TECHNOLOGY
The malicious apps reached an astonishing spread between 4.5 million and 18.5 million downloads.
Almost 36.5 million Android devices have been affected with a new malware dubbed ‘Judy’. It has been found in 41 apps on the Google Play Store, and uses infected devices to generate fraudulent clicks on advertisements, generating revenues for the perpetrators behind it.
According to Check Point, some of the apps discovered resided on Google Play for several years, but all were recently updated. It is unclear how long the malicious code existed inside the apps, hence the actual spread of the malware remains unknown. The security firm also stated that the malicious apps reached an astonishing spread between 4.5 million and 18.5 million downloads.
Similar to previous malware which infiltrated Google Play, such as FalseGuide and Skinner, Judy reportedly relies on the communication with its Command and Control server (C&C) for its operation. After the firm alerted Google, the apps were removed from the Play store.
How does the Judy Malware work?
To bypass Bouncer, Google Play’s protection, the hackers create a seemingly benign bridgehead app, meant to establish connection to the victim’s device, and insert it into the app store. Once a user downloads a malicious app, it silently registers receivers which establish a connection with the C&C server. The server replies with the actual malicious payload, which includes JavaScript code, a user-agent string and URLs controlled by the malware author.
The malware opens the URLs using the user agent that imitates a PC browser in a hidden webpage and receives a redirection to another website. Once the targeted website is launched, the malware uses the JavaScript code to locate and click on banners from the Google ads infrastructure. Upon clicking the ads, the malware author receives payment from the website developer, which pays for the illegitimate clicks and traffic.
But, who is behind the Judy Malware?
CheckPoint stated that the malicious apps are all developed by a Korean company named Kiniwini, registered on Google Play as ENISTUDIO corp. The company develops mobile apps for both Android and iOS platforms. It is quite unusual to find an actual organization behind mobile malware, as most of them are developed by purely malicious actors. It is important to note that the activity conducted by the malware is not borderline advertising, but definitely an illegitimate use of the users’ mobile devices for generating fraudulent clicks, benefiting the attackers.
Mentioned below is the list of malicious apps released by Check Point:
Fashion Judy: Snow Queen style
Animal Judy: Persian cat care
Fashion Judy: Pretty rapper
Fashion Judy: Teacher style
Animal Judy: Dragon care
Chef Judy: Halloween Cookies
Fashion Judy: Wedding Party
Animal Judy: Teddy Bear care
Fashion Judy: Bunny Girl Style
Fashion Judy: Frozen Princess
Chef Judy: Triangular Kimbap
Chef Judy: Udong Maker – Cook
Fashion Judy: Uniform style
Animal Judy: Rabbit care
Fashion Judy: Vampire style
Animal Judy: Nine-Tailed Fox
Chef Judy: Jelly Maker – Cook
Chef Judy: Chicken Maker
Animal Judy: Sea otter care
Animal Judy: Elephant care
Judy’s Happy House
Chef Judy: Hotdog Maker – Cook
Chef Judy: Birthday Food Maker
Fashion Judy: Wedding day
Fashion Judy: Waitress style
Chef Judy: Character Lunch
Chef Judy: Picnic Lunch Maker
Animal Judy: Rudolph care
Judy’s Hospital: Pediatrics
Fashion Judy: Country style
Animal Judy: Feral Cat care
Fashion Judy: Twice Style
Fashion Judy: Myth Style
Animal Judy: Fennec Fox care
Animal Judy: Dog care
Fashion Judy: Couple Style
Animal Judy: Cat care
Fashion Judy: Halloween style
Fashion Judy: EXO Style
Chef Judy: Dalgona Maker
Chef Judy: ServiceStation Food
Judy’s Spa Salon
Ahead of IPL 2025, Lucknow Super Giants team, owner Sanjiv Goenka meet UP CM Yogi Adityanath
NEET PG 2025 exam date announced: NBEMS to conduct medical exam on THIS date; check details here
Navya Nanda shares adorable childhood photo with Shweta Bachchan Nanda on mother's 51st birthday
IPL 2025: Decoding the player replacement process under new BCCI rules
SHOCKING! Anonymous letter exposes sexual abuse of students by UP teacher, 59 obscene videos surface
From Home Kitchen to Global Stage: The Inspiring Journey of Prachi Dhabal Deb
Ambarish Jethwani Honored as Best CEO Real Estate Icon UAE at Prestigious Industry Event
Ratan Tata’s company to turn this 100-year-old palace into world-class hotel, it is located in...
IPL 2025: When, where and how to watch live matches for free in different countries?
Veteran Tamil actress Bindu Ghosh dies at 76
Will Donald Trump put pressure on Muhammad Yunus to crush radical Islam in Bangladesh?
Vadodara Car Accident: Drugs found in accused Rakshit Chaurasia's blood in narcotics test
Bad news for Bhavish Aggarwal, as Ola Electric shares decline over 7%, mcap falls to Rs...
‘Stupid, stupid, stupid’ Rishabh Pant recreates Sunil Gavaskar’s viral comment, WATCH here
Royal Challengers Bengaluru Unbox 2025 event: When and where to watch live telecast?
Meet woman, wife of Indian billionaire, who leads Rs 10000 crore company, known as 'tractor queen'
Amid Kim Sae-ron controversy, Kim Soo-hyun's scene cut from Good Day, check full detail
Tragedy in Jharkhand: How were four children charred to death at Chaibasa? DETAILS here
86-year-old woman duped of Rs 20.5 crore in a ‘digital arrest’ scam, here's how
Yuvraj Singh and Tino Best fight it out in International Masters final in Raipur: What went down
Tulsi Gabbard, Rajnath Singh hold talks on India-US strategic ties
IPL 2025: Delhi Capitals announces THIS former RCB skipper as their new vice-captain
Imtiaz Ali reveals why he wanted Diljit Dosanjh to play Amar Singh Chamkila: 'He knows that...'
Top 10 Best astrologers: Acharya Indravarman and premier astrologers in India
Using LMS to improve store performance metrics in retail
Planning to buy a Maruti Suzuki car? Prices set to rise by 4% from...
Shah Rukh Khan's new neighbours revealed, superstar moves next to this famous Bollywood family
Has Vande Bharat Express train's average speed dropped? Railways Minister Ashwini Vaishnaw says THIS
Was Amitabh Bachchan involved in BOFORS scandal? Startling revelations HERE!
Krissh 4: Hrithik Roshan, Rakesh Roshan's superhero franchise loses Siddharth Anand over....
Who was Daniel Kahneman? Why ‘Thinking Fast and Slow’ author is trending a year after his death
Parmish Verma opens up about racism in 'Kanneda': 'You can't understand...'
Did Shah Rukh Khan intentionally cordone off media from Jawan 'press conference'?
Man accused of grenade attack at Amritsar temple gunned down in police encounter
Salman Khan shaves off his beard after Sikandar shoot wrap, netizens believe he looks like…
Prabhas has been sidelined due to this superstar in Kalki 2, played major role in Kalki
Gautam Adani provides BIG update, Navi Mumbai International airport will now be inaugurated in...
BCCI's Medical Team head Nitin Patel resigns; more staff exits expected in coming months
Mukesh Ambani, Nita Ambani's 40th wedding anniversary cake had THIS special theme; WATCH video
‘Shah Rukh Khan has Gauri, Aamir Khan has Gauri, Salman Khan Kya dhoondega ab…’
Orry aka Orhan Awatramani among others booked by J-K police for consuming alcohol in Katra
How much will NASA pay Sunita Williams, Butch Wilmore for 9-month space stay? They will get...
NASA confirms Sunita Williams, Butch Wilmore's return date to Earth, shares splashdown time
Bhumi Pednekar gets Harvard degree, flaunts certificate: ‘Math is still not...'
Donald Trump orders dismantling of state-funded news agency Voice of America
iPhone 17 Pro Max launch date, features, camera, price In India, USA, Dubai
Lex Fridman chants 'Gayatri Mantra' on podcast, PM Modi calls it 'great', watch viral video
Hina Khan performs Umrah with brother amid cancer treatment during Ramzan: 'Dil mai aarzoo...'
Ramadan fasting vs intermittent fasting: Which is better for gut health and weight loss?
Viral Video: Monkey hilariously trades expensive phone for mango drink in Vrindavan, WATCH
Ayodhya's Ram Janmabhoomi Trust paid whopping tax of Rs 400 crore in...
Meet IAS officer, son of a dock worker, lived in Mumbai slum, later cracked UPSC exam with AIR...
Meet man who established India’s first engineering college, it is located in...
‘Punished without reason’: Mark Zuckerberg's Meta fires employee day before bonus for sharing...