Skip to content
July 21, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Malware
  • Dr.Web founds 3 new Trojan on Google Play that perform phishing attacks
  • Malware

Dr.Web founds 3 new Trojan on Google Play that perform phishing attacks

Do Son March 20, 2018 3 minutes read
phishing attacks
Add Daily CyberSecurity as a preferred source on Google

Antivirus company Dr.Web’s security experts discovered three new Android Trojans in the Google Play store last week. They were detected as Android.Click.415, Android.Click.416 and Android.Click.417 respectively.

The malicious application used to spread the Trojan horse pretends to be a legitimate Android application. After installation, it can accept the command of the attacker to load and display any web page. According to Dr.Web’s security experts, this feature can be used to launch phishing attacks.

Security experts said that the detected malicious application has the same name and similar icon as the legitimate application. Take Android.Click.415, the malicious application used to spread the Trojan has imitated several popular legitimate Android applications, such as QIWI app (Russian payment service provider), Odnoklassniki and VK (Russian popular social network) and NTV. (Russian Independent Television Station). On the left is the description page of the malicious application in the Google Play Store, and on the right is the description page of the legitimate application:

Each time a malicious application launches, it connects to a command and control (C&C) server. The server responds to the “none” parameter or sends a web page link specified by the attacker. When a parameter is received, the malicious application extracts multiple images from its resources and displays it to the victim.

If a malicious application receives a web page link from a C&C server, they will load the web page and display it. Then, open the page directly in the application via WebView. In this case, these web pages may be fake login interfaces for some online banking systems or social networks, which exposes victims to the risk of phishing attacks.

Next, let’s take a look at how Trojan horses detected as Android.Click.416 and Android.Click.417 work.

Dr.Web’s security experts discovered a total of more than 70 malicious applications for the spread of the two Trojans, with over 270,000 downloads. Similar to the malicious applications that spread Android.Click.415, they are also disguised as legitimate Android applications. These applications may be some mobile games, recipes, and weaving manual applications.

Like Android.Click.415, after establishing a foothold on the victim device, Android.Click.416 and Android.Click.417 will also display any web page by accepting a command response from the C&C server.

 

In addition, in the discovery of Dr.Web security experts, at least four software developers participated in the distribution of these Trojans. Their usernames on the Google Play Store are Tezov apps, Aydarapps, Chmstudio, and SVNGames.

Dr.Web has already communicated these findings to the Google team and also reminded users that even if they download applications from a reliable source such as the Google Play Store, they also need to pay attention to the name of the software developer and the comments under the software description.

Source, Image: drweb

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.


We respect your inbox. Unsubscribe anytime.

Related coverage

  • DeadBolt ransomware is threatening QNAP users
  • PXA Stealer: New Malware Targets Governments and Education Across Europe and Asia
  • 10 Million Dollar Bounty: The Hunt for Ransomware Kingpin Mikhail Matveev
  • Hackers Exploit Google Ads to Spread Malware Disguised as Popular Software
  • Critical Linksys Router Flaw (CVE-2025-34037, CVSS 10.0) Actively Exploited by TheMoon Worm
Track all actively exploited CVEs →

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: android Google Play phishing attacks

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-50522CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    Admin intel📅 Updated: Jul 21, 2026
  • CVE-2026-63030CVSS 9.8
    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion...
    Admin intel📅 Updated: Jul 21, 2026
  • CVE-2026-60137CVSS 5.9
    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter...
    Admin intel📅 Updated: Jul 21, 2026
  • CVE-2026-6875CVSS 9.5
    ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability...
    Admin intel📅 Updated: Jul 18, 2026
  • CVE-2026-39808CVSS 9.8
    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox...
    CISA KEV📅 Added to KEV: Jul 16, 2026
  • CVE-2026-25089CVSS 9.8
    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox...
    CISA KEV📅 Added to KEV: Jul 16, 2026
  • CVE-2026-58644CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    CISA KEV📅 Added to KEV: Jul 16, 2026
  • CVE-2023-4346CVSS 7.5
    KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to...
    CISA KEV📅 Added to KEV: Jul 15, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-1617CVSS 9.8
    Improper neutralization of special elements used in an SQL command ('SQL injection')...
  • CVE-2026-13439CVSS 9.8
    The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to...
  • CVE-2026-64625CVSS 9.8
    AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps...
  • CVE-2026-53595CVSS 9.4
    FreeScout is a free help desk and shared inbox built with PHP's...
  • CVE-2026-44231CVSS 9.1
    RT is an open source, enterprise-grade issue and ticket tracking system. Versions...
  • CVE-2026-63766CVSS 9.8
    GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where...
  • CVE-2026-63767CVSS 9.8
    ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization...
  • CVE-2026-39878CVSS 9.3
    Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability...
  • CVE-2026-54051CVSS 9.9
    Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent...
  • CVE-2026-41252CVSS 9.8
    xrdp is an open source RDP server. Versions 0.10.6 and prior contain...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.