{"id":86509,"date":"2018-07-13T15:44:16","date_gmt":"2018-07-13T10:14:16","guid":{"rendered":"https:\/\/blogs_admin.quickheal.com\/?p=86509"},"modified":"2018-07-13T16:18:44","modified_gmt":"2018-07-13T10:48:44","slug":"quick-heal-detects-malware-misusing-fame-patanjalis-kimbho-app","status":"publish","type":"post","link":"https:\/\/www.quickheal.com\/blogs\/quick-heal-detects-malware-misusing-fame-patanjalis-kimbho-app\/","title":{"rendered":"Quick Heal detects malware misusing the fame of Patanjali&#8217;s Kimbho app"},"content":{"rendered":"<p>When Patanjali&#8217;s Kimbho app came to Google Play Store, it made some headlines on the Internet, newspapers, TVs, etc. It had 1.5 lakh downloads in just 3 hours. Kimbho app was designed for socializing, messaging and sharing videos, images, etc., same as what the WhatsApp and Facebook app do. However, due to some security issues, they removed the app from the Play Store.<\/p>\n<p>Although the original Kimbho app was removed, it left a scope for cyber criminals to publish a fake and malicious version of the app on Google Play Store. Quick Heal Security Labs has spotted a malware that exactly looks like the Kimbho app. It attacks users by hiding and showing ads after certain intervals of time. This malware was downloaded from Google Play Store for more than 1000 times before it was removed.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-86524 aligncenter\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2018\/07\/Play-1-219x390.png\" alt=\"\" width=\"236\" height=\"420\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/07\/Play-1-219x390.png 219w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/07\/Play-1-169x300.png 169w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/07\/Play-1-768x1365.png 768w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/07\/Play-1-789x1403.png 789w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/07\/Play-1.png 1080w\" sizes=\"(max-width: 236px) 100vw, 236px\" \/><\/p>\n<p style=\"text-align: center\">Fig 1. A fake version of the Kimbho app on Google Play<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Is it fake or genuine?<\/strong><\/p>\n<p>The developer\u2018s name and website mentioned in the additional information part on Google Play makes the app look like it is the genuine app from Patanjali.<\/p>\n<p>We analyzed the digital certificates of the genuine and the fake apps and found that they are not the same.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-large wp-image-86511 aligncenter\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2018\/07\/addinfo-545x390.png\" alt=\"\" width=\"545\" height=\"390\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/07\/addinfo-545x390.png 545w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/07\/addinfo-300x215.png 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/07\/addinfo.png 720w\" sizes=\"(max-width: 545px) 100vw, 545px\" \/><\/p>\n<p style=\"text-align: center\">Fig 2. Fake developer name<\/p>\n<p>In the original Kimbho app, there was a verification error while opening a user account because the server was down. Here, it has been updated as that Verification Error Fix. After analysis, we got to know that whatever updated on Google Play is contradicting with our analysis.<\/p>\n<p>Here are some user reviews which are also contradicting with the information given on Google Play.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-large wp-image-86512 aligncenter\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2018\/07\/Reviewplay-524x390.png\" alt=\"\" width=\"524\" height=\"390\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/07\/Reviewplay-524x390.png 524w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/07\/Reviewplay-300x223.png 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/07\/Reviewplay.png 718w\" sizes=\"(max-width: 524px) 100vw, 524px\" \/><\/p>\n<p style=\"text-align: center\">Fig 3. Review of users<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Analysis of fake and malicious version of Kimbho app<\/strong><\/p>\n<p><strong>App Name:<\/strong> Kimbho \u2013 Secure Chat, Free Voip Video Calls<\/p>\n<p><strong>Package Name:<\/strong> com.bolo.chating<\/p>\n<p><strong>MD5:<\/strong> f6682f8d3a5de26266146f0830776286<\/p>\n<p><strong>Size:<\/strong> 4.11MB<\/p>\n<p>On installation, it displays the icon of Kimbho app. When a user clicks on it, it hides and runs ad services in the background. This makes it difficult for the user to know if or not the app has been installed.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-86514 aligncenter\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2018\/07\/kimbhoinstall-1-219x390.png\" alt=\"\" width=\"236\" height=\"420\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/07\/kimbhoinstall-1-219x390.png 219w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/07\/kimbhoinstall-1-169x300.png 169w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/07\/kimbhoinstall-1-768x1365.png 768w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/07\/kimbhoinstall-1-789x1403.png 789w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/07\/kimbhoinstall-1.png 1080w\" sizes=\"(max-width: 236px) 100vw, 236px\" \/> <img loading=\"lazy\" decoding=\"async\" class=\"wp-image-86515 aligncenter\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2018\/07\/fakegoolge-219x390.png\" alt=\"\" width=\"236\" height=\"420\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/07\/fakegoolge-219x390.png 219w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/07\/fakegoolge-169x300.png 169w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/07\/fakegoolge-768x1365.png 768w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/07\/fakegoolge-789x1403.png 789w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/07\/fakegoolge.png 1080w\" sizes=\"(max-width: 236px) 100vw, 236px\" \/><\/p>\n<p style=\"text-align: center\">Fig 4. After it hides, it uses the icon of Google Play Store.<\/p>\n<p>After hiding the malware uses the logo and name of Google Play Store to confuse the user. The fake Play Store can be uninstalled as it is not an inbuilt app. Thereafter, it starts showing ads after a timespan of 10-15 minutes. These are unwanted ads, shown in between other applications interfering with the user\u2018s activity.<\/p>\n<p>This malicious app only takes advantage of the popularity of Kimbho app to earn money by displaying ads.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-86516 aligncenter\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2018\/07\/Screenshot_20180709-211709-219x390.png\" alt=\"\" width=\"236\" height=\"420\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/07\/Screenshot_20180709-211709-219x390.png 219w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/07\/Screenshot_20180709-211709-169x300.png 169w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/07\/Screenshot_20180709-211709.png 720w\" sizes=\"(max-width: 236px) 100vw, 236px\" \/> <img loading=\"lazy\" decoding=\"async\" class=\"wp-image-86517 aligncenter\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2018\/07\/Screenshot_20180709-230123-219x390.png\" alt=\"\" width=\"236\" height=\"420\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/07\/Screenshot_20180709-230123-219x390.png 219w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/07\/Screenshot_20180709-230123-169x300.png 169w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/07\/Screenshot_20180709-230123.png 720w\" sizes=\"(max-width: 236px) 100vw, 236px\" \/><\/p>\n<p style=\"text-align: center\">Fig 6. Ads shown by the malware<\/p>\n<p>&nbsp;<\/p>\n<p><strong>How to stay safe from fake mobile apps<\/strong><\/p>\n<p>1. Check an app\u2019s description before you download it.<\/p>\n<p>2. Check the app developer\u2019s name and their website. If the name sounds strange or odd, you have reasons to suspect it.<\/p>\n<p>3. Go through the reviews and ratings of the app. But, note that these can be faked too.<\/p>\n<p>4. Avoid downloading apps from third-party app stores.<\/p>\n<p>5. Use a reliable mobile antivirus that can prevent fake and malicious apps from getting installed on your phone.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>When Patanjali&#8217;s Kimbho app came to Google Play Store, it made some headlines on the Internet, newspapers, TVs, etc. It had 1.5 lakh downloads in just 3 hours. Kimbho app was designed for socializing, messaging and sharing videos, images, etc., same as what the WhatsApp and Facebook app do. However, due to some security issues, [&hellip;]<\/p>\n","protected":false},"author":48,"featured_media":86528,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[965,55],"tags":[431,1524,49],"class_list":["post-86509","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-adware","category-android","tag-android","tag-fake-app","tag-malware"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/86509"}],"collection":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/users\/48"}],"replies":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/comments?post=86509"}],"version-history":[{"count":3,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/86509\/revisions"}],"predecessor-version":[{"id":86525,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/86509\/revisions\/86525"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/media\/86528"}],"wp:attachment":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/media?parent=86509"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/categories?post=86509"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/tags?post=86509"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}