UPDATED 23:04 EST / SEPTEMBER 24 2018

APPS

Malicious apps with hidden cryptomining script found in Google Play – again

Despite numerous promises from Google LLC and occasional crackdowns, cryptojacking apps — apps that hijack a mobile device to mine cryptocurrencies — have once again been discovered in the Google Play store.

A week after a report from the Cyber Threat Alliance found that cryptomining detections spiked 459 percent this year, securities researcher at Sophos Ltd. Monday said they’ve discovered at least 25 Android apps in the official Google Play store containing code that mines cryptocurrencies in the background.

The apps were disguised as games, utilities and educational apps, but unbeknown to downloaders, they contain embedded code from Coinhive that enables the app to mine for the Monero cryptocurrency. Eleven of the 25 apps were preparation apps for standardized tests given in the U.S. published by a single developer account called “Gadgetium.”

Combined, the discovered apps are believed to have been downloaded around 120,000 times.

In an arguable positive, the apps were found to be using throttling to limit processor usage by mining. That means they were less likely to be detected or cause mayhem in the process such as device overheating, high battery drain and overall device sluggishness, something seen by some code used in cryptojacking attacks last year.

The Sophos researchers said they informed Google of the apps in August, but only a few have been removed, leaving the majority available for download.

In Google’s defense, it is a numbers game with Google Play and detecting these apps is sometimes like finding a needle in a haystack. Nonetheless, Sophos researchers argued, if they can find them, so should Google. In this case, a simple scan for Coinhive code embedded in apps allowed the researchers to discover the malicious apps.

Image: Sophos

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.