Dropper apps spread malware that can steal money from Android users’ banking apps
The apps that help to get the malware past the Google Play Store protection are called dropper apps. They are aptly named because these apps have a payload consisting of malicious apps installed on an infected handset. In its report, Trend Micro writes, “Malicious actors have covertly added a growing number of banking Trojans to Google Play Store via malicious droppers this year, demonstrating that such a technique is effective at evading detection.”

Banned from the Play Store, make sure none of these apps stay on your phone
In addition, due to the high demand for new ways to distribute mobile malware, several attackers claim that their droppers could help other cybercriminals spread their malware on the Google Play Store.” Late last year, Trend Micro discovered a new variant of dropper that it called DawDropper.These apps were originally found in the Google Play Store under the titles:
- Call Recorder APK (com.caduta.aisevsk)
- Rooster VPN (com.vpntool.androidweb)
- Super Cleaner – hyper & smart (com.j2ca.callrecorder)
- Document Scanner – PDF Creator (com.codeword.docscann)
- Universal Saver Pro (com.virtualapps.universalsaver)
- Eagle photo editor (com.techmediapro.photoediting)
- Call recorder pro+ (com.chestudio.callrecorder)
- Extra Cleaner (com.casualplay.leadbro)
- Crypto utilities (com.utilsmycrypto.mainer)
- FixCleaner (com.cleaner.fixgate)
- Just In: Video Motion (com.olivia.openpuremind)
- com.myunique.sequencestore
- com.flowmysequto.yamer
- com.qaz.universalsaver
- Lucky Cleaner (com.luckyg.cleaner)
- Simpli Cleaner (com.scando.qukscanner)
- Unicc QR Scanner (com.qrdscannerratedx)
Although Google launched these apps from the Play Store, they may still be on your Android phone. If so, remove them immediately.
Trend Micro adds that “DawDropper’s malicious payload belongs to the Octo malware family, a modular and multi-stage malware capable of stealing banking information, intercepting text messages and hijacking infected devices. Octo is also known as Coper and has historically been used to target Colombian internet banking users.”
Google is also making policy changes to the Google Play Store, including banning copycat apps
Ironically, one app that can be affected is the “App Tracking Protection” app from the pro-privacy company DuckDuckGo, which creates VPNs to block trackers in other apps.