Showing posts with label Malware. Show all posts
Showing posts with label Malware. Show all posts

Reason Why Adobe Flash is No Longer Safe For Your PC (Uninstall)

I will advise you to uninstall Adobe Flash on your PC as soon as possible but if you are too in love with it and don't want breakup or heartbreak, pls update it at least. This information is coming to you because there are security threats being discovered by Kaspersky that reveals exploit known as FinSpy or FinFisher targeted at computers with Adobe Flash player.

Apart from the malware threats, do you know that Adobe flash is a memory-and-battery-sucking monster that is riddled with holes and years-old unpatched code which makes it a fertile ground for hackers? Okay now you know.

So Kaspersky Labs has revealed that there has been a recent vulnerability discovered in Adobe’s Flash platform that allows hackers to plant malware. According to Kaspersky, the exploit is known as FinSpy or FinFisher and is actually a commercial product that is sold to countries and law enforcement agencies to conduct surveillance. The attacker, BlackOasis, is using the FinSpy malware through Microsoft Word documents to attack victim machines.

READ: Adobe Flash Malware Threat Reported in 2016

Now the most worrying part is the report claims that it has identified BlackOasis targets in countries like Russia, Iraq, Afghanistan, Nigeria, Libya, Jordan, Tunisia, Saudi Arabia, Iran, the Netherlands, Bahrain, United Kingdom, and Angola. So users in these regions should be extremely careful to avoid stories that touches.

Meanwhile, in their quest to curb this issue, Adobe has released a security update that is expected to fix the problem, but it wouldn't be a bad idea to uninstall Flash given that companies like Mozilla and Google have announced their plans to stop supporting flash in their browser and even Adobe has confirmed that they will be ending support for Flash in 2020.

READ: 10 Hidden Notepad Tricks You May Not Know

So the ball is in your court. Are you updating or uninstalling?

How Red Alert 2.0 Trojan Works: Android Malware That Steals Your Banking Login

The coming of internet and online activities made life more easier but I won't forget to highlight the dangers that could potentially emerge from the use of internet. Recently, we have seen an influx of malicious malware and viruses being released to affect the unsuspecting populace. One of the latest Malware to hit the internet is called "Red Alert 2.0 Trojan"

Red Alert 2.0 Trojan is a new Android malware whose main purpose is to steal your banking and social logins details from your phone. Note that Trojan horse, or Trojan, is any malicious computer programme (in this case a mobile application) that appears harmless but tricks users of its true intent so they download/install and use it. It may provide unauthorised access to your device or steal sensitive information.

HOW RED ALERT 2.0 TROJAN WORKS

The Red Alert 2.0 Trojan is hidden in plain site in apps available on third-party app stores as fake versions of legitimate banking or social networking mobile apps.

For instance, you could run a search for XYZ and find a replica of the app and go on to install. Once you launch the app in your phone, it presents you with similar login details as seen in the official app. Once you proceed to enter your login details, your details will be stolen. They are sent to the hackers over the internet and they now have access to your bank account.

What IS NEW ABOUT RED ALERT 2.0

This trojan has a few new tricks too. It is able to intercept and block incoming verification calls from banks and social networks. It can also intercept verification SMS and harvest info from those text messages for the use of the hackers.

The summary is that once Red Alert is active on your mobile phone, thieves can steal your login details and your money while keeping you unreachable by your bank if they suspect malicious activity going on. Nasty boy. This makes the trojan especially dangerous.

RED ALERT 2.0 TROJAN IS CHEAP!

Another problem that researchers point to is the fact that the trojan is being sold on hacking forums for as low as $500, meaning that it can get in the hands of a lot of bad people easily.

Is Your Smartphone Vulnerable To Red Alert 2.0?
Red Alert 2.0 is said to work on phones running Android version 6.0 (Marshmallow) and earlier.

WHAT CAN YOU DO?
Researchers RedAlert 2.0 targets over 60 Android banking and social apps. However, the number can increase quickly, considering how cheap the trojan is being sold. Here are the things you can do to keep yourself safe:

✔ Upgrade your smartphone to Android 7 Nougat, if there is an update available for it. This automatically takes you outside of the scope of Red Alert 2.0, as researchers say the trojan works only on smartphones running Android version 6.0 (Marshmallow) and earlier.

✔️ Be careful where you install your Android mobile applications from. The official app market is your best bet.

✔️ When you run a search for a banking or social networking app, always take a closer look at the details. Often there are little tell-tale signs that can give you a tip. Where in doubt, do not install.

✔️ When wanting to install banking and social apps, if possible, use a link provided on your bank’s website. via.

OTHER DANGEROUS MALWARE
Hummingbird
✔️ CopyCat
✔️ WanaCry
✔️ LeakerLocker

Be careful and stay safe.

VIRUS ALERT! Beware of ExpensiveWall Malware Now Spreading in Playstore

A new dangerous Malware called ExpensiveWall is currently affecting more than 21.1Million Android devices right now. To make things worst, this malicious malware/virus is also traced in Google Playstore according to reports. So this post is to alert you and other Android users about this Malware so that you can stay protected from being attacked.
Lovely wallpaper Malware
The ExpensiveWall Malware was revealed by researchers at Check Point and it has already affected at least 50 apps on Google Play, which were downloaded between 1 million and 4.2 million times before they were removed.

"Lovely wall paper" is one of the infected apps on Playstore. The ExpensiveWall malware was “packed” inside wallpaper apps, which allowed it to escape Google Play's built-in anti-malware protections.

HOW IT WORKS
The ExpensiveWall malware packed inside an android apps, will ask users for permissions, such as SMS and internet access. If granted, the malware will start sending premium SMS messages and register users for other paid services that don't exist without the user's knowledge.

Though granting apps permissions are normal but absolutely abnormal for a wall paper to be asking users for permission for sms or internet access.

SEE ALSO... Beware of LeakerLocker Virus

HOW TO PROTECT YOUR ANDROID FROM BEING INFECTED

It's always advisable not to install apps from unknown sources and if you want to install from playstore, ensure you install trusted apps that has been available for at least one year with good reviews and high number of downloads. Source 1 2.

Beware of Faketoken Trojan Virus That Mimics Ridesharing Apps

Another Trojan Virus is currently trending and it's called "Faketoken". It has been distributed and affected some Android devices through Ridesharing apps so you should be careful and more proactive when using such apps on your devices.

One thing is certain, Malware creators will continue creating and distributing their dangerous viruses as there is no sign of them stopping. Some of them has made so many dollars through these malicious activities and while you can't stop them completely, you can protect your devices and apply common wisdom while dealing with some sensitive online activities. Having said that, let's see how this Malware works.

HOW FAKETOKEN VIRUS WORKS

Some Ridesharing apps have been discovered to be harboring mobile Trojan horses. These malwares steal bank data by impersonating the interfaces of these ridesharing apps. According to Kaspersky Labs, if your ridesharing app asks you to re-enter your credit card information after you have already input it upon installation, you should proceed with caution. The malware responsible for this is known as the Faketoken Trojan, and apparently it has been around for a while now but more active and taking toll on many phones at the moment.

According to Kaspersky, the latest version of the Faketoken Trojan is called Faketoken.q. The company revealed that the malware infects phones through bulk SMS, where it prompts the user to download images. Once the user downloads the image, the Faketoken Trojan installs all its necessary parts, and begins to monitor everything done on the phone. Now, once the malware detects an app whose interface it can simulate, it overlays the app with its own screen. Then, instead of proceeding as usual, the app prompts you to enter your credit card information.

SEE ALSO... How LeakerLocker Virus Infects Your Phone and How To Stay Safe

Some sensitive apps like mobile banking apps, Android Pay, the Google Play Store, and of course ridesharing apps has been infected already. However, the Virus is more popular in Russia but I am spreading this information globally as it could be unleashed to other parts of the world to cause more havoc.

HOW TO STAY SAFE FROM FAKETOKEN VIRUS

Kaspersky recommends that you go to Android settings and prevent the installation of apps from unknown sources.
✔️ Simply go to Settings
✔️ Tap on Security
✔️ Then uncheck Unknown Sources.

On a more serious note, you need to be aware of the permissions an app requests before installation, even if you download the app from a presumably safe source, like Google Play Store. Also, it would be prudent to install an antivirus app on your phone.

Personally, I usually read app permission and requests to know what the app can do on my phone before installing it. Some apps that requires the permission to access my sms, call log, override other apps, galleries and some other sensitive information are carefully examined before i decide to install. I urge you to also apply that principle and you should at least minimize the chances of being attacked by this dangerous and malicious malware in circulation.

New Virus: LeakerLocker Malware Demands $50 From You

LeakerLocker is a form of Android ransomware that threatens to send all your private information, data and web history to all of your contacts and demands $50 from you if you don't want it expose you to the public.

This ransomware is called LeakerLocker, and it was found in the Google Play Store. It works in a different and weird way because unlike other ransomware, it does not encrypt its victims’ files. Rather, it makes a backup of victims’ data stored on the device. Then the developers of the malware demand $50 in exchange for not leaking your personal info to your phone and email contacts. Some of your personal info at risk includes your web history, emails, location history and more.

The LeakerLocker Malware was found in two apps in the Google Play Store. These are Wallpaper Blur HD, which has been downloaded up to 10,000 times by Android users, and Booster & Cleaner Pro, which has been downloaded up to 5,000 times as well. So this simply means that at the moment, about 15,000 people have already fallen victim to this malware, which has been in the Google Play Store since April this year. Imagine the apps even had good reviews on playsStore; developers has manipulated fake reviews of the apps to deceive people who want to download.

HOW LEAKERLOCKER WORKS

Once you download any of these vulnerable apps, LeakerLocker asks for a large number of permissions, including the ability to manage calls, read and send text messages, and access contacts. After you grant it access, the malware communicates with a receiver, thus initiating the malicious activity and locking the Home screen of the device with an extortion threat. Analysis of the malware code shows that it is capable of accessing an email address, some contact information, Chrome browser history, text messages and calls, and photos from the camera.

HOW PAYMENT IS MADE

LeakerLocker demands the ransom via credit card. Researchers have advised victims not to pay up, because there’s no guarantee that the information will be released or will not be used to get at them again.

MUST READ: Checkout All New Viruses Trending Now and How To Stay Away From Them

McAfee researchers have reported the malware to Google, and the offending apps have been removed from the Google Play Store.
via

Beware of CopyCat Malware, 14M Android Phones Infected

There is a new dangerous Android malware in circulation right now called CopyCat and it has reportedly infected over 14 million devices globally.

At the moment, 280,000 Android devices has been affected by CopyCat in the US alone. Though Google has been tracking the malware since 2015 and the company has updated PlayProtect to block CopyCat. However, millions of devices are still getting attacked via third-party app downloads and phishing attacks.

HOW COPYCAT MALWARE WORKS

The CopyCat virus pretends to be a popular app to confuse you and once it is downloaded on your phone, the app collects data about the infected device and downloads rootkits to ease root the phone, essentially eliminating the security system. Then, CopyCat downloads fake apps, as well as taking control of the device’s Zygote, (launcher for every app on your phone). Immediately the malware has control of the Zygote, your phone is olin its total control and it knows every app you download, as well as every app you open. After that, the malware can now be able to replace the Referral ID on your apps with its own, which redirects ad revenue to the hackers instead of to your app’s creators. So far, CopyCat has helped hackers make over $1.5 million.

According to researchers at Checkpoint,
the malware basically roots devices and hijacks apps to make millions in fraudulent revenue. The majority of the devices affected by the CopyCat malware are in Asia right now, but this does not mean that devices in other places are safe.


THE CREATORS OF COPYCAT MALWARE

We can't really tell exactly the creators of this dangerous malware but considering the fact that CopyCat Virus checks to see if the infected device is located in China and sparing devices from that region, it could be a signal that the perpetrators of the cyberattack are located in China and are trying to avoid police investigation. The attack hit its highest number of victims between April and May of last year, but it still affects Android users today, especially those that use Android 5.0 and earlier Android versions. Also, users who download apps from third-party sites are at risk.

SEE ALSO... Beware of JUDY Virus

HOW TO BE SAFE

✔ It's advisable to use an updated Android phone with new OS version especially if it's your main phone for carrying out sensitive transactions and works.

✔ Also, you should endeavor to always install apps from Playstore or trusted sites.

✔ Be very careful when collecting apps from your friend's phones or via laptops

✔ Ensure your memory card isn't used on another person's phone or laptop. Alternatively, make sure you format an SD card before using on your phone.

✔ Be careful when installing apps shared on social media like whatsapp and telegram.

Stay safe!!

Dvmap is The New Deadly Android Virus - See How It Works

It's unfortunate that Viruses and Malware developers will continue finding ways to bypass security on mobile devices and PC in order to harm or hold the owner at ransom. Few weeks ago, we talked about Judy which was a serious ransomware that autoclicks ads thereby generating money for the owner and Ransomware which encrypts (locks) folders on users PC and demand for some thousands of dollars as ransom in order to regain access to the files, but thanks to the developers who found a way to descript and fix it BUT now there is a new trending Virus called Dvmap that is attaching Android devices.
Android virus
Dvmap is primarily targeting mobile devices, according to Kaspersky Labs . This threat is known as Dvmap, and it is different from all the malware we know and trust Google to protect us from.

Kaspersky has been monitoring the distribution of a Trojan horse in the Play Store since April 2017. Dvmap has been able to hide from Google’s protection and verification mechanisms by regularly swapping clean code with malicious code and vice versa. Now, we know that the Bouncers, which was introduced in 2012 to keep malware from the Play Store, can be tricked easily.

How It Works


This malware, classified by Kaspersky Labs as Trojan.AndroidOS.Dvmap.a is a particularly tricky form of malware, according to experts. It tries to gain root access in four different ways, even with 64-bit compatible code. Worse, it injects malicious code into system libraries libdmv.so and libandroid_runtime.so. Subsequently, the Trojan horse triggers protection mechanisms to verify and install third-party apps. This is done by an administrator service called com.qualcmm.timeservices, which looks similar to a legitimate background service like com.qualcomm.timeservices. Note the difference between the two service names, as it is a common ruse employed by hackers and malware advertisers to trick users into trusting them.

Now, the malware could install third-party software on infected devices at a later date. The author could offer this ability to anyone interested, on the black market. Right now, a huge number of devices could be affected. But so far, only a maximum of 50,000 devices are reported to be affected.

REASON WHY IT'S TOO DANGEROUS

Theoretically, Google can delete harmful apps remotely from your device. However, since the malware manipulates system libraries, it could prevent Google from being able to do so, or report the uninstallation immediately to the malware’s author. The author could then install a different version of the malware to escape the protection mechanism again.

HOW TO FIX YOUR PHONE IF INFECTED BY DVMAP

Right now, only formatting the system partition and reinstalling the original firmware can save an affected smartphone.

HOW TO SECURE AND PREVENT YOUR PHONE FROM. BEING ATTACHED

The only way to prevent this from happening is to have the latest security patches. However, not everyone gets the updates, as manufacturers fear that if they do so they will not buy new phones. But ensure your apps are up to date. Refrain from the habit of downloading or collecting apps, music, files etc from untrusted sites, phones or PC.
via

14-Year-Old Japanese Boy Arrested for Creating Ransomware

Japanese authorities have arrested a 14-year-old boy in Osaka, a prefecture and large port city, for allegedly creating and distributing a ransomware malware.

According to a reliable security report, this is the first such arrest in Japan which involves a Ransomware-related crime.
Ransomware is a piece of malware that encrypts files on a victim's computer and makes them inaccessible until the victim pays a ransom, usually in Bitcoins, in order to get the decryption keys for the encrypted files.

Ransomware has been around for a few years, but currently, it has become a major cyber threat for businesses and users across the world.

Just last month, the WannaCry ransomware hit over 300,000 PCs within just 72 hours, wreaking havoc worldwide.
The recent arrest came after the teenager, who is a third-year junior high school student, created a ransomware virus and uploaded its source code on the Internet, according to multiple Japanese media.

The student, who admitted to the allegations, combined free encryption software to develop his own ransomware infection and then uploaded it to a foreign website and even taught people to download and use it to spread further for financial gain.

The teen also advertised the website through social media, including Twitter, telling users "I made ransomware. Please feel free to use it," the sources said.

According to Japanese police, the teen's ransomware allowed a downloader to infect victims' computers, demanding payment in digital currency. His ransomware framework has been downloaded over 100 times.

The authorities have not revealed the identity of the teenager, but have informed that the student just took about 3 days to create the ransomware program using his personal computer.

The student also told the authorities that he learned to code on his own and created the ransomware out of curiosity in order to become famous.

The Japanese police spotted the ransomware during "cyber patrolling" in January and confiscated the teen's computer after searching his house in April.
Learn How to Code — Though it is never recommended to develop a malware and spread it for fun, financial gain or other purposes, learning to code is not a crime.

If you're looking to 'learn how to code' and seeking a career as an expert-level programmer, you should know how to play with codes and make your own.

We have introduced an ultimate programming bundle that includes ten online training courses that could elevate your programming skills straight from beginner to advanced level.

The Ultimate Learn to Code 2017 Bundle, comes with lifetime access, offers you professional training courses on Python, Ruby, Java, iOS, HTML, CSS, AngularJS and other programming languages that are in high demands.

Beware of Judy Malware, Checkout Infected Apps on Playstore

Researchers at Check Point, which recently reported malicious subtitles, have now reported a new malware campaign on Google Play. Dubbed 'Judy', the auto-clicking adware was found on 41 apps developed by a Korean company, according to researchers.

The malware used infected devices to generate fraudulent clicks on advertisements for generating revenues. Researchers claim that the 'Judy' malware has affected between 8.5 million and 36.5 million Android devices as the malicious apps saw downloads between 4.5 million and 18.5 million. Notably, Google removed the malicious apps from the Google Play store after Check Point notified it about the threat.
judy malware
"Some of the apps we discovered resided on Google Play for several years, but all were recently updated. It is unclear how long the malicious code existed inside the apps, hence the actual spread of the malware remains unknown," writes Check Point team talking about the Judy malware.
Researchers also found several apps containing Judy malware developed by other developers on Google Play. Though, any connection between the two malware campaigns couldn't be established. "The connection between the two campaigns remains unclear, and it is possible that one borrowed code from the other, knowingly or unknowingly," adds the team.

Check Point reported that the oldest app in the second campaign from other developers were last updated in April 2016 which means that the "malicious code hid for a long time on the Play store undetected."

Researchers also add that similar to previously reported malicious apps like FalseGuide, Judy also relies on the communication with its Command and Control server (C&C) for its operation.
Check Point last month reported FalseGuide botnet malware which infected millions of Android devices via Google Play, and which was hidden in over 40 guide apps for games in Google Play.

According to a security source, the researchers also uncovered a few more apps, published by other developers on Play Store, inexplicably containing the same the malware in them.
The connection between the two campaigns remains unclear, though researchers believe it is possible that one developer borrowed code from the other, "knowingly or unknowingly."

"It is quite unusual to find an actual organization behind the mobile malware, as most of them are developed by purely malicious actors," CheckPoint researchers say.

Apps available on play store directly do not contain any malicious code that helped apps to bypass Google Bouncer protections.

Once downloaded, the app silently registers user device to a remote command and control server, and in reply, it receives the actual malicious payload containing a JavaScript that starts the actual malicious process.

"The malware opens the URLs using the user agent that imitates a PC browser in a hidden webpage and receives a redirection to another website," the researchers say. "Once the targeted website is launched, the malware uses the JavaScript code to locate and click on banners from the Google ads infrastructure."

The malicious apps are actual legitimate games, but in the background, they act as a bridge to connect the victim’s device to the adware server.

Once the connection is established, the malicious apps spoof user agents to imitate itself as a desktop browser to open a page and generate clicks.

Here’s a list of malicious apps developed by Kiniwini and if you have any of these installed on your device, remove it immediately:

INFECTED & MALICIOUS APPS

  1. Fashion Judy: Snow Queen style
  2. Animal Judy: Persian cat care
  3. Fashion Judy: Pretty rapper
  4. Fashion Judy: Teacher style
  5. Animal Judy: Dragon care
  6. Chef Judy: Halloween Cookies
  7. Fashion Judy: Wedding Party
  8. Animal Judy: Teddy Bear care
  9. Fashion Judy: Bunny Girl Style
  10. Fashion Judy: Frozen Princess
  11. Chef Judy: Triangular Kimbap
  12. Chef Judy: Udong Maker – Cook
  13. Fashion Judy: Uniform style
  14. Animal Judy: Rabbit care
  15. Fashion Judy: Vampire style
  16. Animal Judy: Nine-Tailed Fox
  17. Chef Judy: Jelly Maker – Cook
  18. Chef Judy: Chicken Maker
  19. Animal Judy: Sea otter care
  20. Animal Judy: Elephant care
  21. Judy’s Happy House
  22. Chef Judy: Hotdog Maker – Cook
  23. Chef Judy: Birthday Food Maker
  24. Fashion Judy: Wedding day
  25. Fashion Judy: Waitress style
  26. Chef Judy: Character Lunch
  27. Chef Judy: Picnic Lunch Maker
  28. Animal Judy: Rudolph care
  29. Judy’s Hospital: Pediatrics
  30. Fashion Judy: Country style
  31. Animal Judy: Feral Cat care
  32. Fashion Judy: Twice Style
  33. Fashion Judy: Myth Style
  34. Animal Judy: Fennec Fox care
  35. Animal Judy: Dog care
  36. Fashion Judy: Couple Style
  37. Animal Judy: Cat care
  38. Fashion Judy: Halloween style
  39. Fashion Judy: EXO Style
  40. Chef Judy: Dalgona Maker
  41. Chef Judy: ServiceStation Food
  42. Judy’s Spa Salon


At least one of these apps was last updated on Play store in April last year, means the malicious apps were propagating for more than a year.

MUST READ... 8 Ways To Keep Your Smartphone and PC Safe From Virus Attack

Google has now removed all above-mentioned malicious apps from Play Store, but since Google Bouncer is not sufficient to keep bad apps out of the official store, you have to be very careful about downloading apps.

Wanakey: Download WanaKiwi Tool For Ransomware Decryption

Is you PC affected by the latest deadly Ransomware called WanaCry? A timely solution to the attack is here. Well, in case you don't know, a malware called Ransomeware (aka WanaCry) has affected more than 300,000 computers in 150 nations since its attack on computers running the Microsoft Windows operating system last Friday.

The way it works? Very dangerous! Once your company is infected, the ransomware encrypts your data demands ransom payments from the infected computers in the Bitcoincryptocurrency. Hence the name "Ransomeware" But good news is there is a fix now so no need to pay any ransom anymore as security experts released a decryption tool called WanaKiwi. or WanaKey

WanaKiwi can be used on Windows XP, Vista, 7, Server 2003, and Server 2008, and can run using the command prompt. If your system is affected by Ransomeware, follow the below link to download the decryption tool kit.

WHERE TO GET IT

Download Wanakey. The guides on how to run it is provided there as well.

Kindly SHARE this article and help save someone out there today.

#wanacry #wanakey #wanakiwi #ransomeware #malware

Beware Of QuadRooter: The New Dangerous Security Flaw Affecting Android Phones On Qualcomm Chipsets

Another Android security flaw has been discovered by researchers at security Check Point . This new security issue affects Android devices powered by Qualcomm chipsets and it is called QuadRooter.

According to check point, the flaw is fundamentally a set of four vulnerabilities that has already affected over 900 million smartphones and tablets all over the world running Google's Android OS

Surprisingly, Samsung's latest Galaxy S7 flagships and BlackBerry DTEK50, which blackberry boasted to be "the world's most secure Android smartphone." were the most hit by QuadRooter.

How It Works
The QuadRooter security flaw gives attackers complete control of any affected phone or tablet, including access to sensitive personal and enterprise information stored on the device once exploited. This is made possible by the application of a trick to deceive android users to install a very dangerous and malicious app unknowingly to them as it would require no special permissions to suggest it's a malware. Once installed, your phone activities will then be monitored by the bad guys in the backyard.

What Is The Way Forward
At the moment, Qualcomm is now aware of this latest threat and the company is doing everything within their power to fix it as soon as possible. The company says that all the bugs were fixed at its end and patches were handed over to customers. While fix for three vulnerabilities have already made it to recent Android monthly security updates released by Google, one is still outstanding - it'll be be included in the September update.

How Do I Know If My Phone Is Infected With QuadRooter?
Fortunately, Check Point has launched a free QuadRooter Scanner app on Google Play which users of devices running on Qualcomm chipset can use to scan and analyze their phones to know if the flaw exist or not.

5 Reasons Why You Should Not Install Flash Keyboard On Your Android Phone

Android users are surrounded with several apps to download from both google playstore and other sources. There are millions of applications for almost every category of human beings. There are apps with different tasks and functions and one of the popular apps are keyboard apps as we need them for typing.

Flash Keyboard is among the most popular applications in Google playstore as it has recorded over 50 million downloads and was sometime ranked as the 11th most popular app on playstore but unknowingly to users, the app is full of malware and not safe for users. This was recently discovered by a UK-based cyber-security firm by name Pentest . They found the keyboard to be asking for “excessive permissions”, displaying infected ads, asking for admin privileges in order to make uninstall very difficult, monitoring user behavior, and then sending data to servers in China without the user’s consent.

Reasons Why Flash Keyboard App Is A Malware
According to Pentest
1. The app requires unwanted access to a phone’s Bluetooth connection, geo-location feature, or Wi-Fi status which is not ideal for a keyboard app.

2. The app always ask for access to kill background processes, read SMS messages, show system overlays, or remove download notifications. Pentest says there are no reasons for a keyboard app to require these intrusive permissions.

3. Flash Keyboard was asking for device admin permissions, and was using these powers to take over the smartphone’s lock screen and show ads even if users opted out.

4. Flash Keyboard secretly transfers data to secret servers located in China and other foreign countries. The app transmitted sensitive user data including the owner’s email address, device manufacturer, model number, IMEI and Android version to what it believes to be analytics servers in the US, Netherlands and China.

5. Flash Keyboard sends details of the currently connected Wi-Fi network and others in the proximity, the identity of the mobile network being used and GPS coordinates that are accurate to within three meters of the user.

Source: Pentest

READ ALSO 📖

Checkout How To Manually Remove Computer Virus Without And Antivirus Software

Learn How To Remove Dangerous Monkey test Virus From Your Cell Phone

Beware Of This Malware That Steals Your Bank Account Details

So you have seen it. If you noticed, the owners of the app are always running ads on Facebook and Google adword to promote it but seeing what is on ground now, i think you should think twice before downloading the app. Of course there are other nice and amazing android keyboard you should try. For instance SwiftKey, Google keyboard and Gokeyboard are all nice.

Please hit the SHARE BUTTONs to share this with your friends so that they will be aware of this malware pending the time the app developers fixes it. Thank you.