In some Android applications downloaded from the Google Play Store and unofficial platforms, Kaspersky Lab has detected the malicious Trojan Necro, the company reported to RBC.

"This is a downloader for Android that downloads and runs other malicious components on the infected smartphone depending on the commands given by the creators of the Trojan. As part of this malicious campaign, Kaspersky's solutions have recorded Necro attacks on users in Russia, Brazil, Vietnam, Ecuador, and Mexico," the experts stated.

Kaspersky noted that the Trojan can download modules that secretly display ads and click on them, as well as forward internet traffic; open arbitrary links in invisible windows using WebView and execute arbitrary JavaScript code there; download executable files and third-party applications; and subscribe to paid services. The infected smartphone can also be used to access prohibited resources and as part of a proxy botnet.

The virus was found in unofficial applications such as Spotify Plus, modified versions of WhatsApp, and game modifications for Minecraft, Stumble Guys, and Car Parking Multiplayer. Among the programs available for download on Google Play, the Trojan was detected in the photo enhancement app Wuta Camera and the Max Browser. "Necro got into applications as part of an unverified ad module," the experts explained. Google removed the malicious code from Wuta Camera and Max Browser from the store. However, Necro can still be encountered in third-party applications.

Kaspersky has detected Necro before. In 2019, the company reported discovering the virus in the document recognition app CamScanner, after which Google temporarily removed it from its store, and the developers later eliminated the malicious code. Kaspersky emphasized that downloading applications from official stores does not always protect against malware infections, so it's essential to use antivirus software and periodically scan the device.