{"id":16892,"date":"2019-11-14T13:10:21","date_gmt":"2019-11-14T21:10:21","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2019\/11\/14\/news-10630\/"},"modified":"2019-11-14T13:10:21","modified_gmt":"2019-11-14T21:10:21","slug":"news-10630","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2019\/11\/14\/news-10630\/","title":{"rendered":"Stealthy new Android malware poses as ad blocker, serves up ads instead"},"content":{"rendered":"<p><strong>Credit to Author: Nathan Collier| Date: Thu, 14 Nov 2019 19:51:58 +0000<\/strong><\/p>\n<p>Since its discovery less than a month ago, a new Trojan malware for Android we detect as <a rel=\"noreferrer noopener\" aria-label=\"Android\/Trojan.FakeAdsBlock (opens in a new tab)\" href=\"http:\/\/ https:\/\/blog.malwarebytes.com\/detections\/android-trojan-fakeadsblock\/\" target=\"_blank\">Android\/Trojan.FakeAdsBlock<\/a> has already been seen on over 500 devices, and it\u2019s on the rise. This nasty piece of mobile malware cleverly hides itself on Android devices while serving up a host of advertisements: full-page ads, ads delivered when opening the default browser, ads in the notifications, and even ads via home screen widget. All while, ironically, posing as an ad blocker vaguely named Ads Blocker.<\/p>\n<h3>Upon installation: trouble<\/h3>\n<p>Diving right into this mobile threat, let\u2019s look at its ease of infection.  Immediately upon installation, it asks for <em>Allow display over other apps <\/em>rights.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" data-attachment-id=\"41072\" data-permalink=\"https:\/\/blog.malwarebytes.com\/android\/2019\/11\/stealthy-new-android-malware-poses-as-ad-blocker-serves-up-ads-instead\/attachment\/1-59\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/1.png\" data-orig-size=\"1080,1920\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"1\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/1-169x300.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/1-338x600.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/1-338x600.png\" alt=\"\" class=\"wp-image-41072\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/1-338x600.png 338w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/1-169x300.png 169w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/1.png 1080w\" sizes=\"(max-width: 338px) 100vw, 338px\" \/><\/figure>\n<\/div>\n<p>This is, of course, so it can display all the ads it serves. <\/p>\n<p>After that, the app opens and asks for a <em>Connection request <\/em>to &#8220;set up a VPN connection that allows it to monitor network traffic.&#8221;<em> <\/em>Establishing a VPN connection is not unusual for an ad blocker, so why wouldn\u2019t you click <em>OK?\u00a0 <\/em><\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" data-attachment-id=\"41073\" data-permalink=\"https:\/\/blog.malwarebytes.com\/android\/2019\/11\/stealthy-new-android-malware-poses-as-ad-blocker-serves-up-ads-instead\/attachment\/2-47\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/2.png\" data-orig-size=\"1080,1920\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"2\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/2-169x300.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/2-338x600.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/2-338x600.png\" alt=\"\" class=\"wp-image-41073\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/2-338x600.png 338w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/2-169x300.png 169w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/2.png 1080w\" sizes=\"(max-width: 338px) 100vw, 338px\" \/><\/figure>\n<\/div>\n<p>To clarify, the app doesn\u2019t actually connect to any VPN.\u00a0 Instead, by clicking <em>OK, <\/em>users actually allow the malware run in the background at all times.<\/p>\n<p>Next up is a request to add a home screen widget.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" data-attachment-id=\"41074\" data-permalink=\"https:\/\/blog.malwarebytes.com\/android\/2019\/11\/stealthy-new-android-malware-poses-as-ad-blocker-serves-up-ads-instead\/attachment\/3-40\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/3.png\" data-orig-size=\"1080,1920\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"3\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/3-169x300.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/3-338x600.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/3-338x600.png\" alt=\"\" class=\"wp-image-41074\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/3-338x600.png 338w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/3-169x300.png 169w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/3.png 1080w\" sizes=\"(max-width: 338px) 100vw, 338px\" \/><\/figure>\n<\/div>\n<p>This is where things get suspicious. The added widget is nowhere to be found. On my test device, it added the widget to a new home screen page.\u00a0 Good luck finding and\/or clicking it though.<\/p>\n<ul class=\"wp-block-gallery aligncenter columns-2 is-cropped\">\n<li class=\"blocks-gallery-item\">\n<figure><img decoding=\"async\" data-attachment-id=\"41075\" data-permalink=\"https:\/\/blog.malwarebytes.com\/android\/2019\/11\/stealthy-new-android-malware-poses-as-ad-blocker-serves-up-ads-instead\/attachment\/4-26\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/4.png\" data-orig-size=\"1080,1920\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"4\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/4-169x300.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/4-338x600.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/4-338x600.png\" alt=\"\" data-id=\"41075\" data-link=\"https:\/\/blog.malwarebytes.com\/?attachment_id=41075\" class=\"wp-image-41075\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/4-338x600.png 338w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/4-169x300.png 169w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/4.png 1080w\" sizes=\"(max-width: 338px) 100vw, 338px\" \/><\/figure>\n<\/li>\n<li class=\"blocks-gallery-item\">\n<figure><img decoding=\"async\" data-attachment-id=\"41076\" data-permalink=\"https:\/\/blog.malwarebytes.com\/android\/2019\/11\/stealthy-new-android-malware-poses-as-ad-blocker-serves-up-ads-instead\/attachment\/5-20\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/5.png\" data-orig-size=\"1080,1920\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"5\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/5-169x300.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/5-338x600.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/5-338x600.png\" alt=\"\" data-id=\"41076\" data-link=\"https:\/\/blog.malwarebytes.com\/?attachment_id=41076\" class=\"wp-image-41076\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/5-338x600.png 338w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/5-169x300.png 169w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/5.png 1080w\" sizes=\"(max-width: 338px) 100vw, 338px\" \/><\/figure>\n<\/li>\n<\/ul>\n<p>The fake ad blocker then outputs some jargon to make it look legit.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" data-attachment-id=\"41077\" data-permalink=\"https:\/\/blog.malwarebytes.com\/android\/2019\/11\/stealthy-new-android-malware-poses-as-ad-blocker-serves-up-ads-instead\/attachment\/6-15\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/6.png\" data-orig-size=\"1080,1920\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"6\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/6-169x300.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/6-338x600.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/6-338x600.png\" alt=\"\" class=\"wp-image-41077\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/6-338x600.png 338w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/6-169x300.png 169w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/6.png 1080w\" sizes=\"(max-width: 338px) 100vw, 338px\" \/><\/figure>\n<\/div>\n<p>Take a good look, because this will most likely be the last time you\u2019ll see this supposed ad blocker if you are one of the many unfortunate victims of its infection.<\/p>\n<h3>Extreme stealth<\/h3>\n<p>Ads Blocker is inordinately hard to find on the mobile device once installed. To start, there is no icon for Ads Blocker. However, there are some hints of its existence, for example, a small key icon status bar.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" data-attachment-id=\"41078\" data-permalink=\"https:\/\/blog.malwarebytes.com\/android\/2019\/11\/stealthy-new-android-malware-poses-as-ad-blocker-serves-up-ads-instead\/attachment\/key-6\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/key.png\" data-orig-size=\"388,64\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"key\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/key-300x49.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/key.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/key.png\" alt=\"\" class=\"wp-image-41078\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/key.png 388w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/key-300x49.png 300w\" sizes=\"(max-width: 388px) 100vw, 388px\" \/><\/figure>\n<\/div>\n<p>This key icon was created after accepting the fake VPN connection message, as shown above. As a result, this small key is proof that the malware is running the background.<\/p>\n<p>Although hard to spot, another clue is a blank white notification box hidden in plain sight.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" data-attachment-id=\"41079\" data-permalink=\"https:\/\/blog.malwarebytes.com\/android\/2019\/11\/stealthy-new-android-malware-poses-as-ad-blocker-serves-up-ads-instead\/attachment\/7-12\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/7.png\" data-orig-size=\"1080,1920\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"7\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/7-169x300.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/7-338x600.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/7-338x600.png\" alt=\"\" class=\"wp-image-41079\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/7-338x600.png 338w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/7-169x300.png 169w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/7.png 1080w\" sizes=\"(max-width: 338px) 100vw, 338px\" \/><\/figure>\n<\/div>\n<p><strong>Warning<\/strong>: If you happen to press this blank notification, it will ask permission to <em>Install unknown apps <\/em>with a toggle button to <em>Allow from this source. <\/em>In this case,<em> <\/em>the source is the malware, and clicking on it could allow for the capability to install even more malware.<\/p>\n<p>If you try to find Ads Blocker on the <em>App info <\/em>page on your mobile device to remove manually, it once again hides itself with a blank white box.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" data-attachment-id=\"41080\" data-permalink=\"https:\/\/blog.malwarebytes.com\/android\/2019\/11\/stealthy-new-android-malware-poses-as-ad-blocker-serves-up-ads-instead\/attachment\/8-7\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/8.png\" data-orig-size=\"1080,1920\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"8\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/8-169x300.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/8-338x600.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/8-338x600.png\" alt=\"\" class=\"wp-image-41080\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/8-338x600.png 338w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/8-169x300.png 169w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/8.png 1080w\" sizes=\"(max-width: 338px) 100vw, 338px\" \/><\/figure>\n<\/div>\n<p>Luckily, it can\u2019t hide the app storage used, so the floating <em>6.57 MB <\/em>figure show above can assist in finding it. Unless you spot this app storage number and figure out which app it belongs to (by process of elimination), you won&#8217;t be able to remove Ads Blocker from your device. <\/p>\n<h3>Android malware digs in its fangs<\/h3>\n<p>This Android malware is absolutely relentless in its ad-serving capabilities and frequency. As a matter of fact, while writing this blog, it served up numerous ads on my test device at a frequency of about once every couple minutes. In addition, the ads were displayed using a variety of different methods.<\/p>\n<p>For instance, it starts with the basic full-page ad:<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" data-attachment-id=\"41081\" data-permalink=\"https:\/\/blog.malwarebytes.com\/android\/2019\/11\/stealthy-new-android-malware-poses-as-ad-blocker-serves-up-ads-instead\/attachment\/9-5\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/9.png\" data-orig-size=\"1080,1920\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"9\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/9-169x300.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/9-338x600.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/9-338x600.png\" alt=\"\" class=\"wp-image-41081\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/9-338x600.png 338w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/9-169x300.png 169w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/9.png 1080w\" sizes=\"(max-width: 338px) 100vw, 338px\" \/><\/figure>\n<\/div>\n<p>In addition, it offers ads in the notifications:<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" data-attachment-id=\"41082\" data-permalink=\"https:\/\/blog.malwarebytes.com\/android\/2019\/11\/stealthy-new-android-malware-poses-as-ad-blocker-serves-up-ads-instead\/attachment\/10-5\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/10.png\" data-orig-size=\"1080,1920\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"10\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/10-169x300.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/10-338x600.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/10-338x600.png\" alt=\"\" class=\"wp-image-41082\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/10-338x600.png 338w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/10-169x300.png 169w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/10.png 1080w\" sizes=\"(max-width: 338px) 100vw, 338px\" \/><\/figure>\n<\/div>\n<p>Oh look, it wants to send ads through the default web browser:<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" data-attachment-id=\"41083\" data-permalink=\"https:\/\/blog.malwarebytes.com\/android\/2019\/11\/stealthy-new-android-malware-poses-as-ad-blocker-serves-up-ads-instead\/attachment\/11-6\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/11.png\" data-orig-size=\"1080,1920\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"11\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/11-169x300.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/11-338x600.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/11-338x600.png\" alt=\"\" class=\"wp-image-41083\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/11-338x600.png 338w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/11-169x300.png 169w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/11.png 1080w\" sizes=\"(max-width: 338px) 100vw, 338px\" \/><\/figure>\n<\/div>\n<p>Last, remember the request to add a widget to the home screen that seemed to be invisible? Invisible widget presents: even more ads.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" data-attachment-id=\"41084\" data-permalink=\"https:\/\/blog.malwarebytes.com\/android\/2019\/11\/stealthy-new-android-malware-poses-as-ad-blocker-serves-up-ads-instead\/attachment\/12-5\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/12.png\" data-orig-size=\"1080,1920\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"12\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/12-169x300.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/12-338x600.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/12-338x600.png\" alt=\"\" class=\"wp-image-41084\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/12-338x600.png 338w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/12-169x300.png 169w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/12.png 1080w\" sizes=\"(max-width: 338px) 100vw, 338px\" \/><\/figure>\n<\/div>\n<p>The ads themselves cover a wide variety of content, and some are quite unsavory\u2014certainly not what you want to see on your mobile device.<\/p>\n<h3>Infections on the rise<\/h3>\n<p>Needless to say, this stealthy Android malware that plasters users with vulgar ads is not what folks are looking for when they download an ad blocker. Unfortunately, we have already counted over 500 detections of Android\/Trojan.FakeAdsBlock. Moreover, we collected over 1,800 samples in our Mobile Intelligence System of FakeAdsBlock, leading us to believe that infection rates are quite high. On the positive side, <a rel=\"noreferrer noopener\" href=\"http:\/\/www.malwarebytes.com\/android\" target=\"_blank\">Malwarebytes for Android<\/a> removed more than 500 infections that are otherwise exceedingly difficult to remove manually.  <\/p>\n<h3>Source of infection<\/h3>\n<p>It is unclear exactly where this Android malware is coming from. The most compelling evidence we have is based on VirusTotal submission data, which  suggests the infection is spreading in the United States. Most likely, users are downloading the app from third-party app store(s) looking for a legitimate ad blocker, but are unknowingly installing this malware instead.<\/p>\n<p>Moreover, from the filenames of several submissions, such as <em>Hulk (2003).apk, Guardians of the Galaxy.apk, <\/em>and <em>Joker (2019).apk.<\/em>, there\u2019s also a connection with a bogus movie app store as another possible source of infection. <\/p>\n<p>Additional evidence demonstrates the Android malware might also be spreading in European countries such as France and Germany. A forum post was created on the French version of <a href=\"https:\/\/www.commentcamarche.net\/\">CCM.net<\/a> regarding Ads Blocker, and a German filename was submitted to VirusTotal.\u00a0 <\/p>\n<h3>A new breed of mobile malware<\/h3>\n<p>A new breed of stealthy mobile malware is clearly on the uptick. Back in August, we wrote about the <a rel=\"noreferrer noopener\" aria-label=\"hidden mobile malware xHelper (opens in a new tab)\" href=\"https:\/\/blog.malwarebytes.com\/android\/2019\/08\/mobile-menace-monday-android-trojan-raises-xhelper\/\" target=\"_blank\">hidden mobile malware xHelper<\/a>, which we detect asAndroid\/Trojan.Dropper.xHelper. At that time, xHelper had already been removed from 33,000 mobile devices\u2014and the numbers continue to grow. Ads Blocker is even more stealthy and could easily reach the same rate of infection.<\/p>\n<p>You can call it shameless plugging if you like, but this trend of stealthy Android malware highlights the necessity of a good mobile anti-malware scanner, like <a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/play.google.com\/store\/apps\/details?id=org.malwarebytes.antimalware\" target=\"_blank\">Malwarebytes<\/a>. With more and more users turning to their mobile phones for banking, shopping, storing health data, emailing, and other sensitive, yet important functions, protecting against mobile malware has become paramount. Beware of third-party app stores, yes, but have backup in case apps like Ads Blocker have you fooled. <\/p>\n<p>Stay safe out there!<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/android\/2019\/11\/stealthy-new-android-malware-poses-as-ad-blocker-serves-up-ads-instead\/\">Stealthy new Android malware poses as ad blocker, serves up ads instead<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/android\/2019\/11\/stealthy-new-android-malware-poses-as-ad-blocker-serves-up-ads-instead\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Nathan Collier| Date: Thu, 14 Nov 2019 19:51:58 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/android\/2019\/11\/stealthy-new-android-malware-poses-as-ad-blocker-serves-up-ads-instead\/' title='Stealthy new Android malware poses as ad blocker, serves up ads instead'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/11\/FakeAdsBlock_Featured_Image.jpg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>Since its discovery less than a month ago, a stealthy new Android malware has already been detected on over 500 devices, and it\u2019s on the rise. Learn how this clever threat pretends to be an ad blocker and then hides itself on mobile devices, all while serving up tons of ads. <\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/android\/\" rel=\"category tag\">Android<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/ads-blocker\/\" rel=\"tag\">ads blocker<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/android\/\" rel=\"tag\">Android<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/android-malware\/\" rel=\"tag\">android malware<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/android-trojan\/\" rel=\"tag\">android trojan<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/android-trojan-fakeadsblock\/\" rel=\"tag\">Android\/Trojan.FakeAdsBlock<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/anti-malware\/\" rel=\"tag\">Anti-Malware<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/fake-ad-blocker\/\" rel=\"tag\">fake ad blocker<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/fakeadsblock\/\" rel=\"tag\">FakeAdsBlock<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/mobile-malware\/\" rel=\"tag\">mobile malware<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/stealth-mobile-malware\/\" rel=\"tag\">stealth mobile malware<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/trojan\/\" rel=\"tag\">trojan<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/trojans\/\" rel=\"tag\">Trojans<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/android\/2019\/11\/stealthy-new-android-malware-poses-as-ad-blocker-serves-up-ads-instead\/' title='Stealthy new Android malware poses as ad blocker, serves up ads instead'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/android\/2019\/11\/stealthy-new-android-malware-poses-as-ad-blocker-serves-up-ads-instead\/\">Stealthy new Android malware poses as ad blocker, serves up ads instead<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[23448,10462,11254,23449,23450,11013,23451,23452,11255,23453,10833,12269],"class_list":["post-16892","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-ads-blocker","tag-android","tag-android-malware","tag-android-trojan","tag-android-trojan-fakeadsblock","tag-anti-malware","tag-fake-ad-blocker","tag-fakeadsblock","tag-mobile-malware","tag-stealth-mobile-malware","tag-trojan","tag-trojans"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/16892","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=16892"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/16892\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=16892"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=16892"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=16892"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}