• Skip to primary navigation
  • Skip to main content
  • Skip to footer
Logo of Agilient Security Consultants, Australia

Agilient Security Consultants Australia

Cybersecurity & Risk Management Specialists

Menu
  • Home
  • Industries
      • Aviation
      • Defence & Defence Industry
      • Government
      • Health & Hospitals
      • Corrections and Detention
      • Maritime
      • Aged Care Facilities
      • Mining, Oil & Gas
      • Public Venues & Events
      • Rail
      • Research and Education Industry
      • Telecommunications
      • Utilities
    • advice-colleagues-communication-newIndustries
  • Services
      • Cybersecurity
      • Protective Security
      • Business Resilience
      • Building Security Consultants
      • Security Audits
      • Pandemic Planning
      • Electronic Security
      • IT Disaster Recovery Plan
      • Security Consultants
      • CCTV and Security Cameras
      • Duress Alarms
      • Security Risk Assessment Consultants
      • Managed Security Service Provider
      • Protection against Vehicles as a Weapon
    • training-1Services
  • Solutions
    • banner-menuUnisys Solutions
    • CTO-Blog-110619-Header-GraphicLookingGlass Solutions
    • menu-bg-2Dell Technologies (RSA) Solutions
    • Sightline-Visualization-menuSightline Solutions
  • Resources
    • menumanagers-dealing-customer-agreTraining
    • working-together-newJoin The Tribe
    • Webinars_3-1.jpgUpcoming and Past Events
    • hacking-detected-shutterstock_newResources
  • Articles
  • About
    • About Us
      We are an Australian owned and operated security company specialising in risk, cybersecurity, protective security, crisis and business continuity management services.
    • frequently-asked-questions-smallFAQ’s
    • bg-menu-government-institutionsConsultant Registration
  • Contact Us
Contact Us

Android Users Attacked By Malware App

You are here: Home / Security News / Android Users Attacked By Malware App

Over 500,000 Android phone and tablet users have fallen for a malicious attack, using an app found on the Google Play app store. The app was found exfiltrating users’ contact lists, and then signing up the users to unwanted paid premium subscriptions without their knowledge and consent.

The latest malware was found in a messaging application called Color Message, which has since been removed from the app marketplace.

How Color Message Works

From the moment it is downloaded, Color Message can access user contact lists, which then allows the hacker to automatically exfiltrate the network and subscribe to unwanted paid services. It has been noted that Colour Message is difficult to identify and remove, with the app hiding it’s icon once it has been installed. Therefore, to uninstall the app, you must dig through the settings on your phone or tablet.

Colour Message Terms and Conditions

“We are committed to ensuring that the app is as useful and efficient as possible”, documented the hackers in the app terms and conditions. “And for that reason, we reserve the rights to change the app or charge for its services, at any time and for any reason. We will never charge you for the app or its services without making it very clear to you exactly what you’re paying for”.

Hackers have continued to skirt Google Play protections, using a barrage of evasion tactics since 2017.

Contact Agilient to find out how you can ensure the apps you download are not malware, and how to keep your Android devices secure.

Author: Mahdi Kobeissi, Cyber Security Consultant

Tweet
Share

Security News Android devices,  Color Message,  cybersecurity,  Google Play,  joker app,  malware,  malware app

Looking for a security partner? Get in touch with Agilient.

Looking for practical and cost-effective security and risk solutions for your government department, agency or company? Speak with Australia’s leading senior security, risk and resilience experts.


Looking for a pandemic planning partner? Get in touch with Agilient.

Looking for practical and cost-effective risk management solutions for your government department, agency or company? Speak with Australia’s leading senior risk and emergency management experts.



Footer

Agilient is a proud member of

Ai Group Defence Council
Australian Industry & Defence Network
Australian Security Industry Association
Sydney Aerospace & Defence Interest Group

Company and Licensing Details:

ABN: 37 157 911 441
NSW Security Master Licence # 410783087
ACT Security Master Licence # 17502184
Vic Security Registration # 878-460-40S
Qld Security Firm Licence # 3834422

Join The Tribe

Sign up to receive our regular Agilient newsletter including the latest security, risk and resilience updates

Sign up now

Copyright © 2022 Agilient – Level 14, 275 Alfred St, North Sydney NSW 2060 Australia – 1300 341 692