Clear, practical technology insights BSOD Code Lookup · Windows Error Code Lookup · Wi-Fi Troubleshooting · PC Troubleshooting Checklist

Necro Android Malware Reached Apps With 11 Million Downloads

Kaspersky found the Necro loader in Wuta Camera and Max Browser versions distributed through Google Play; here is what users should check and remove.

Table of Contents

In September 2024, Kaspersky reported that versions of Wuta Camera and Max Browser distributed through Google Play contained the Necro malware loader. The two app listings had a combined audience of more than 11 million downloads; that figure does not prove that 11 million devices were successfully infected.

Which Google Play apps contained Necro?

Wuta Camera: Kaspersky found the loader in versions 6.3.2.148 through 6.3.6.148. After the report, it said the malicious component was removed in version 6.3.7.138.

Max Browser: Kaspersky reported that versions beginning with 1.2.0 contained the loader. Google removed the app from the store after notification.

11 million Android devices infected with malware from Google Play Picture 1

The research also found Necro in modified apps distributed through unofficial sources. Third-party “mod” packages carry extra risk because attackers can alter a legitimate app and distribute it outside the developer's normal update channel.

See Kaspersky's Necro technical report for the affected-version evidence.

What the Necro loader could do

The loader was designed to retrieve and run additional components. Kaspersky documented capabilities associated with malicious advertising, hidden web content, downloaded code, and unwanted subscriptions. The exact impact on a device depends on which components were delivered and executed.

Other Android banking threats from the same period

NGate and NFC relay fraud

ESET reported a 2024 campaign targeting customers of three Czech banks. Attackers combined phishing, social engineering, and a malicious Android app to relay payment-card NFC data from a victim's phone to an attacker-controlled device for unauthorized ATM transactions.

11 million Android devices infected with malware from Google Play Picture 2

The app was not reported as a normal Google Play download. Victims were directed through deceptive messages and sites, then persuaded to install software and place a physical card near the phone. A 2026 NGate variant shows that the technique has continued to evolve.

Read ESET's NGate investigation.

BingoMod remote-access fraud

Cleafy described BingoMod as an Android remote-access trojan that abused Accessibility permissions, stole credentials and messages, and enabled on-device fraud through remote control. Its operators also included a device-wipe function intended to hinder investigation.

11 million Android devices infected with malware from Google Play Picture 3

Specific loss limits or guaranteed wipe behavior should not be generalized to every infection. The important warning signs are an unexpected APK, a security-themed app arriving through a message, and a request for powerful Accessibility access.

How to check an Android phone

  1. Open the Play Store, tap the profile icon, select Play Protect, and run a scan.
  2. Review Settings > Apps for Wuta Camera, Max Browser, unfamiliar “security” apps, or packages installed around the time suspicious messages arrived.
  3. Check special access for Accessibility, Device Admin, notification access, VPN, install-unknown-apps permission, and default payment apps.
  4. Install Android and Google Play system updates.

11 million Android devices infected with malware from Google Play Picture 4

Play Protect checks installed apps and can warn about known harmful software, but a clean scan is not proof that every app is safe.

What to do if you find a suspicious app

  1. Disconnect from sensitive accounts and avoid banking on the device until it is assessed.
  2. Revoke the app's Accessibility or Device Admin access, then uninstall it.
  3. If uninstall is blocked, restart in safe mode and try again, or obtain help from the device manufacturer or a trusted technician.
  4. From a different trusted device, change passwords for accounts used on the phone and review active sessions.
  5. Contact the bank immediately if credentials, card data, or transactions may be affected.
  6. Back up essential personal files and consider a factory reset for confirmed high-privilege malware.

Do not restore unknown APK files or all previous apps automatically after a reset. Reinstall software only from trusted listings and verify the developer.

Discussion

Reader Comments 0

Sign in with email or Google to join the discussion.