Tech

Stealthy malware named after The Matrix villain 'Agent Smith' hit over 25 million Android devices worldwide

hugo weaving as agent smith in the matrix
The malware automatically replaces installed apps with "malicious" versions without the user's knowledge. "The Matrix"
Read in app

A dangerous new mobile malware named after The Matrix's main villain has infiltrated more than 25 million Android devices around the world.

On Thursday, July 11, cybersecurity software company Check Point Software Technologies' research arm (Check Point Research) said in a news release that the malware dubbed "Agent Smith" automatically replaces installed apps with "malicious" versions without the user's knowledge.

The dubious software stealthily does this by disguising itself as a Google-related app and exploiting known Android operating system vulnerabilities.

Agent Smith Affected Apps
The top 10 countries with the most number of Agent Smith infections.  Check Point Research

Other Southeast Asian countries that were affected include The Philippines (226,701), Malaysia (55,647), Thailand (52,848) and Vietnam (32,916). Singapore was observed to have the least number of attacks in the region.

What does Agent Smith do?

Check Point Research noted that Agent Smith currently uses "broad access" to the devices' resources to display fraudulent advertisements for financial gain. However, the team said the software "could easily be used for far more intrusive and harmful purposes", such as stealing banking credentials and eavesdropping.

Agent Smith’s flow of attack as portrayed by Check Point Research. Check Point Research
Agent Smith’s flow of attack as portrayed by Check Point Research.  Check Point Research

It added that the activity resembles previous malware campaigns like Gooligan, Hummingbad, and CopyCat.

Check Point Software Technologies' head of mobile threat detection research, Jonathan Shimonovich, said: "The malware attacks user-installed applications silently, making it challenging for common Android users to combat such threats on their own.

He added that the best protection against invasive mobile malware attacks from the likes of Agent Smith would be to combine advanced threat prevention and threat intelligence while adopting a "hygiene first" approach to safeguard digital assets.

Users are also advised to only perform downloads on trusted app stores to lower their exposure to infection as third party stores would typically lack the necessary security measures to block adware-loaded apps, Shimonovich said.

Indiscriminate infections

According to Check Point Research's online blog,Agent Smith started proliferating through widely-used third party app store "9Apps", and targeted mainly Hindi, Arabic, Russian and Indonesian speaking users.

Read more: A laptop infected with 6 of the most dangerous computer viruses in history was sold at auction to an anonymous buyer for $1.345 million — here's what each virus can do

Although primary victims were observed to be mostly based in India (59%), the research team said that unlike previously seen malware campaigns that did not involve Google Play and affected mostly developing countries, Agent Smith had a "significant impact" on developed nations — where Google Play is "readily available" — as well.

These include the US which saw approximately 303,000 infections, Saudi Arabia (245,000), Australia (141,000) and the UK (137,000).

A world infection heat map showing the hotspots of Agent Smith attacks. The most number of infections were observed in India. Check Point Research
A world infection heat map showing the hotspots of Agent Smith attacks. The most number of infections were observed in India.  Check Point Research

Check Point added that it has submitted data to Google and law enforcement units to facilitate further investigation.

At the time of publishing the report, no malicious apps were found to remain on the Google Play Store, it said.

Read the original article on Business Insider Singapore. Follow Business Insider Singapore on Twitter.

Read next

Qayyah Moynihan was a Translation Editor for Insider, based in London.She joined Insider Inc. as a multimedia journalist in April 2018, launching the publication's translation desk.As well as translating stories from Insider's foreign language editions, she reported on breaking news and exclusive features in French, Spanish, Italian, and Portuguese. She also transcribed and produced subtitles for Insider videos.She covered everything from space exploration and relationships to politics and tech. Her translations were cited by the BBC, the Washington Post, Sky News, the Guardian, the New York Times, CNN, the Independent, and more.Previously, she reported for the Liverpool Echo, was a news presenter at Pure FM and Wirral Radio, and worked as a multimedia journalist and translator for SUR in Spain.Here's some of her work:— How Bolivia embraced toxic bleach as a COVID-19 miracle cure after a tide of misinformation— Schlumberger is slashing its global workforce but workers in the Ivory Coast say they weren't paid fair severance — Ubisoft faces new allegations of sexual harassment and 'deep-rooted, toxic' culture — COVID-19 up to 3.5 times likelier to kill people of ethnic minorities in UK— Coronavirus crisis will cause 7 million unplanned pregnancies and 31 million gender-based violence cases, UN says— How Venezuela opposition leader easily 'duped' Maduro's security teams— 'I'd wiped out half a family': F-16 pilot grapples with guilt after a bungled bombing mission in Iraq killed at least 4 civilians