The Star Malaysia - Star2

QR code reader apps hit by malware

- By SHARMILA NAIR bytz@thestar.com.my

Hundreds of thousands of Android users fell victim to malware embedded in Qr code readers apps on the Google Play store.

According to researcher­s at sophosLab, the malware called Andr/HiddnAd-AJ was found in seven apps of which six were Qr code reader apps and one was a smart compass app.

Although Google has already removed these apps from the Google Play store, it was not before they were downloaded more than 500,000 times.

“The adware part of each app was embedded in what looks at first sight like a standard Android programmin­g library that was itself embedded in the app.

“By adding an innocent-looking ‘graphics’ subcompone­nt to a collection of programmin­g routines that you’d expect to find in a regular Android program, the adware engine inside the app is effectivel­y hiding in plain sight,” according to the report.

despite the malware, the apps still worked. For instance, they could still scan Qr codes.

so if a user was just trying out an app for fun and deleted it soon after, he or she won’t be exposed to the malware as it only kicked in six hours after the installati­on.

users unlucky enough to continue using it were avalanched by adware that filled the entire screen and especially when they opened the web browser.

“For all its apparent innocence, however, this malware not only pops up ads, but can also send Android notificati­ons, including clickable links to lure users into generating ad revenue for criminals,” the report stated.

despite the hiccup, sophos advises users to stick to Google Play as the company does at least carry out some pre-acceptance checks for apps and games.

“Many off-market Android app repositori­es have no checks at all – they’re open to anyone, which can be handy if you’re looking for unusual or highly specialise­d apps that wouldn’t make it onto Google Play. But unregulate­d app repositori­es are also risky, for all the same reasons,” it stated.

 ?? — Bloomberg ?? The malware in the QR code reader app only became active six hours after installati­on.
— Bloomberg The malware in the QR code reader app only became active six hours after installati­on.

Newspapers in English

Newspapers from Malaysia