Candy Crush and Other Games Infected With Dangerous Trojans

Share this article
Wikimedia Commons

Wikimedia Commons

ESET Press Release – ESET recently discovered an interesting stealth attack on Android users. Cybercriminals created fake version of popular arcade games such as Plants vs Zombies, Candy Crush or Super Hero Adventure to deliver backdoor Trojan directly onto victims‘ devices. ESET offers in-depth analysis of this Trojan dropper on WeLiveSecurity.com. These malicious downloads were made available on the official Google Play Store.

ESET telemetry detects fake versions of arcade games that install the Trojan as Android/TrojanDropper.Mapin and the Trojan itself as Android/Mapin. This malware is capable of taking control of victim’s device and make it part of a botnet under attacker’s control. Moreover, Android/Mapin has one addition that makes the detection more complicated – a timer that delays the execution of the malicious payload so victims won’t suspect a game infected their device.

„Some variants of Android/Mapin takes minimum of three days to achieve full Trojan functionality. It may also be one of the reasons why the TrojanDownloader was able to evade Google’s Bouncer malware prevention system,“ says Lukáš Štefanko, Malware Researcher at ESET.

Android/Mapin was able to sneak in Google Play and several alternative Android markets as fake versions of the popular games: Plants vs zombies, Plants vs Zombies 2, Subway suffers, Traffic Racer, Temple Run 2 Zombies, Super Hero Adventure, Candy Crush, Jewel Crush, Racing Rivals and others. Trojan pretends to be a Google Play Update or an application named Manage Settings. According to Štefanko there is possibility that this threat is still under development and the trojan may be improved in the future.

On WeLiveSecurity.com, ESET added:

The most interesting thing about this Android Trojan is that it was available for download from the official Google Play Store by the end of 2013 and 2014 as Hill climb racing the game, Plants vs zombies 2, Subway suffers, Traffic Racer, Temple Run 2 Zombies, and Super Hero Adventure by the developers TopGame24h, TopGameHit and SHSH. The malware was uploaded to Google Play on November 24-30, 2013 and November 22, 2014.

Print Friendly, PDF & Email

Comments