Avoid This Fake, Data-Stealing Chrome Update

Chrome for Android receives updates through the Google Play Store, but users unaware of that may be more likely to fall prey to newly discovered malware that steals calling, texting and banking information. Making matters worse, the thieving Update_chrome.apk file evades antivirus software and cannot be removed without wiping your device.

Image: Shutterstock / Izf

Image: Shutterstock / Izf

The malware was discovered in the wild yesterday (April 28) by California-based security firm Zscaler. The firm has not reported a point of origin for the attacks, but it observed that the files are being downloaded from web pages whose addresses look like they could host Google or Android updates, such as “http[:]//android-update15[.]pw/”.

MORE: Mobile Security Guide: Everything You Need to Know

After downloading the APK file, users would need to disable one of Android’s default security settings which prevents the installation of programs from unknown sources. Once that’s done and the target gives Update_chrome.apk administrative access, the malware registers the phone with its remote server, and monitors all SMS messages and calls, which it sends to remote servers.

Source: Zscaler

Source: Zscaler

If users open the Play Store on an infected device, the malware presents a phony payment information page for entering credit card numbers. After that data is entered, a screenshot is then sent to a phone number in Russia, which doesn't sound like a safe way to store your banking data.

Android anti-virus software often detects malicious files, but Update_chrome.apkincludes “hard coded checks for antivirus applications like Kaspersky, ESET, Avast and Dr. Web.” After the antivirus suites are found, the malware wipes them from the device, so it can operate without restriction.

The addresses that host the file only exist for short amounts of time, which makes it more difficult for anti-virus filters that use URL-based filtering to detect websites that should not be opened.

Image: Zscaler

Image: Zscaler

According to Zscaler’s Director of Security Research Deepen Desai, Update_chrome.apk is spreading via “compromised or malicious websites using scareware tactics or social engineering.” Desai told ZDNet that the firm has seen Android malware use “scareware tactics where the user will see a popup indicating that their device is infected with a virus and asks them to update to clean up infection."

Unfortunately, once this software is installed onto a device, it can only be removed by doing a complete factory reset. As always, we suggest that you don't change the setting that allows for installation of apps from unknown sources, and to only download and install software from approved first-party stores like Google Play.

TOPICS
Henry T. Casey
Managing Editor (Entertainment, Streaming)

Henry is a managing editor at Tom’s Guide covering streaming media, laptops and all things Apple, reviewing devices and services for the past seven years. Prior to joining Tom's Guide, he reviewed software and hardware for TechRadar Pro, and interviewed artists for Patek Philippe International Magazine. He's also covered the wild world of professional wrestling for Cageside Seats, interviewing athletes and other industry veterans.

Latest in Browsers
iPhone 16 Pro Max shown in hand
Your iPhone has a custom voice command feature — here's how to use it
iPhone 16 Pro Max shown in hand
You can change your iPhone's default browser — here's how
Google Chrome on Android
How to stop your personal data from appearing in Google searches
Opera Air
I just tested the world’s first mindful browser — it’s calmly convinced me to ditch Google Chrome
A photo of the Google Chrome logo on a white background, displayed on the screen of a large MacBook Pro which is situated on a table with green foliage behind.
Google Chrome just got three new modes — and it's a game changer for performance
Google Calendar app on iPhone
Google Calendar just got the dark mode we’ve been waiting for — here’s how to activate it
Latest in News
ChatGPT on iPhone
ChatGPT is down — updates on major outage affecting users worldwide
Emma D'Arcy in House of the Dragon season 2
‘House of the Dragon’ season 3 has officially begun filming — what it could mean for the potential release window
AirPods Max in various colors
AirPods Max is getting a big update with lossless audio and ultra-low latency — here's how it works
A mosquito resting on a plant
Experts predict a spring surge in these 9 pest populations — here's what's forecast for your area
Apple Watch SE (2022) shown on wrist
Apple Watch SE 3 reportedly in ’serious jeopardy’ — here’s why
Galaxy S25 Plus held in the hand.
Samsung could delay One UI 7’s release in the US — here’s what we know
  • Shakiermite83
    wow had one of these exact popups thismorning glad i always just exit out of those popups!
    Reply
  • henrytcasey
    17893910 said:
    wow had one of these exact popups thismorning glad i always just exit out of those popups!

    Well done!
    Reply