Skip to main content

New Android malware disguises itself as a Chrome update

There’s a new info-stealing malware hiding out there in a familiar cloak, waiting to infect your Android device. Zscaler’s security research team, ThreatLabZ, discovered the malware, which hides in the form of an Android Google Chrome update.

The domains used by the infostealer look like file names for Google updates, but each URL is only active for a little while before being replaced. It changes URLs like a spy changes clothing in order to remain undetected by URL filters.

ZScaler provided a list of URLs they’ve caught:

http[:]//ldatjgf[.]goog-upps.pw/ygceblqxivuogsjrsvpie555/

  • http[:]//iaohzcd[.]goog-upps.pw/wzbpqujtpfdwzokzcjhga555/
  • http[:]//uwiaoqx[.]marshmallovw.com/
  • http[:]//google-market2016[.]com/
  • http[:]//ysknauo[.]android-update17[.]pw/
  • http[:]//ysknauo[.]android-update16[.]pw/
  • http[:]//android-update15[.]pw/
  • http[:]//zknmvga[.]android-update15[.]pw/
  • http[:]//ixzgoue[.]android-update15[.]pw/
  • http[:]//zknmvga[.]android-update15[.]pw/
  • http[:]//gpxkumv.web-app.tech/xilkghjxmwvnyjsealdfy666/

Director of Security Research at Zscaler, Deepen Desai, told ZDNet, “The malware may arrive from compromised or malicious websites using scareware tactics or social engineering.” An easy way to avoid that trouble is to stay away from questionable websites in the first place, and think twice about clicking “Ok.”

He said, “One common theme we have seen in recent malicious android application packages involves scareware tactics where the user will see a popup indicating that their device is infected with a virus and asks them to update to clean up infection.”

After downloading, the fake update called “Update_chrome.apk” prompts unsuspecting Android users to grant it admin access. If they agree, the malware seeks out and nullifies any already installed security or antivirus apps like Avast, ESET, Dr. Web, and Kaspersky to prevent them from functioning as they should.

Once the security software is crippled, the fake Chrome goes about tracking all texts and calls, sending the info to a command-and-control server. The malware can even hang up on unknown callers. If the Google Play Store is installed, it will show a fake credit card payment page that looks eerily close to the real one. If the user falls for that, the malware will send the CC info to a Russian telephone number.

Since the user can’t revoke its admin access, once the user gives the fake chrome infostealer admin access, the only recourse is to factory reset the device.

Editors' Recommendations

Aliya Barnwell
Former Digital Trends Contributor
Aliya Tyus-Barnwell is a writer, cyclist and gamer with an interest in technology. Also a fantasy fan, she's had fiction…
Google just announced 10 huge updates for your Android phone
The Home Screen on the Google Pixel 8 Pro.

Google I/O, the annual everything-Google-software fest, has kicked off. As usual, Android takes center stage. From enhanced privacy and Google Wallet upgrades to theft detection and app safety checkups, there’s a lot to look forward to here.

From Android 15 features to more general Android updates, here’s a breakdown of all the major Android announcements from I/O 2024.
Making life easier with Google Wallet

Read more
Android 15 might add a new way to charge your gadgets
The Android 15 logo on a smartphone.

Wireless charging has been a fringe feature for over a decade, despite Apple's push into the ecosystem with the iPhone X and its later adoption of MagSafe. It has been limited to flagship phones, save for a few exceptions, mostly due to the painfully slow charging speeds. But with Android 15, Google now seems to offer phone makers additional reasons to adopt wireless charging even without dedicated hardware.

Instead of relying on a dedicated charging coil, Android 15 could enable wireless charging on phones with Near Field Communications (or NFC) tech. Android Authority dug up instances from the source code of Android 15's first user beta, which arrived last week, that suggests the implementation.
Not new, but definitely noteworthy
Samsung Galaxy S23 FE Tushar Mehta / Digital Trends

Read more
Google just released the first Android 15 beta. Here’s what’s new
The Android 15 logo on a smartphone.

Google has just released the first public beta build of Android 15, marking an end to the developer-focused test phase. The beta version’s release also means that Android 15 is finally in a state where it can be tried by the masses without people having to worry about too many bugs leaving their phone in a sorry state.

The first beta version of Android 15 doesn’t introduce a ton of new features, as most of the notable additions have already appeared in the Developer Preview builds. Google’s blog post, however, mentions the following features as the key highlights

Read more