An application that looks like the legitimate Netflix app for Android is actually a text-book case of an information- stealing Trojan, according to Symantec Malware masquerading as a popular Netflix application for Android is actually a social engineering scam that utilizes a classic Trojan to get account information and passwords. Symantec warned about the malware in a blog post this week, noting it is a clear example of how far mobile malware has come. [Social engineering: 3 mobile malware techhiques]The Android.Fakeneflic exploit, according to Symantec’s Irfan Asrar, “is a text book case of an information stealing Trojan that targets account information. The malicious app is not too difficult to understand. Despite the fact that there are multiple permissions being requested at the time of installation — identical to the permissions required by the actual app — our analysis shows that this is, in fact, a red herring, probably used to add to the illusion that the end user is dealing with the genuine article.”The phony application was found on an Android user forum and is not available in the official Android app market. Asrar says the fake app is divided into two main parts; a splash screen followed by a login screen where the user information is captured and posted to a server. Asrar said it appeared that the server where the data was being posted is offline. “Furthermore, there appears to be no attempt to verify whether the data entered by an unsuspecting user was accurate or not,’ explained Asrar. “Once a user has clicked on the “Sign in’ button, they are presented with a screen indicating incompatibility with the current hardware and a recommendation to install another version of the app in order to resolve the issue. There is no attempt to automatically download the recommended solution. Upon hitting the “Cancel” button, the app attempts to uninstall itself. Any attempt to prevent the uninstall process results in the user being returned to the previous screen with the incompatibility message.”[More scams in 5 more dirty tricks: Social engineers’ latest pick up lines]The fake app had the perfect opportunity to take advantage because of the initial limited release of the official Netflix application for Android, said Asrar. The Netflix app was initially pushed only to certain devices that provided the best user experience and only recently was it made available on the Android app market. But the popularity of the service prompted several unsanctioned developers to attempt to port a pirated copy of the app to run on devices that were not officially supported. “A gap in availability, combined with the large interest of users attempting to get the popular service running on their Android device, created the perfect cover for Android.Fakeneflic to exploit,” said Asrar. Related content news SpecterOps to use in-house approximation to test for global attack variations The new offering uses atomic tests and in-house approximation in purple team assessment to test all known techniques of an attack. By Shweta Sharma Sep 28, 2023 3 mins Penetration Testing Network Security Security news New Trojan ZenRAT masquerades as Bitwarden password manager A report by Proofpoint identifies the new Trojan as undocumented and possessing information-stealing capabilities. By Lucian Constantin Sep 28, 2023 4 mins Cyberattacks Hacking Data and Information Security news UK Cyber Security Council CEO reflects on a year of progress Professor Simon Hepburn sits down with broadcaster ITN to discuss Council’s work around cybersecurity professional standards, careers and learning, and outreach and diversity. By Michael Hill Sep 27, 2023 3 mins Government Data and Information Security Security Practices news FIDO Alliance certifies security of edge nodes, IoT devices Certification demonstrates that products are at low risk of cyberthreats and will interoperate securely. By Michael Hill Sep 27, 2023 3 mins Certifications Internet Security Security Hardware Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe