A premium services subscription scam for Android named ‘Dark Herring’ has been operating for around two years. The operation used 470 Google Play Store apps and impacted over 100 million users worldwide, potentially causing losses of up to hundreds of millions of USDs.
‘Dark Herring’ was available in 470 applications on the Google Play Store and the earliest submission dates back to March 2020.
The fraudulent apps were installed by over 105 million users in 70 countries, subscribing them to premium services that charged $15 per month through Direct Carrier Billing (DCB).
DCB is a mobile payment option that allows users to purchase digital content from the Play Store, charging it to their prepaid balance or postpaid bill.
Dark Herring operators cashed the subscriptions before the users realized the fraudulent charges several months after the infection.
Zimperium zLabs, a Google partner and member of the Google App Defense Alliance discovered ‘Dark Herring’.
Dark Herring was a success due to its AV anti-detection capabilities, propagation through a large number of apps, code obfuscation, and the use of proxies as first-stage URLs. All these capabilities combined into a single piece of software is not usual for Android fraud.
Also, the actors used a sophisticated infrastructure that received communications from all users of the 470 applications but handled each separately based on a unique identifier.
The installed app does not contain any malicious code but features a hard-coded encrypted string that points to a first-stage URL hosted on Amazon’s CloudFront.
The response from the server contains links to additional JavaScript files hosted on AWS instances, which are downloaded onto the infected device.
These scripts prepare the app to acquire its configuration in relation to the victim, generate the unique identifiers, fetch the language and country details and determine which DCB platform is applicable in each case.
The app finally provides a customized WebView page that prompts the victim to enter their phone number, receive a temporary OTP code to activate the account on the application.
Most of the downloaded applications belong to the “Entertainment” category. The most prevalent Dark Herring apps were photography tools, casual games, utilities, and productivity apps.
The countries that were at greater risk were India, Pakistan, Saudi Arabia, Egypt, Greece, Finland, Sweden, Norway, Bulgaria, Iraq, and Tunisia.
Some of the most popular Dark Herring apps which had several million downloads include Smashex, Upgradem, Stream HD, Vidly Vibe, Cast It, My Translator Pro, New Mobile Games, StreamCast Pro, Ultra Stream, Photograph Labs Pro, VideoProj Lab, Drive Simulator, Speedy Cars – Final Lap, Football Legends etc.
















Comments