lifescienceforever

Joker – Dangerously appearing a true Villain in Android





History of Joker – The Malware 

The Joker malware is a ransomware that was first
reported in 2018 and targeted Android devices. The malware classifies itself as
a variant of the Serval Ransomware, which is also known as the Android
Ransomware. It has been found to create copies of important files and demands a
ransom of $50 in order to get them back. 


This malware is very hard to detect because it
encrypts itself from the inside out, meaning it does not have any external
evidence on its application until it executes. It also hides its processes from
being seen by the user, meaning that regular installation detection tools will
not be able to tell if a device has been infected or not. 


The Joker malware is a new type of ransomware
that encrypts the user’s data and demands for ransom in exchange for the
decryption key. The developers of this malware are still unknown, but what they
want is clear – to make money. 


Joker malware is a form of Android malware that
takes screenshots of the phone, monitors text messages, records calls, and then
sends this information to a remote location. It also tries to send any
sensitive banking information the user inputs. Joker Malware was first
discovered in December 2013 and can be rooted in Samsung Galaxy S3 devices. 


Appearance
in 2021
 


This
malware first appeared in September 2020, when it was discovered in 24 Android
apps. Before Google banned them, the apps had accumulated over 500,000
downloads. At this time, the malware has infected people in over 30 nations
throughout the world, including the United States, Brazil, and Spain, among
others. 


It was discovered in eight new apps in June 2021. All of those
apps had been withdrawn from the Google Play Store by the time the article was
published. The software is mainly shared by scanner, wallpaper, and message
apps that wind up in the Play Store, according to the research. 


In August 2021, the ‘Joker’ malware debuted shortly after the
previous event. This time, it was discovered in 16 applications available on
the Google Play Store. Again, the majority of the apps were PDF scanners, SMS
apps, and communications apps in general. It was unclear how many people
downloaded those apps before they were removed this time. 


A Squid Game-related app with Joker malware was discovered in the
Google Play Store in October 2021. “Squid Wallpaper 4K HD” was the
name of the programme, which was withdrawn after roughly 5,000 people
downloaded it. 


The malware reappeared in November 2021. It was discovered in
seven apps on the Google Play Store. Over 50,000 people have downloaded one of them.
The Joker reappeared in December of 2021. This time, it was found in an app
that had over 500,000 downloads (at the time it was deleted) and was available
on the Google Play Store. ‘Color Message’ is the name of the app. 


New Version 


The Joker virus has reappeared in the Google Play store. The Joker
malware affected multiple apps last year, as well as earlier this year in
February, which Google later banned from the Play store. The malware has
returned to the Google Play store and has infected several apps that you may
have installed on your phone. As many as 11 apps have been removed from the
Google Play store. 


Among
the affected apps are: 

com.imagecompress.android 
com.relax.relaxation.androidsms 
com.cheery.message.sendsms 
com.peason.lovinglovemessage 
com.contact.withme.texts 
com.hmvoice.friendsms 
com.file.recovefiles 
com.LPlocker.lockapps 
com.remindme.alram 
com.training.memorygame 


The
Joker malware steals money from victims by inadvertently enrolling them in
premium memberships. It collects the victim’s SMS messages including OTP to
validate purchases and then simulates user interaction with adverts without
their awareness. This means that the user may be unaware that they have been
signed up for a paid membership service and that money has been debited from
their account. 


“Joker keeps making its way into Google’s official
application market as a consequence of modest tweaks to its code, allowing it
to sneak past the Play store’s security and vetting obstacles,” according
to Check Point. Two new Joker Dropper and Premium Dialer malware types have
been found in the Play Store this time. These were discovered hidden inside “software
that appeared to be authentic.” 


The malicious actor behind Joker “took an old approach from
the traditional PC threat landscape and utilised it in the mobile app
market to avoid detection by Google,” according to the research. 


This time, the Joker virus had two parts: a
“Notification Listener service that is part of the
original programme, and a dynamic dex file loaded from the
C&C server to complete the user’s registration to the services.” 


Symptoms and Safety Measures 


Most of the time, based on what we’ve observed
thus far, Jokar Make it Sure that you won’t notice anything. Well, you’ll
notice the damage whenever you detect a difference in your money, but because
this virus acts in the background, it has the potential to cause a lot of harm
without your knowing. It will ask for some permissions when you install
the programme, but that’s something that every app does. You might find
that your device has slowed down a little on occasion, which could be the case
with phones with lesser technology. You might also find that new apps appear on
your phone, albeit this is uncommon in the app launcher. It will be hidden from
your app list if this happens. However, due to several limits in place, this is
unlikely. After all, it isn’t how the ‘Joker’ generally works. 


Downloading new programmes that appear
to be shady is not a good idea. As previously stated, this malware typically
lurks in apps that purport to be SMS apps, chat apps, PDF scanners, and other
similar apps. It’s possible to discover it in image editing programmes and
other places. Check the reviews before downloading an app, and if at all
possible, avoid downloading apps as soon as they are sent to the Google Play
Store. Unfortunately, this will have an impact on the creators, but at the very
least, you’ll have more time to make sure it’s not a fraud. Alternatively, look
into the origins of the app. Feel free to download it if it comes from
a source you know and trust. Also, keep in mind the permissions that
a given programme requests. If they appear to be impractical for that
type of programme, you may want to reconsider installing it. 

Picture of swapnilpatane30@gmail.com

swapnilpatane30@gmail.com

Facebook
X
LinkedIn
Pinterest
WhatsApp
Email

You May Like To Read This