Dr.Web Antivirus

Dr.Web Antivirus Dr.Web Anti-virus—Quality always comes first!

17/07/2023

Infinite horizons: Read issues of the Anti-virus Times—you’ll be up to speed on today's Internet threats and learn how to neutralise them

Window and iOS devices support the launch of the Dr.Web FixIt!For information security incident investigations
09/07/2023

Window and iOS devices support the launch of the Dr.Web FixIt!
For information security incident investigations

Dr.Web vxCube can be interesting for banks, big corporation to check incoming files with e-mail (it has the option to be...
26/06/2023

Dr.Web vxCube can be interesting for banks, big corporation to check incoming files with e-mail (it has the option to be integrated with our Dr.Web Mail Security Suite and also has the API that can be connected to the mail servers to get attachments checked

In October 2021, one of Kazakhstan’s telecommunication companies contacted Doctor Web, with suspicion of malware in the corporate network. During the first look, we found backdoors that were previously only used in targeted attacks. During the investigation, we also found out that the company’s ...

Android apps containing SpinOk module with spyware features installed over 421,000,000 timesMay 29, 2023Doctor Web disco...
01/06/2023

Android apps containing SpinOk module with spyware features installed over 421,000,000 times

May 29, 2023

Doctor Web discovered an Android software module with spyware functionality. It collects information on files stored on devices and is capable of transferring them to malicious actors. It can also substitute and upload clipboard contents to a remote server. Dubbed Android.Spy.SpinOk in accordance with Dr.Web classification, this module is distributed as a marketing SDK. Developers can embed it into all sorts of apps and games, including those available on Google Play.

On the surface, the SpinOk module is designed to maintain users’ interest in apps with the help of mini games, a system of tasks, and alleged prizes and reward drawings. Upon initialization, this trojan SDK connects to a C&C server by sending a request containing a large amount of technical information about the infected device. Included are data from sensors, e.g., gyroscope, magnetometer, etc., that can be used to detect an emulator environment and adjust the module’s operating routine in order to avoid being detected by security researchers. For the same purpose, it ignores device proxy settings, which allows it to hide network connections during analysis. In response, the module receives a list of URLs from the server, which it then opens in WebView to display advertising banners.

Below are examples of ads Android.Spy.SpinOk displays:

At the same time, this trojan SDK expands the capabilities of JavaScript code executed on loaded webpages containing ads. It adds many features to such code, including the ability to:

obtain the list of files in specified directories,
verify the presence of a specified file or a directory on the device,
obtain a file from the device, and
copy or substitute the clipboard contents.
This allows the trojan module’s operators to obtain confidential information and files from a user’s device—for example, files that can be accessed by apps with Android.Spy.SpinOk built into them. For this, the attackers would need to add the corresponding code into the HTML page of the advertisement banner.

Doctor Web specialists found this trojan module and several modifications of it in a number of apps distributed via Google Play. Some of them contain malicious SDK to this date; others had it only in particular versions or were removed from the catalog entirely. Our malware analysts discovered it in 101 apps with at least 421,290,300 cumulative downloads. Thus, hundreds of millions of Android device owners are at risk of becoming victims of cyber espionage. Doctor Web notified Google about the uncovered threat.

Below are the names of the 10 most popular programs found to carry the Android.Spy.SpinOk trojan SDK:

Noizz: video editor with music (at least 100,000,000 installations),
Zapya - File Transfer, Share (at least 100,000,000 installations; the trojan module was present in version 6.3.3 to version 6.4 and is no longer present in current version 6.4.1),
VFly: video editor&video maker (at least 50,000,000 installations),
MVBit - MV video status maker (at least 50,000,000 installations),
Biugo - video maker&video editor (at least 50,000,000 installations),
Crazy Drop (at least 10,000,000 installations),
Cashzine - Earn money reward (at least 10,000,000 installations),
Fizzo Novel - Reading Offline (at least 10,000,000 installations),
CashEM: Get Rewards (at least 5,000,000 installations),
Tick: watch to earn (at least 5,000,000 installations).
The full list of apps is available via this link.

Dr.Web anti-virus for Android successfully detects and neutralizes all known versions of the Android.Spy.SpinOk trojan module and programs that contain it, so this malicious app poses no threat to our users.

More details on Android.Spy.SpinOk

Khalti मा आएको छ ‘The Biggest Payment Jatra’ 🤩अब Khalti बाट Dr Web को भुक्तानी गरि Pulsar N160 ( ५ जनाले ) जित्ने मौकार ...
20/05/2023

Khalti मा आएको छ ‘The Biggest Payment Jatra’ 🤩

अब Khalti बाट Dr Web को भुक्तानी गरि Pulsar N160 ( ५ जनाले ) जित्ने मौका

र हरेक दिन नयाँ उपहार जित्न:

👉रू.१०० माथि को भुक्तानीमा Scratch Card
👉 दैनिक Khutruke फुटाउने मौका (सबैलाई)

हरेक Round को अन्त्यसम्म २ भुक्तानी पुरा गरि बन्नुहोस् एउटा Pulsar N160 को भाग्यशाली बिजेता 🏍️

आजै अफरको मज्जा लिनुहोस्: http://kk5.io/KhaltiPaymentJatra

08/03/2023
Happy New Year 2023.
31/12/2022

Happy New Year 2023.

Happy Dashain
03/10/2022

Happy Dashain

Dr. Web Security Space             5PC1YEAR  MRP 3000/- Inclusive VAT
30/07/2022

Dr. Web Security Space
5PC1YEAR MRP 3000/- Inclusive VAT

Dr.Web KATANAA non-signature anti-virus offering preventive protection against the latest active threats, targeted attac...
29/07/2022

Dr.Web KATANA
A non-signature anti-virus offering preventive protection against the latest active threats, targeted attacks, and infiltration attempts that take advantage of vulnerabilities (including zero-day ones) your anti-virus can’t detect.

Dr web security space for Android Device 3Device 1Year 1200/- Inclusive vat
28/07/2022

Dr web security space for Android Device
3Device 1Year 1200/- Inclusive vat

Dr. Web Security Space            1PC1YEAR  MRP 1030/- Inclusive VAT
27/07/2022

Dr. Web Security Space
1PC1YEAR MRP 1030/- Inclusive VAT

Dr.Web Premium"The best Dr.Web subscription package for active Internet users"
26/07/2022

Dr.Web Premium

"The best Dr.Web subscription package for active Internet users"

Dr web security space for Android Device 1Device 1Year 600/- Inclusive vat
25/07/2022

Dr web security space for Android Device
1Device 1Year 600/- Inclusive vat

Happy Saune Sankranti (Luto Falne Din)(साउन संक्रान्तिको शुभकामना
17/07/2022

Happy Saune Sankranti (Luto Falne Din)(साउन संक्रान्तिको शुभकामना

गुरुर्ब्रह्मा ग्रुरुर्विष्णुः गुरुर्देवो महेश्वरःगुरुः साक्षात् परं ब्रह्म तस्मै श्री गुरवे नमःगुरुर्ब्रह्मा ग्रुरुर्विष...
13/07/2022

गुरुर्ब्रह्मा ग्रुरुर्विष्णुः गुरुर्देवो महेश्वरः
गुरुः साक्षात् परं ब्रह्म तस्मै श्री गुरवे नमः
गुरुर्ब्रह्मा ग्रुरुर्विष्णुः गुरुर्देवो महेश्वरः
गुरुः साक्षात् परं ब्रह्म तस्मै श्री गुरवे नमः

Address

Sundhara
Kathmandu
44600

Opening Hours

Monday 10:00 - 18:00
Tuesday 10:00 - 18:00
Wednesday 10:00 - 18:00
Thursday 10:00 - 18:00
Friday 10:00 - 18:00
Sunday 10:00 - 18:00

Telephone

+97714226603

Alerts

Be the first to know and let us send you an email when Dr.Web Antivirus posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Practice

Send a message to Dr.Web Antivirus:

Share