How Spies Plants Malware Into the Google Play Store
Updated: May 10
Malicious Android apps from the so-called PhantomLance campaign targeted hundreds of users, and at least two slipped past Google's defenses.
GOOGLE'S PLAY STORE for Android apps has never had a reputation for the strictest protection from malware. Shady adware and even banking trojans have managed over the years to repeatedly defy Google's security checks. Now security researchers have found what appears to be a more rare form of Android abuse: state-sponsored spies who repeatedly slipped their targeted hacking tools into the Play Store and onto victims' phones. At a remote virtual version of its annual Security Analyst Summit, researchers from the Russian security firm Kaspersky today plan to present research about a hacking campaign they call PhantomLance, in which spies hid malware in the Play Store to target users in Vietnam, Bangladesh, Indonesia, and India. Unlike most of the shady apps found in Play Store malware, Kaspersky's researchers say, PhantomLance's hackers apparently smuggled in data-stealing apps with the aim of infecting only some hundreds of users; the spy campaign likely sent links to the malicious apps to those targets via phishing emails. "In this case, the attackers used Google Play as a trusted source," says Kaspersky researcher Alexey Firsh. "You can deliver a link to this app, and the victim will trust it because it’s Google Play." Kaspersky says it has tied the PhantomLance campaign to the hacker group OceanLotus, also known as APT32, widely believed to be working on behalf of the Vietnamese government. That suggests the PhantomLance campaign likely mixed spying on Vietnam's Southeast Asian neighbors with domestic surveillance of Vietnamese citizens. Security firm FireEye, for instance, has linked OceanLotus to previous operations that targeted Vietnamese dissidents and bloggers. FireEye also recently spotted the group targeting China's Ministry of Emergency Management as well as the government of the Chinese province of Wuhan, apparently searching for information related to Covid-19. The first hints of PhantomLance's campaign focusing on Google Play came to light in July of last year. That's when Russian security firm Dr. Web found a sample of spyware in Google's app store that impersonated a downloader of graphic design software but in fact had the capability to steal contacts, call logs, and text messages from Android phones. Kaspersky's researchers found a similar spyware app, impersonating a browser cache-cleaning tool called Browser Turbo, still active in Google Play in November of that year. (Google removed both malicious apps from Google Play after they were reported.) While the espionage capabilities of those apps was fairly basic, Firsh says that they both could have expanded. "What's important is the ability to download new malicious payloads," he says. "It could extend its features significantly." Kaspersky went on to find tens of other, similar spyware apps dating back to 2015 that Google had already removed from its Play Store, but which were still visible in archived mirrors of the app repository. Those apps appeared to have a Vietnamese focus, offering tools for finding nearby churches in Vietnam and Vietnamese-language news. In every case, Firsh says, the hackers had created a new account and even Github repositories for spoofed developers to make the apps appear legitimate and hide their tracks. In total, Firsh says, Kaspersky's antivirus software detected the malicious apps attempting to infect around 300 of its customer's phones. In most instances, those earlier apps hid their intent better than the two that had lingered in Google Play. They were designed to be "clean" at the time of installation and only later add all their malicious features in an update. "We think this is the main strategy for these guys," says Firsh. In some cases, those malicious payloads also appeared to exploit "root" privileges that allowed them to override Android's permission system, which requires apps to ask for a user's consent before accessing data like contacts and text messages. Kaspersky says it wasn't able to find the actual code that the apps would use to hack Android's operating system and gain those privileges.
When WIRED reached out to Google for comment, the company responded in a statement, saying, "We appreciate the work of the researchers in sharing their findings with us. We've since taken action against all the apps they identified." Once Kaspersky had identified the PhantomLance apps, its researchers were able to match their code with older malware used by OceanLotus, which has been active since at least 2013. The apps shared characteristics with Android malware that Chinese security firm Antiy Labs found in an unofficial Vietnamese app store in 2014, for instance, and the spyware's command-and-control domains overlapped with desktop-targeted OceanLotus malware identified previously by security firms Trend Micro, ESET, and Palo Alto Networks. PhantomLance would hardly be the first instance of state-sponsored hackers abusing Google Play to distribute their spy tools. The nonprofit Security Without Borders found last year that one hacking contractor was hiding Android spy tools in Google Play on behalf of the Italian government. And last November, Google revealed that the notorious Russian hacker group Sandworm had in late 2017 snuck several pieces of malware into Google Play targeting Ukrainians and Koreans—the latter perhaps as part of Russia's sabotage operations focused on the 2018 Olympics in Pyeongchang. But the PhantomLance operation is particularly disturbing because it shows that even after Google removed much of OceanLotus's spyware from Google Play, it didn't detect at least two of the malicious apps, says Kaspersky's Kurt Baumgartner. "Even after this group had been reported as active on Google Play, they were still active and hosting viable variants into late 2019," Baumgartner says. "To me, this says something about the walled garden approach—and how confidence in walled gardens is shaken."