BatSaver Android Malvertising Spyware
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
It is delivered disguised as a battery saving application users download from the Google Play Store or from third-party sites. Once installed it requests full permissions from the user before ostensibly acting as intended. However, it will also attempt to collect log and user data, receive SMS messages and modify system settings.
The malware also includes an ad-clicking backdoor that connects to a separate command and control server to receive new domains. Malicious adverts are displayed to the user when the use the device's default browser.
Remediation advice
Additionally, to prevent and detect an infection ensure that:Remediation steps
| Type | Step |
|---|---|
|
Last edited: 17 February 2020 12:38 pm