Wednesday, Aug 19, 2026
English News
  • Hyderabad
  • Telangana
  • AP News
  • India
  • World
  • Entertainment
  • Sport
  • Science and Tech
  • Business
  • Rewind
  • ...
    • NRI
    • View Point
    • cartoon
    • My Space
    • Education Today
    • Reviews
    • Property
    • Lifestyle
E-Paper
  • NRI
  • View Point
  • cartoon
  • My Space
  • Reviews
  • Education Today
  • Property
  • Lifestyle
Home | Andhra Pradesh | Android Users Beware Latest Malware Utilizes Ocr To Steal Sensitive Data

Android users beware: Latest malware utilizes OCR to steal sensitive data

Trend Micro, the cybersecurity software company, has reported that both malware instances employ identical network infrastructure and certificates, suggesting they were created by the same threat actors.

By IANS
Updated On - 30 July 2023, 12:43 PM
Android users beware: Latest malware utilizes OCR to steal sensitive data
Representational Image.
whatsapp facebook twitter telegram

San Francisco: Two new malware families targeting Android users have been discovered on Google Play, named CherryBlos and FakeTrade, which are designed to steal cryptocurrency credentials and funds or conduct scams using optical character recognition (OCR), a new report has said.

According to cybersecurity software company Trend Micro, both malware uses the same network infrastructure and certificates, indicating the same threat actors created them.

Also Read

  • Android malware ‘Goldoson’ infects 60 Google Play apps with 100 mn downloads
  • Android malware mimics ChatGPT apps to target smartphone users
  • This Android malware switches off Wi-Fi and drain mobile wallet

The malicious apps are distributed through a variety of channels, including social media, phishing websites, and shopping apps on Google Play.

CherryBlos malware was first seen spread in April 2023 in the form of an APK (Android package) file marketed on Telegram, Twitter, and YouTube as AI tools or cryptocurrency miners.

The names used for the malicious APKs are GPTalk, Happy Miner, Robot999, and SynthNet, according to the report.

The downloaded malware CherryBlos (AndroidOS_CherryBlos.GCL), named because of the unique string used in its hijacking framework, can steal cryptocurrency wallet-related credentials, and replace victims’ addresses while they make withdrawals.

In addition, a more interesting feature can be enabled, which uses OCR to remove text from photos and images.

“Once granted, CherryBlos will perform the following two tasks — Read pictures from the external storage and use OCR to extract text from these pictures, and upload the OCR results to the C&C server at regular intervals,” the researchers wrote.

Moreover, another campaign that employed several fraudulent money-earning apps — first uploaded to Google Play in 2021 — involved the FakeTrade malware.

Researchers discovered links to a Google Play campaign in which 31 scam apps known as “FakeTrade” used the same C2 network infrastructures and certifications as the CherryBlos apps, the report said.

These apps employ shopping themes or money-making entices to deceive users into watching commercials, committing to premium subscriptions, or topping up their in-app wallets while never allowing them to pay out the virtual prizes.

The applications have a similar interface and mostly target customers in Malaysia, Vietnam, Indonesia, the Philippines, Uganda, and Mexico, with the majority of them appearing on Google Play between 2021 and 2022.

  • Follow Us :
  • Tags
  • Android
  • cybersecurity
  • Google Play
  • malware

Related News

  • WhatsApp users targeted with fake RBI, MCA files in malware campaign: Centre

    WhatsApp users targeted with fake RBI, MCA files in malware campaign: Centre

  • Meta’s AI model hacked external system during cybersecurity test

    Meta’s AI model hacked external system during cybersecurity test

  • TRAI launches revamped MyCall app with real-time call quality feedback features

    TRAI launches revamped MyCall app with real-time call quality feedback features

  • Google selects 20 AI startups for 2026 Play Accelerator India programme

    Google selects 20 AI startups for 2026 Play Accelerator India programme

Latest News

  • Andhra govt allays fears over data centres affecting water supply to Vizag

    3 minutes ago
  • Shakira visits earthquake-hit schools in Colombia, announces 1 million usd relief effort

    5 minutes ago
  • Scottish MP Martyn Day marries Keralite Nitin Chand at Guruvayur

    14 minutes ago
  • Honourable reception awaits Bangladesh PM Rahman if he visits India, says envoy

    21 minutes ago
  • 2026 Cincinnati Open: Sabalenka, Andreeva and Gauff advance to fourth round

    23 minutes ago
  • Trump orders halt to Iran talks: Report

    32 minutes ago
  • Ravi Teja will be seen in a never-before avatar in ‘Irumudi’: Shiva Nirvana

    34 minutes ago
  • Warehouse burns near Moscow. In Ukraine, drone crews prepare to strike again

    41 minutes ago

company

  • Home
  • About Us
  • Contact Us
  • Privacy Policy

business

  • Subscribe

telangana today

  • Telangana
  • Hyderabad
  • Latest News
  • Entertainment
  • World
  • Andhra Pradesh
  • Science & Tech
  • Sport

follow us

  • Telangana Today Telangana Today
Telangana Today Telangana Today

© Copyrights 2024 TELANGANA PUBLICATIONS PVT. LTD. All rights reserved. Powered by Veegam