Android device users have once again found themselves in the crosshairs of cybercriminals. This time, they are being targeted by a threat masquerading as a seemingly harmless application that turns a phone into a flashlight (Flashlight LED Widget).
According to analysis by experts from ESET, the malicious application's goal is to steal login credentials for, among others, the Commbank banking app, Facebook, Instagram, and WhatsApp. Additionally, the app can spy on the user and record what they do in the form of photos.
A seemingly innocent app
The threat detected by ESET as Trojan.Android/Charger.B, in addition to providing the promised flashlight function, has additional capabilities - it steals login credentials for banking apps such as Commbank, NAB, and Westpac Mobile Banking, as well as social media platforms including Facebook and Instagram. The threat can display screens to the user that look almost identical to the original login screens of online banking apps. The malicious app can then block infected devices to hide its malicious activity, intercept SMS messages used to authorize transactions, and display fake notifications to bypass two-factor authentication. All these actions are intended to steal money from users' accounts. The threat can infect all versions of Android.
How the malicious app operates
After installation and launch, the app requests administrator privileges. This allows it to hide its icon and appear on the device screen only as a flashlight widget. After the Android flashlight app is launched, its malicious functions are decrypted and run in the background – the user doesn't even know that a very clever spy is starting to operate on their smartphone. The Trojan then registers the device on the cybercriminals' server, sends information about the device, and takes photos of the owner using the front-facing camera. An interesting fact is that if a device is infected but its location points to Russia, Ukraine, or Belarus, the command server deactivates the threat. The cybercriminals behind this app likely come from those countries and want to avoid action by local law enforcement.
How can I remove the malicious app?
If you recently downloaded the Flashlight app from Google Play, you can check whether your device has been infected. To do so, go to Settings > App Manager > Flashlight Widget.
Finding the app is easy. Unfortunately, uninstalling it is not. The Trojan tries to prevent removal by not allowing the user to revoke administrator privileges – which is necessary to remove the app. The app can only be removed by starting the device in safe mode.