logo

Malware on Google Play abusing Accessibility Service

ID: 7c0d6a2d-1fe8-5382-8e38-829ecbd384df

STIX ID: report--7c0d6a2d-1fe8-5382-8e38-829ecbd384df

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Analysis of two malicious Android apps discovered on Google Play: 'Earn Real Money Gift cards' (BankBot variant) and 'Bubble Shooter Wild Life' (package: com.bubblesooter.wildlife, MD5: ef652a8813b1fd840da54b0c360df888). The report shows the latter uses Allatori obfuscation, a 20-minute delayed trigger, and social-engineered system dialogs to trick users into granting Accessibility permissions; once granted it checks for /sdcard/Download/app.apk, toggles "Installation from Unknown Sources", and automatically installs additional APKs. Researchers notified Google; the apps had fewer than 5,000 downloads but the abuse of Accessibility and automated installation poses a significant user risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.