Report: Fake Minecraft - Pocket Edition Scams Android Users

roseofbattle

News Room Contributor
Apr 18, 2011
2,306
0
0
Report: Fake Minecraft - Pocket Edition Scams Android Users

A modified version of Mojang's Minecraft - Pocket Edition contained a Trojan to forcibly send text messages to premium-rate numbers.

Several Russian third-party app stores have made a version of Minecraft - Pocket Edition available to download for a cheaper price than the legitimate game by Mojang, web security firm F-Secure reports. Not only do the scammers receive money for the fake app, but they also use the app to generate SMS messages to premium-rate numbers in Russia, racking up victims' phone bills.

The Trojanized Minecraft costs €2.50 compared to the actual game's price of €5.49. Similar malicious applications are usually free. The fake app earns the group/person responsible some cash for each download, but the Trojan generates more money.

"The real game is included, but it has one added permission: android.permission.SEND_SMS and the payment system has been enhanced," F-Secure told PC Mag. The app uses this permission to send text messages from the phones with the Trojan to "premium-rate numbers" in Russia and signing them up for expensive subscriptions, adding money to victims' phone bills. Even if the makers of the fake app don't own the premium-rate numbers, it wouldn't be unheard of them to make a cut of the money.

Mojang did its homework and coded security measures to prevent Trojans like this one from occurring, but the developers behind the Trojanized app used a tool to successfully hack it. "The original Minecraft includes a check inside the dex code that verifies the signature that has been used to sign the APK [Android application package file]," F-Secure stated. "If it's not [Mojang's], the code refuses to run." Except in this case.

As always pay attention to what you download to ensure you're getting legitimate software. Some application stores do not vet apps thoroughly.

Source: PC Mag [http://securitywatch.pcmag.com/mobile-security/319722-mobile-threat-monday-fake-minecraft-scams-android-gamers]


Permalink
 
Mar 30, 2010
3,785
0
0
I'm aghast...

[sub][sub]Sorry.[/sub][/sub]

Ok, seriously - If the makers of this app only receive a fraction of the costs incurred from these texts, is this app just the product of a troll taking aim at gullible app users to rob them of cash, or are the premium rate line owners in question involved as well?
 

Donzacuceron

New member
Sep 22, 2012
39
0
0
nathan-dts said:
Phone applications shouldn't have texting permissions. There's no reason for it.
What about all those don't bother me while _______ applications that send a text to whoever is calling you, that you're sleeping or in the movies etc..