We know that most of our members wouldn't fall for one of these tricks, but that doesn't mean sharing the warning is a bad idea. We all have friends and family members who might fall for one of these nasty malware tricks, so we wanted to pass the latest intel along to you guys. There is a new scheme for Android which basically tries to trick users into believing they have a virus on their device. It's a trick that is pretty popular on the desktop, but is fairly unusual/new on Android.
The bad guys have figured out ways of taking over advertising space, but instead of showing ads, they bring up sneaky warnings claiming the users Android is infected. The ads claim they have an antivirus tool that you can download if you click on the ad. Of course, once you do that, you have actually put the malware on your smart-device. Here's a quote with more of the details,
What happens is that cyber crooks sign-up to run an advert campaign via one of the big ad platforms and they deliberately hack the ads to show a dialog that tries to scare the user into downloading an app because their phone has a virus. Ironically it is the fake virus warning that ultimately leads to the device being infected!
Ironically it is the fake virus warning that ultimately leads to the device being infected!
The fact that the hackers can alter the advert is a weakness in the ad platform itself and hopefully once the ad company spots these malicious ads it will close the security hole. This particular ad tries to get the user to download appmarket_2.0.2.apk which installs the Android/Hnd Adwo malware. According to AVG, reports about this particular malware have rocketed over the last week but are now in decline.
Android/Hnd Adwo displays unwanted advertisements as notifications and it requires the complete removal of the infected app to block the ads from being pushed. It is currently ranked 7 in the world for mobile, online and PC malware and has affected more than 10,000,000 users!
As always, it's a good idea never to install .apk files from sources you don't know to be legitimate, and especially not from some random ad that pops up on your phone!
Source: AndroidAuthority