{"id":220921,"date":"2021-04-07T13:01:04","date_gmt":"2021-04-07T10:01:04","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/google-removes-a-fake-netflix-app-thats-been-spreading-malware-via-whatsapp\/"},"modified":"2021-04-07T13:01:04","modified_gmt":"2021-04-07T10:01:04","slug":"google-removes-a-fake-netflix-app-thats-been-spreading-malware-via-whatsapp","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/google-removes-a-fake-netflix-app-thats-been-spreading-malware-via-whatsapp\/","title":{"rendered":"#Google removes a fake \u2018Netflix\u2019 app that\u2019s been spreading malware via WhatsApp"},"content":{"rendered":"<p>&#8220;<strong>#Google removes a fake \u2018Netflix\u2019 <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">app<\/a> that\u2019s been spreading malware via <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/social-mediaa\/\" data-internallinksmanager029f6b8e52c=\"1\" title=\"Social Media\" target=\"_blank\" rel=\"noopener\">WhatsApp<\/a><\/strong>&#8221;<\/p>\n<div>\n                            Google has removed a fake Netflix app from the Play Store that aimed to spread malware by automatically responding to your WhatsApp messages.<\/p>\n<p>Earlier this year, the security firm Check Point Research, found that<span>\u00a0an app named FlixOnline was assuming the look of Netflix, and promising two months of free subscription through WhatsApp messages.<\/span><\/p>\n<p>However, a link attached to these messages would redirect you to a site to just capture your details, including your credit card.<\/p>\n<p>Here\u2019s how the malware worked. Once you installed the FlixOnline app from the Play Store, it asked for mainly three types of permissions: screen overlay, battery optimization ignore, and notification. Researchers from Check Point noted that overlay is used by malware to create fake logins and steal user credentials by creating fake windows on top of existing apps.<\/p>\n<figure class=\"post-image post-mediaBleed aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-1345764 lazy\" alt=\"\" width=\"265\" height=\"475\" sizes=\"auto, (max-width: 265px) 100vw, 265px\" src=\"https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2021\/04\/flixonline1.png\" data-lazy=\"true\" srcset=\"https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2021\/04\/flixonline1.png 265w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2021\/04\/flixonline1-117x210.png 117w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2021\/04\/flixonline1-151x270.png 151w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2021\/04\/flixonline1-75x135.png 75w\"\/><figcaption><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/thenextweb.com\/security\/2021\/04\/07\/google-fake-netflix-app-whatsapp-malware\/#\" data-url=\"https:\/\/twitter.com\/intent\/tweet?url=https%3A%2F%2Fthenextweb.com%2Fsecurity%2F2021%2F04%2F07%2Fgoogle-fake-netflix-app-whatsapp-malware%2F&amp;via=thenextweb&amp;related=thenextweb&amp;text=Check out this picture on: Flixonline app requesting for permissions on your phone.\" data-title=\"Share Flixonline app requesting for permissions on your phone. on Twitter\" data-width=\"685\" data-height=\"500\" class=\"post-image-share popitup\" title=\"Share Flixonline app requesting for permissions on your phone. on Twitter\"><i class=\"icon icon--inline icon--twitter--dark\"\/><\/a>Flixonline app requesting for permissions on your phone.<\/figcaption><\/figure>\n<p>The app \u201clistened\u201d for notifications, and automatically replied to your WhatsApp chats with a message that looked like this:<\/p>\n<p>\u201c<i>2 Months of Netflix Premium Free at no cost For REASON OF QUARANTINE (CORONA VIRUS)* Get 2 Months of Netflix Premium Free anywhere in the world for 60 days. Get it now HERE<span>\u00a0<\/span>https:\/\/bit[.]ly\/3bDmzUw\u201d.<\/i><\/p>\n<p>The link, of course, was a phishing page to collect your information.<\/p>\n<p><span>Aviran Hazum, Manager of Mobile Intelligence at Check Point Software, said that this is a novel method of spreading malware, and while this app is removed from the Play Store, it could return in another form:\u00a0<\/span><\/p>\n<blockquote><p><span>The malware\u2019s technique is new and innovative, aiming to hijack users\u2019 WhatsApp account by capturing notifications, along with the ability to take predefined actions, like \u2018dismiss\u2019 or \u2018reply\u2019 via the Notification Manager. The fact that the malware was able to be disguised so easily and ultimately bypass Play Store\u2019s protections raises some serious red flags. Although we stopped one campaign using this malware, the malware may return hidden in a different app.<\/span><\/p>\n<\/blockquote>\n<p>He added that this incident also indicates limitations of Play Store\u2019s in-built protections and Google couldn\u2019t detect malware in this app through its automated tools. Notably, WhatsApp doesn\u2019t have any vulnerability that enabled this.<\/p>\n<p>Attackers making applications and websites that masquerade Netflix is not a new trend. It was one of the most imitated brands for phishing attacks for Q1 2020.<\/p>\n<p>FlixOnline app was live for two months and had nearly 500 installs before Google removed it last month.<\/p>\n<\/p><\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong>\n<\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more like this article, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/technology\/\" target=\"_blank\" rel=\"noopener\">Technology category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/thenextweb.com\/security\/2021\/04\/07\/google-fake-netflix-app-whatsapp-malware\/\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;#Google removes a fake \u2018Netflix\u2019 app that\u2019s been spreading malware via WhatsApp&#8221; Google has removed a fake Netflix app from the Play Store that aimed to spread malware by automatically responding to your WhatsApp messages. Earlier this year, the security firm Check Point Research, found that\u00a0an app named FlixOnline was assuming the look of Netflix,&#8230;<\/p>\n","protected":false},"author":1,"featured_media":220922,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/img-cdn.tnwcdn.com\/image\/tnw?filter_last=1&fit=1280,640&url=https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/07\/google-android-malware-hed.jpg&signature=20eb89353a9495bc4f08d8de9bbc9610","fifu_image_alt":"","footnotes":""},"categories":[18],"tags":[26293,1377,72047],"class_list":["post-220921","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology","tag-google","tag-netflix","tag-whatsapp"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/220921","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=220921"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/220921\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/220922"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=220921"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=220921"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=220921"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}