Security

TrojanFlyer Malware Detected: Affects 120,000 Android Phones

PSafe’s Threat Analysts have discovered a malicious malware that infected at least 8 apps in Google Play. The malware, named TrojanFlyer, has the potential to affect at least 120,000 Android users, possibly more. If you don’t have Full Virus scan activated, do so now, to safeguard your Android device from these kinds of vicious attacks.

The mistake that app users make is assuming that only one or two apps are infected, concluding that suspicious apps fall into the same category on Google Play, or are produced by the same developer.

Not so with TrojanFlyer. In this latest attack, cyber criminals used clever methods by corrupting several apps in different categories carrying the same malware.

These developer names popped up across the 8 apps: Chet Grode, DenSavin, Lakov Kay. The apps were a QR code reader, wallpaper, battery optimizer, and photo galleries of beautiful women.

These 8 app packages were the culprits:

  • com.appmasteringsoft.qrcodefree
  • com.boxedstudiolow.wallhdplus
  • com.lightboostcleaner.app
  • com.ivoice.voicecallsrecorderapp
  • com.microtikappstudio.wallalbumsfree
  • vn.smartringtonesapp
  • com.exfrontvisuals.hdimagesfree
  • Com.esterightsapps.wallcollectionfree

After users initially downloaded these apps, they behaved normally, while in the background the malware was already running, using a service to start the APP which takes over a user’s entire operating system.

The malware used a developer’s tool called AlarmManager to monitor if a smartphone is turned on and has a WiFi connection. Once an Internet connection is established, hackers downloaded the second part of the malware.

Next, the malware gained further control through permissions. These apps asked users permission to make calls, access SMS information and call history, as well as, access a user’s filing storage system, including personal photos.

Once the malware gained control, it could gain access to the entire device’s contents. Including, call history:

Contact list:

SMS history:

Number of photos and photo storage:

The scary result is criminals had full control of a smartphone with TrojanFly, being able to access personal information, private photos, make calls, send text messages, or infiltrate banking apps.

With the latest Android 6.0/7.0 updates, permissions for your apps has certainly changed, but always be cautious which permissions you allow. Ensure the permissions fit the purpose of the app.

If you’re being asked for access to your contacts list, for example, and you’re unsure, always delete the app immediately and activate a trusted antivirus app.

PSafe’s DFNDR security app deters 65,000 instances of malware and 700,000 suspicious links a day. We strive to offer the most robust protection for your Android device. Find our full suite of products on the Google Play store now.

 

PSafe Newsroom

The dfndr blog is an informative channel that presents exclusive content on security and privacy in the mobile and business world, with tips to keep users protected. Populated by a select group of expert reporters, the channel has a partnership with dfndr lab's security team. Together they bring you, first-notice news about attacks, scams, internet vulnerabilities, malware and everything affecting cybersecurity.

Recent Posts

24 Billion Passwords Exposed? How to Check If You’re Affected.

A massive password leak has triggered a global security alert: Cybernews researchers identified an exposed…

57 years ago

That QR Code on Your Bar Table During the Game: Would You Scan It Without Thinking?

A QR code on a bar table could hide a phishing link. Learn how to…

57 years ago

Could You Spot a Fake Login Page in 5 Seconds? Take the Phishing Test

Before you keep reading, imagine this: You receive a message warning that your account is…

57 years ago

Is Mobile Data Always Safer Than Public Wi-Fi? Myth or Fact?

You’re at an airport and need to open your banking app. Which would you choose:…

57 years ago

Jury Duty Scam: Fake Arrest Warrants Are Targeting Americans

What would you do if someone claiming to be a U.S. Marshal called and said…

57 years ago

World Cup 2026 Streams: How to Tell Safe Links from Dangerous Ones

Kickoff is minutes away. You search for a 2026 World Cup stream and receive a…

57 years ago