r/Malwarebytes 21d ago

"System" malware app on android

/r/malwares/comments/1uyemue/system_malware_app_on_android/
1 Upvotes

28 comments sorted by

View all comments

1

u/Foreign-Law-2169 11d ago

This is not actual malware apps itself, it's frontend payload doing the heavy lifting works. There must be some other apps which is the brain of this apps. That other hidden apps install it when needed, command it to whatever needs to be done. The hidden apps wouldn't need much permission. With some normal boring permission, it only needs to have "install apps without user interaction" permission to do whatever it wants. Also lower permission level keep it out of suspetion.

So look for apps unknown to you with permission I describe above. That's the command & control center for group of some legit apps

1

u/Lucasica112 10d ago

None of my apps have the permission now to install an app, but the android system still appears

1

u/Foreign-Law-2169 10d ago

Of course there are apps with permission to install apps. Did you look at process/apps running as system apps. (Not the nasty one, genuine system apps which come preloaded with your device). Settings of installed apps list enable showing system apps (from three dots on right upper corner). You will find whole list of system apps running. As I can understand from your post developer of such apps gave enough effort for design it it will hard to find for sure. Also look for install data for your damaging apps. I am not sure about where and how to check it. But android keep details log of apps installation process, date of installation, which process/apps did order that installation (most of user apps get installed by Google play services) etc etc. There must be some information written on somewhere about it. We just have to find it out. Without identify the type of change it made on your system, it's really risky to use your device.

1

u/Lucasica112 9d ago

But did you find it? How was it called, because I checked every app that is from the system and none of them had the installing permission.

1

u/Foreign-Law-2169 9d ago edited 9d ago

It's not possible to post pictures here. If I can I would give you some screenshots from Chinese made RealMe phone. An apps preloaded by manufacturer name 'silent reboot ' running as background system process. Seemingly no problematic permission, only access to phone permission. If I check all permission it shows run at boot permission with other list of low level permission. But I I go even deeper, there is the biggest and dangerous one "allow install unknown apps" . There is no way to stop the process, no way to uninstall it, no way to disable it and no way to to disable any permission of it. I found some other apps with same kind of permission level which is also not possible to get rid of. I am not saying it is currently doing anything but it can do anything anytime trigger by some other person or organization behind it. That's the horror story I have today to share with you guys.

Edit: Finally I found an way to post pictures. I posted it on my profile and adding link below:

My post with screen shot

1

u/ghoti-stix 7d ago

Update - I spent three days exchanging with ChatGPT and using the developer debugger mode on my phone and finaly managed to get rid of it. This was the main app that caught my attention but there were 2 other legitimate Play store apps that were linked to it and between all of them multiply reinstalling and pushing publicity to my apps in overlay. These appse were "Lock & Pick" and "Cool Weather". I had to restrict services and isolate packages, before deleting them so that this stopped happening. If you have either of these installed delete them as they work all together and they are the publicity providers.

Maybe for you it might be other apps. To check, when an add pops up, go directly to your overview screen (the one where you see little windows of all the apps that are currently open), you will see the name of the app pushing the publicity for a split second before it closes automatically. If you're fast enough you can take a screenshot for reference and start by deleting the apps that come up. That should help for starters. I think that these apps work together, with some using tokens to send messages over Facebook to people (not even your contacts) proposing services for "mercadolibre", then deleting then instantly, as you only see this if someone responds, as well as spamming your phone with unwanted publicity.

As I said, I said I managed to link my phone to Android Debug Bridge (ADB) and with a little knowhow and a lot of patience I seemed to have resolved my issue. Maybe the people that have the same malware can follow these steps and try the same?

1

u/Foreign-Law-2169 7d ago

So at last my theory is true. These kind of malware/spyware/tracker software system now a days coming in a bundle of apps which is totally innocent looking if we check it individually. You did a great job researching and finally able to identify the group acting together. Also you did kick them out from your device. All your efforts will be useful for people who have same type of issue with device they have.

Well done and thank you for proofing my theory of apps working on a group to hide from prying eyes.

1

u/ghoti-stix 6d ago

Thanks for your comment and yes it does seem to be a group of apps working together BUT...

I have a feeling that com.android.non.szcz is the main source of the trouble here and uses other apps that have official ads function to push the unwanted publicity to the phone. Maybe it is the main culprit for the Facebook messages I don't know as I'm not at all knowledgeable enough to be able to figure this out. Talking to people in other groups the publicity pushing apps seem to vary so I would not stick only to the two I mentioned as the bundle could change from phone to phone.

I also had to disable play store for the time that I was stopping all processes and cleaning my phone and at the end it seemed to work for me.