Trojan targets half a million Pokémon Go fans

Kaspersky Lab warns that thousands of Pokémon Go fans have been infected by malicious app

Half a million Pokmon Go fans could be at risk from a trojan that targeted players with a fake game guide.

The success of Pokmon Go has made it a target for hackers, who are taking advantage of the craze to target unwitting players, said Kaspersky Lab.

A "Guide for Pokmon Go" loaded with malware and listed on the official Google Play store has been downloaded 500,000 times and infected at least 6,000 phones, with the hidden malware able to seize root access on Android handsets. 

Advertisement - Article continues below

Google removed the app from its store after Kaspersky Lab notified it. 

The malware is clever enough to be patient to avoid detection, with the trojan waiting for just the right time to run, and checking if the target is worth its while or if it's trapped in a sandbox and the attack is already thwarted. Once installed, it installs other apps and displays ads.

So far, there have been only 6,000 successful infections, in Russia, India and Indonesia, but as it's targeted to English speakers, Kaspersky believes there may be victims around the world. 

"Victims of this trojan may, at least at first, not even notice the increase in annoying and disruptive advertising, but the long term implications of infection could be far more sinister,"  said Roman Unuchek, senior malware analyst at Kaspersky Lab.

Advertisement
Advertisement - Article continues below

"If you've been hit, then someone else is inside your phone and has control over the OS and everything you do and store on it. Even though the app has now been removed from the store, there's up to half a million people out there vulnerable to infection and we hope this announcement will alert them to the need to take action."

Advertisement - Article continues below

The security firm advised anyone infected to backup their data and reset their device.

Other security experts said the attack was to be expected because of the attention the game has seen. "There's no surprise that an app as popular as Pokmon Go has spawned associated malware," said Tim Erlin, director at security firm Tripwire. "Anytime we see a large event or significant trend in technology, cybercriminals do their best to take advantage of it."

"Consumers should protect themselves by avoiding third-party app stores that don't offer the same protections around available apps," Erlin added. "Even within the well-protected app stores caution is well advised. Maybe don't be the first, or even the hundredth, person to download that app."

Featured Resources

Successful digital transformations are future ready - now

Research findings identify key ingredients to complete your transformation journey

Download now

Cyber security for accountants

3 ways to protect yourself and your clients online

Download now

The future of database administrators in the era of the autonomous database

Autonomous databases are here. So who needs database administrators anymore?

Download now

The IT expert’s guide to AI and content management

Your guide to the biggest opportunities for IT teams when it comes to AI and content management

Download now
Advertisement

Recommended

Visit/security/cyber-security/355267/zoom-hires-ex-facebook-cso-to-boost-platform-security
cyber security

Zoom hires ex-Facebook CSO Alex Stamos to boost platform security

8 Apr 2020
Visit/security/vulnerability/355236/hp-support-assistant-flaws-leave-windows-devices-open-to-attack
vulnerability

HP Support Assistant flaws leave Windows devices open to attack

6 Apr 2020
Visit/security/cyber-security/355234/safari-bug-let-hackers-access-cameras-on-iphones-and-macs
cyber security

Safari bug let hackers access cameras on iPhones and Macs

6 Apr 2020
Visit/software/video-conferencing/355229/zoom-we-moved-too-fast
video conferencing

Zoom CEO admits company "moved too fast" as privacy issues mount

6 Apr 2020

Most Popular

Visit/mobile/mobile-phones/355239/microsofts-patent-design-reveals-a-mobile-device-with-a-third-screen
Mobile Phones

Microsoft patents a mobile device with a third screen

6 Apr 2020
Visit/security/cyber-security/355271/microsoft-gobbles-up-corpcom-domain-to-keep-it-from-hackers
cyber security

Microsoft gobbles up corp.com domain to keep it from hackers

8 Apr 2020
Visit/server-storage/servers/355254/a-critical-flaw-in-350000-microsoft-exchange-remains-unpatched
servers

A critical flaw in 350,000 Microsoft Exchange remains unpatched

7 Apr 2020