JAKARTA - Kaspersky discovered a new Trojan called Fleckpe'. This Trojan spreads through Google Play under the guise of editor photos, wallpaper packages, and other applications. In fact, users without realizing it subscribe to paid services.

Kaspersky data shows that this type of Trojan has been active since 2022. Company researchers found there were at least eleven applications infected with Fleckpe, which have been installed on more than 620,000 devices.

Although the app has been removed from the official platform by the time the Kaspersky report is published, it is possible the perpetrators of the crime will continue to spread this malware in other apps. This means the number of installations actually tends to be higher.

This infected Fleckpe app looks original but in fact contains a malicious dropper that works to decrypt and execute payloads from application assets. This payload makes connections with the attacker's command and control servers and sends information about infected devices, including state details and operators. After that, paid subscription pages are also available.

Trojans then secretly launch web browsers and try to subscribe to paid services on behalf of users. If the subscription process requires confirmation code, malware will access device notifications to get them.

"Thus, Trojans will set up paid service on users' devices without their consent, resulting in the victim losing money," Kaspersky said in a written statement received on Monday, May 8.

Interestingly, the functionality of the application remains unaffected, and users can continue to edit photos or tune wallpapers without realizing that they have been charged for a service.

Kaspersky Telemetry shows that malware is targeting users, especially in Thailand, although there are also victims found in Poland, Malaysia, Indonesia, and Singapore.


The English, Chinese, Japanese, Arabic, and French versions are automatically generated by the AI. So there may still be inaccuracies in translating, please always see Indonesian as our main language. (system supported by DigitalSiber.id)