Story image

GhostClicker adware infiltrated 300 apps on Google Play

18 Aug 17

A pervasive auto-clicking adware by the name of GhostClicker has infected as many as 340 apps from Google Play, many of which are still available for download.

Trend Micro researchers published a blog about the adware this week, which has hit apps across a range of categories. Those categories include file managers, QR scanners, GPS apps and media players, as well as popular game “Aladdin’s Adventures World” which was downloaded 5 million times.

As of August 7, 101 of those apps were still available from Google Play.

The GhostClicker adware buries itself in Google Mobile Services and in Facebook Ad’s software development kits with the simple name of ‘logs’.

The autoclick mechanism comes through Google’s mobile advertising platform Admob. It detects the device’s screen size and then attempts to display ads and use APIs for ‘ghostlike’ clicking.

GhostClicker is also able to generate fake traffic by inserting itself into download links through Google Store. It is also able to use its Command and Control server to open YouTube video links.

When users install infected apps, Trend Micro researchers report that some request device administrator permission but don’t explicitly say whether data wipes and password resets are part of their security policies.

“This can be a way to deter users from removing the app, taking advantage of the lengthy and nebulous process of uninstalling apps. It’s certainly not a user-friendly process: uninstalling an app with device administration requires that it be disabled first before an app can be removed,” researchers state.

GhostClicker has been spotted mostly in Southeast Asia including Japan and Taiwan, the United States, Russia and Italy.

The adware itself is a newer iteration of its 2016 version. The earlier version did not have the autoclick feature and device administrator permission requests.

“After the user unlocks the screen, the adware will pop up interstitial advertisements at certain intervals if the device is connected to a network with data. We encountered this version of GhostClicker in Aladdin’s Adventure’s World,” researchers state.

While GhostClicker is intrusive, drains CPU, mobile data and battery life, there is a way to stop it.

“GhostClicker can be mitigated by restricting the use of the device administration feature, which is typically used to create security-aware applications like enterprise device or BYOD management and antivirus apps. Everyday users won’t really miss out on much when doing this,” the researchers conclude.

Trend Micro says it has disclosed its findings to Google and is working with the company to take down the infected apps. Google Play Protect has also been updated to catch apps that violate Play policy.

ForeScout acquires OT security company SecurityMatters for US$113mil
Recent cyberattacks, such as WannaCry, NotPetya and Triton, demonstrated how vulnerable OT networks can result in significant business disruption and financial loss.
Exclusive: Fileless malware driving uptake of behavioural analytics
Fileless malware often finds its way into organisations via web browsers (or in combination with other vectors such as infected USB drives).
'DerpTrolling’ faces jail time for Sony DoS attacks
A United States federal court has charged a 23-year-old man for the hacks on Sony Online Entertainment and other major companies back in 2014.
Kiwis concerned about being scammed – survey
This unease is warranted given the growing sophistication of scammers and their activities, and numbers of attempted fraud.
It's time to rethink your back-up and recovery strategy
"It is becoming apparent that legacy approaches to backup and recovery may no longer be sufficient for most organisations."
Dropbox strengthens security with raft of new partnerships
Integrations will keep customer content protected and secure with tools for controlling identity access, governing data, and managing devices.
Interview: Aruba’s NZ country manager talks channel strategy
“What we're taking to market is that message around simplification and having everything in one place.”
Companies swamped by critical vulnerabilities – Tenable
Research has found enterprises identify 870 unique vulnerabilities on internal systems every day, on average, with over 100 of them being critical.