malware primarily spreads through unofficial websites and modified apps, but two legitimate Google Play apps were also found to be infected. Kaspersky identified several malicious plugins associated with Necro, including those that display ads, download and execute files, facilitate subscription fraud, and use infected devices as proxies. The total number of infections is unknown, but at least 11 million devices were infected through Google Play.

  • GenderNeutralBro@lemmy.sdf.org
    link
    fedilink
    English
    arrow-up
    12
    arrow-down
    1
    ·
    2 months ago

    This is Kaspersky, so the only answer you’re going to get from them is “use Kaspersky Premium”.

    The only non-Play apps they mention in their report are modified versions of otherwise-clean apps (like Spotify or Minecraft). They didn’t mention anything on F-Droid or other app stores.

    • DarkThoughts@fedia.io
      link
      fedilink
      arrow-up
      7
      arrow-down
      2
      ·
      2 months ago

      I’d very highly suggest not to use Russian anti-virus software, regardless which version we’re talking about.

      • JustMarkov@lemmy.ml
        link
        fedilink
        English
        arrow-up
        5
        ·
        2 months ago

        I’d very higly suggest to not use any anti-virus, other than open-source ones, like ClamAV or Hypatia.