logo

Android malware 'Necro' infects 11 million devices via Google Play

ID: b5933dff-d3ac-5cf4-83c6-6dfa79e55e44

STIX ID: report--b5933dff-d3ac-5cf4-83c6-6dfa79e55e44

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-09-23

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Kaspersky and BleepingComputer report a widespread campaign where the Necro Android Trojan loader was distributed through malicious ad SDKs in legitimate Google Play apps (notably Wuta Camera and Max Browser) and via unofficial modified apps, achieving at least 11 million installs; Necro delivers multiple payloads and plugins for ad fraud, subscription fraud, arbitrary code execution (JavaScript/DEX), and proxying, using obfuscation and steganography for payload delivery — affected apps were removed from Play and users are advised to uninstall compromised apps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.