A new malware alert has been issued that has infected numerous Android devices across Asia.
(Baonghean.vn) - A new Android Trojan malware has recently been identified, infecting over 600,000 users in Southeast Asia through the Google Play app store.
Security researchers are warning that two new types of Android Trojans have been discovered targeting users in Southeast Asia and East Asia. One of them has accumulated hundreds of thousands of installations through the Google Play app store.
![]() |
Illustrative image. |
According to a report by the renowned Russian cybersecurity company Kaspersky, this Trojan, named Fleckpe, first appeared in 2022 and was distributed through malicious applications in the Google Play app store.
Kaspersky has identified a total of 11 malicious applications in the official Google Play app store, which have been installed more than 620,000 times. These malicious applications, such as photo editing utilities, smartphone wallpaper packs, and similar software, have been removed from the Google Play app store.
When running on an infected device, the Fleckpe malware downloads a library containing a virus program that aims to establish a connection with a command and control (C&C) server and send information about the infected device.
The server responds with a paid registration page that the Trojan loads in an invisible browser window. If the registration process requires a verification code, the malware leverages previously requested access to the notification area, retrieves and enters that code into the page to complete the registration process.
Most victims of the Fleckpe malware have been identified in Thailand, but the malware has also infected users' devices in Indonesia, Malaysia, Poland, and Singapore.
A second malware identified, named FluHorse, is also distributed through malicious applications. However, unlike Fleckpe, these applications infiltrate victims' devices via phishing emails, according to Israeli cybersecurity company Check Point.
The FluHorse malware mimics popular apps with over 1 million installations on the Google Play app store and is specifically designed for users in Taiwan (paid apps) and Vietnam (banking apps).
This malware is designed to collect victims' login credentials and two-factor authentication (2FA) codes transmitted via SMS and send them to the operator. Phishing emails contain bait related to toll payments and direct victims to a fake website used to distribute malicious applications.
After the victim installs the malicious app, they will be prompted to enter login information and then asked to wait 10 or 15 minutes until the information is verified.
During this time, the attackers attempt to use login credentials to carry out malicious transactions, and the malware abuses previously requested permissions to redirect any SMS confirmation codes to the attackers.
According to cybersecurity firm Check Point, the victims of the FluHorse malware are diverse and include prominent figures such as government officials.



