Categories: NewsSecurity

Google Removes 300 Play Store Apps That Secretly Used Phones for DDoS Attacks

Android users generally assume Google’s Play Store is safe to use since the tech giant scans all its apps to ensure none contain malware. Every once in a while, however, hackers manage to get malicious apps past Google. Recently, according to reports, Google had to remove 300 apps from its Play Store as they were found to be using Android devices to launch distributed denial of service (DDoS) attacks.

Hijacking Phones for Large-scale DDoS Attacks

The apps Google removed were seemingly harmless: video players, storage managers, and so on. As it turns out, they were merely masquerading as legitimate apps, when in reality they were hijacking users’ phones to use them as part of a DDoS botnet.

The botnet caught the attention of content delivery network Akamai after being used to assault one of its clients, a hospitality company, with traffic from hundreds of thousands of different IPs. Dubbed WireX, the botnet is said to have been active since around August 2, but was only discovered on August 17. In some of its attacks it also asked for ransom fees.

After discovering the threat, Akamai teamed up with Google and several security researchers from companies including Cloudflare, RisIQ, Team Cymru, and Flashpoint to investigate and solve the issue. The findings, according to a Google spokesperson, led to a large number of apps on the Play Store:

“We identified approximately 300 apps associated with the issue, blocked them from the Play Store, and we’re in the process of removing them from all affected devices. The researchers’ findings, combined with our own analysis, have enabled us to better protect Android users, everywhere.”

Related Post

These apps could use infected devices for DDoS attacks as long as they were powered on. It is not clear how many were infected, but Akamai told journalist Brian Krebs

that up to 70,000 devices could have been compromised. Researchers believe the botnet had managed to infect devices in 100 different countries.

In one occurrence, according to Gizmodo, WireX emailed the organization it was attacking

, demanding a ransom. Cybercriminals have been pushing different types of ransomware lately, as The Merkle recently reported on a Chinese underground app that allows anyone without coding skills to create custom ransomware.

Google is now handling the apps that infected Android users by removing them both from its Play Store and from affected devices. It is unclear how long that will take.

WireX’s origins

Researchers believe WireX likely began as a distributed method of “click fraud,” a form of fraud that occurs when malicious scripts or programs imitate a legitimate user clicking on ads in order to generate revenue. According to reports, multiple antivirus tools currently detect WireX as a click fraud malware, not as a DDoS botnet.

At some point, WireX’s administrators decided to use their expertise to turn WireX into a DDoS botnet. It was able to generate what appeared to be legitimate internet traffic, as it included what was named a “headless” web browser that could do everything a real browser does without displaying its interface to the user on the infected device.

Francisco Memoria

Francisco is a cryptocurrency enthusiast who's lucky enough to be able to write about his passion.

Share
Published by
Francisco Memoria

Recent Posts

Bitcoin ETFs Struggle, Avalanche Prices Waver, BlockDAG Emerges as Top Crypto Mining Platform

BlockDAG Leads The Crypto Revolution: Outshining Bitcoin ETF Woes And Avalanche Price Concerns In a…

1 hour ago

BlockDAG Outshines Aptos and XRP: Best Cryptocurrency Investments for 2024

BlockDAG's $28M Outshines The Others: Assessing The Impact Of Aptos's Recent Token Unlock And XRP's…

3 hours ago

BNB Price Surge, Dogwifhat Decline: BlockDAG Poised as the Best Upcoming Crypto Investment

BNB's Rising Price, Dogwifhat's Decline: Why BlockDAG is the Next Big Crypto In 2024?  As…

5 hours ago

BlockDAG Leads the Future of Crypto With Updated Security Protocols & $28M Presale Amid XRP Struggles & Rising TRON Price

The cryptocurrency market is filled with potential for those who are well-informed and decisive. As…

9 hours ago

Learn what’s up with Binance (BNB), Worldcoin (WLD), and  DTX Exchange (DTX)

Binance (BNB) Announces 54th Project, Worldcoin (WLD) to Release Tokens, while DTX Exchange (DTX) Eyes…

11 hours ago

Raboo ICO Fuels Crypto Investment as BOME and Memecoin (MEME) Eye Explosive Growth

The crypto investment world is on fire right now with the influx of various meme…

12 hours ago