Download PDF version Contact company

Check Point Research (CPR) discovered new malware on Google’s Play Store that spreads via WhatsApp messages.  The malware is designed to automatically respond to incoming WhatsApp messages on the victim’s device, using content that the malware downloads from a remote server.

Hidden in fake Netflix app

CPR found the malware hidden in a fake Netflix application on the Play Store called FlixOnline, which promised unlimited entertainment from anywhere in the world.

If successful, the malware enables its threat actors to perform a range of malicious activities, such as spreading additional malware via malicious links, stealing credentials and data from users' WhatsApp accounts, and spreading fake or malicious messages to users. WhatsApp contacts and groups, for example, work-related groups.

Malware spreading through link 

The malware was designed to be wormable, meaning it can spread from one Android device to another after a user clicks on the malicious link in the message and downloads the malware. It works like this:    

  • Victim installs the fake FlixOnline app from Google’s Play Store which contains the malware
  • The malware changes permissions on the user’s device to enable automatic responses to new notifications on WhatsApp
  • The malware responds to every WhatsApp message the victim receives with an automatic reply crafted by the threat actors
  • In this campaign, the response was a fake Netflix site that phished for users credentials and credit card information

Automated response

The malware sent the following automatic response to its victims incoming WhatsApp messages, attempting to lure others with the offer of a free Netflix service: 2 Months of Netflix Premium Free at no cost For REASON OF QUARANTINE (CORONA VIRUS)* Get 2 Months of Netflix Premium Free anywhere in the world for 60 days. 

Fake service within the application

CPR found the malware hidden within an application on Google Play called FlixOnline

CPR found the malware hidden within an application on Google Play called FlixOnline. The app turned out to be a fake service that claimed to allow users to view Netflix content from around the world on their mobiles.

However, instead of allowing the mobile user to view Netflix content, the application is actually designed to monitor a user’s WhatsApp notifications, sending automatic replies to a user’s incoming messages using content that it receives from a remote server.

Innovative hijack technique 

Aviran Hazum, Manager of Mobile Intelligence at Check Point Software said, “The malware’s technique is new and innovative, aiming to hijack users. Whatsapp account by capturing notifications, along with the ability to take predefined actions, like dismiss or reply via the Notification Manager.”

“The fact that the malware was able to be disguised so easily and ultimately bypass Play Store’s protections raises some serious red flags. Although we stopped one campaign using this malware, the malware may return hidden in a different app.”

Mobile security solution

Users should be wary of download links or attachments that they receive via WhatsApp or other messaging apps

The Play Store’s protections can only go so far, so mobile users need a mobile security solution. Luckily, we detected the malware early, and we quickly disclosed it to Google who also acted quickly.

Users should be wary of download links or attachments that they receive via WhatsApp or other messaging apps, even when they appear to come from trusted contacts or messaging groups. If you think you’re a victim, we recommend immediately removing the application from devices and changing all passwords.

App taken down by Google

CPR responsibly disclosed its findings to Google. The malicious application was subsequently taken down by Google. Over the course of two months, the FlixOnline app was downloaded approximately 500 times. CPR has shared its research findings with WhatsApp, though there is no vulnerability on WhatsApp’s end.

 Security Tips for Android Users

  • Install a security solution on your device
  • Download applications only from official markets
  • Keep your device and apps up to date
Download PDF version Download PDF version

In case you missed it

Visual AI Company AnyVision Changes its Name to Oosto
Visual AI Company AnyVision Changes its Name to Oosto

AnyVision announced today that the company will change its name to Oosto. The new name reflects the company’s evolution and vision for the future which is shaped, in part, by a new collaboration with Carnegie Mellon University’s (CMU) CyLab Biometric Research Center. The CMU partnership will focus on early-stage research in object, body, and behavior recognition. Vision AI Oosto CEO, Avi Golan remarks, "Historically, the company has focused on security-related use cases for our watchlist alerting and touchless access control solutions. With the launch of Oosto, we’re looking beyond the lens of security to include ways our solutions can positively impact an organization’s safety, productivity and customer experience.” AnyVision pioneered Vision AI to automate watchlist alerting, identifying security risks as well as valuable customers in real-time to personalize customer experiences and enhance physical security. The rebranded Oosto will leverage the power of Vision AI to enhance the safety of customers, guests, and employees. Solutions include touchless access control, video analytics, and new flavors of video-based recognition (object, body, and behavioral recognition), which deliver the insights and alerts to protect pivotal stakeholders from bad actors and security threats. Partnership with CyLab Biometric Research Center The company’s research partnership with Carnegie Mellon University’s (CMU) CyLab Biometric Research Center will focus on advanced object classification and behavior recognition algorithms for commercial use cases. This collaboration will help Oosto address a broad range of safety-related use cases, including object detection (e.g., weapons on school grounds) and behavioral analysis (e.g., when someone falls down). As part of the partnership, Marios Savvides, a Professor of Electrical and Computer Engineering (ECE) and founder and director of the Biometrics Center at CMU, will join Oosto as the Chief AI Scientist to expand Oosto’s AI team led by CTO, Dieter Joecker. “We were impressed by Oosto's commitment to the fair and ethical use of the technology, preserving user privacy, and creating safer spaces for everyone,” said Professor Marios Savvides. “These shared values make Oosto an ideal research partner for CMU to advance object, body, and behavioral recognition and to positively impact our collective safety.” Long histoy in artificial intelligence Over the past 10 years, more than 400 startups linked to CMU have raised more than $7 billion in funding. CMU has a long history in artificial intelligence including the creation of the first AI computer program in 1956 and pioneering work in self-driving cars, facial recognition, and natural language processing. ECE Professor Marios Savvides was named one of the “2020 Outstanding Contributors to AI” awards from the former U.S. Secretary of the Army. His research has been focused on developing core AI and machine-learning algorithms that were successfully applied for robust face detection, face recognition, iris biometrics, and most recently, general object detection and scene understanding. Savvides has generated over 35 patents and patent publications, and over 50 unpublished patent applications to date. "Under the leadership of Prof. Savvides, CMU’s CyLab Biometric Research Center has an impressive track record of successfully transferring AI research out of a lab environment and into reliable and scalable solutions," added Golan. "Visual intelligence is in its infancy and there is so much more work yet to be done. With this partnership, we now have an elite U.S.-based AI research center that will work in concert with our existing AI teams to accelerate the development of advanced deep learning algorithms and exploration of new safety-related use cases, markets, and industries, including medical, payments, and smart cities.” As part of these corporate rebranding efforts, the company is also renaming its products to OnWatch (formerly A Better Tomorrow), OnAccess (formerly Abraxas), and OnPatrol.

How Well Do Systems Meet Video Surveillance Needs In Prisons?
How Well Do Systems Meet Video Surveillance Needs In Prisons?

Keeping prisoners safely housed is among the biggest challenges the security industry faces. Correctional applications of security technology are often more extreme and require a specialized mix of technologies. We asked our Expert Panel Roundtable: What are the video security and surveillance needs in prisons, and how well do technologies meet those needs? Are there any ethical qualms about selling to prisons?

Which Technologies Are Transforming Airport Security?
Which Technologies Are Transforming Airport Security?

Air travel is returning to pre-pandemic levels. COVID and its aftermath have added new compliance and operational concerns for airport security, and social and political volatility around the world emphasises the need for constant vigilance. A range of new technologies are enhancing airport security, not to mention providing new tools to simplify processes throughout the airport. We asked our Expert Panel Roundtable: Which technologies are transforming airport security?