1 year, 5 months ago

Why users should avoid downloading APK files on Android devices

A new cybercrime operation named “SecuriDropper” was found using a method that bypasses the “Restricted Settings” feature in Android devices to install malware and obtain access to Accessibility Services. The method used by cybercriminals is still present in Android 14 and uses session-based installation API for the malicious APK files, which installs them in multiple steps, involving a “base” package and various “split” data files, a report from Bleeping Computer said. The second stage of delivering the malware includes deceiving users by prompting them to click on a “Reinstall” button after displaying a fake error message about the APK files installation. To protect against such attacks, Android users are advised to avoid downloading APK files from unknown sources or publishers they do not trust.

Discover Related