Fleckpe is a new Android subscription malware that was discovered in the Google Play Store, with more than 620,000 downloads since 2022.
The malware which was discovered by Kaspersky is hidden in photo editing apps, smartphone wallpaper packs, and other general-purpose apps.
The experts discovered eleven apps infected with Fleckpe on Google Play, which have been installed on more than 620,000 devices. Soon after it was discovered, the apps were removed from the Play Store, but the threat actors might have already uploaded other tainted apps that have yet to be discovered.
Upon executing one of the infected apps, it loads a heavily obfuscated native library containing a dropper that decrypts and runs malicious code from the app assets.
The payload sends information about the infected device to the C2 servers, including the MCC (Mobile Country Code) and MNC (Mobile Network Code). In turn, the C2 server returns a paid subscription page. The Trojan opens the page in an invisible web browser and attempts to complete a subscription of the victim. In case the subscription process requires a confirmation code, the malware is able to get it from the notifications.
Once installed, the apps continue providing their legitimate functionality such as installing wallpapers, after the victim has been subscribed to a paid service.
The authors of the malware are upgrading it, for example, they moved most of the subscription code to the native library. The payload is only used to intercept notifications and view web pages.
Most of the victims are from Thailand, however, other infections were observed in Poland, Malaysia, Indonesia, and Singapore.
This is not the first time subscription malware has been found on the Google Play Store. Fleckpe joins other fleeceware families like Joker (aka Bread or Jocker) and Harly, which subscribe infected devices to unwanted premium services and conduct billing fraud.
To avoid malware infection and subsequent financial loss, users are advised to be cautious with apps, even those coming from Google Play, avoid giving permissions they should not have, and install an antivirus that could detect these type of Trojans.

















Comments