This dangerous Android spyware has returned via malicious Play Store apps — delete them right now

One phone with skull and crossbones on screen among several other clean-looking phones.
(Image credit: Marcos_Silva/Shutterstock)

Cybersecurity researchers have discovered a new version of the Mandrake Android spyware hiding in apps on the Google Play Store.

As reported by BleepingComputer, Mandrake was first discovered by Bitdefender in 2020, but before then, it had been operating in the wild since at least 2016. Since then, Kaspersky has discovered a new variant of the Android spyware that’s better at remaining undetected.

In a new report, the cybersecurity firm’s researchers explain that this new version of Mandrake managed to sneak onto the Play Store in five apps submitted back in 2022. Surprisingly, most apps remained available for at least a year, while one held out for two years before it was eventually discovered.

If you own one of the best Android phones and are worried about this resurfaced threat, here’s everything you need to know about the Mandrake spyware and how to stay safe from malware.

Delete these apps right now

At the time of writing, all malicious apps found to contain this new version of the Mandrake spyware have been removed from the Google Play Store. However, if you have any of them installed on your smartphone or one of the best Android tablets, you must manually delete them. 

Here are the apps in question, along with how many times unsuspecting Android users have downloaded them:

  • AirFS - 30,305 downloads
  • Astro Explorer - 718 downloads
  • Amber - 19 downloads
  • CryptoPulsing - 790 downloads
  • Brain Matrix - 259 downloads

Of these malicious apps, AirFS is the one that managed to evade detection the longest, and it was up on the Play Store for two years before eventually being taken down back in March of this year. According to Kaspersky, Android users mainly downloaded these apps in the U.K., Canada, Germany, Italy, Mexico, Spain and Peru.

Hiding in plain sight

Android malware on phone

(Image credit: Shutterstock)

The malicious apps spreading the Mandrake spyware do things a bit differently than your typical Android malware. Instead of putting malicious logic in an app’s DEX file, Mandrake hides its first stage in a native library called “libopencv_dnn.so” which is obfuscated using OOLVM.

Once installed on a potential victim’s Android phone, this library then exports functions that are used to decrypt the second-stage loader DEx from its assets folder and load it into memory. 

This second stage also requests to draw overlays often used in overlay attacks. However, it also loads a second native library (called “libopencv_java3.so”), which decrypts a certificate that is used for secure communications with a hacker-controlled command and control (C2) server.

Once the malicious app is connected to the hacker’s C2 server, it sends a device profile and receives its third stage, which is actually the Mandrake spyware. The spyware can perform a wide range of malicious actions such as collecting data, screen recording and monitoring, command execution, simulating swipes and taps, managing files, and even installing additional malicious apps.

The hackers behind this spyware have also devised a way to display notifications that impersonate real ones from the Play Store to trick users into side-loading additional malware through APK files. 

Just like with other dangerous Android malware strains, Mandrake abuses Android permissions to run in the background and to hide app icons so that it can sneakily operate in the background unnoticed.

How to stay safe from Android malware

A hand holding a phone securely logging in

(Image credit: Google)

While all five malicious apps in question have since been removed from the Play Store, cybercriminals could use new, harder-to-detect apps to continue spreading the spyware from Google’s official app store going forward.

For this reason, you always need to be careful when downloading and installing new apps on your Android devices. You want to look at reviews and ratings carefully before downloading anything. Still, as these can be faked, you should also look for external third-party reviews and video reviews that show a particular app in action before you download it.

At the same time, you also want to ensure that Google Play Protect is enabled on your smartphone or tablet since it can scan all your existing apps and any new ones you download for malware. For additional protection, though, you should also consider using one of the best Android antivirus apps alongside it.

Malicious apps have been very successful for hackers and other cybercriminals in the past, which is why this threat likely won’t be going away anytime soon despite Google’s best efforts to prevent them from ending up on the Play Store. This is why you need to be careful and do your research first before installing any new apps on your Android smartphone or tablet.

More from Tom's Guide

TOPICS
Anthony Spadafora
Managing Editor Security and Home Office

Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches to password managers and the best way to cover your whole home or business with Wi-Fi. He also reviews standing desks, office chairs and other home office accessories with a penchant for building desk setups. Before joining the team, Anthony wrote for ITProPortal while living in Korea and later for TechRadar Pro after moving back to the US. Based in Houston, Texas, when he’s not writing Anthony can be found tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
Green skull on smartphone screen.
Hackers are using the Amazon Appstore to spread malware — delete this malicious app now
One phone with skull and crossbones on screen among several other clean-looking phones.
Malicious iPhone apps are spreading screenshot-reading malware on the Apple App Store — how to stay safe
and image of the Google Chrome logo on a laptop
Popular Chrome extensions hijacked by hackers in widespread cyberattack — 3.2 million at risk
An image of a Google Android robot
Google blocked over 2.5 million suspicious Android apps from the Play Store last year
Green skull on smartphone screen.
Only 3 of the top 150 Android apps can detect reverse engineering tool Frida — here's why that's bad
Mobile malware
New malware uses infected VPN apps to take over your device — here's how to stay safe
Latest in Malware & Adware
Green skull on smartphone screen.
Over 1 million Android devices infected with password-stealing, pre-installed botnet malware — how to stay safe
Green skull on smartphone screen.
This Android banking trojan steals passwords to take over your accounts — and all it takes is a single text message
PayPal logo on iPhone
Watch out! Scammers are using this PayPal setting to take over your PC
A laptop displaying the Chrome logo
Don't click this — malicious ads impersonating Google Chrome spreading dangerous malware
and image of the Google Chrome logo on a laptop
Google Docs under attack from info-stealing malware — how to keep your data and your emails safe
MacBook Pro 2021 (16-inch) on a patio table
Millions of Mac owners urged to be on alert for info-stealing malware
Latest in News
macbook air m4
We just saw the sky blue MacBook Air M4, and I’m in love
Ben Kingsley as Adolf Eichmann in "Operation Finale"
Netflix just got a gripping spy thriller you (probably) haven’t seen — and it’s based on a true story
Samsung's Project Moohan with Android XR at Galaxy Unpacked 2025
Samsung’s Project Moohan could have better displays than Apple Vision Pro — here’s how
Rotel DX-3
This headphone amplifier might cost a lot, but it'll make your headphones sound epic
Close-up photo of the black version of Samsung's Galaxy Ring held between thumb and index finger in front of a garden.
Samsung patent suggests a future Galaxy Ring will include a temperature sensor — here's how it could work
Simone Ashley and Hero Fiennes Tiffin in "Picture This" now streaming on Prime Video
Prime Video’s new romantic comedy is now streaming — and it’s the ultimate mood-booster