Feeds

Flappy Bird's ANIMATED CORPSE may spread malware PLAGUE

Cybercrooks latch onto app flap with trojan pestilence

Combat fraud and increase customer satisfaction

Cybercrooks have been quick to latch onto the hype about Flappy Bird's demise by laying a variety of malware-based traps.

Counterfeit Flappy Bird Android apps packing malware have been spotted all over the web, with sightings by both Trend Micro and Sophos, among others.

Trend warns that counterfeit copies of the mobile game send text messages to premium rate numbers, thereby ringing up unwanted charges to victims’ bills. Counterfeit versions of Flappy Bird are "especially rampant in app markets in Russia and Vietnam," Trend Micro warns.

More malware can be expected to follow.

And that's not the only risk of note. Supposed Flappy Bird downloads actually seek to entrap potential marks within survey scams, Malwarebytes warns.

Survey scams encourage users to disclose certain information by pretending to be consumer surveys. In reality, no matter how many questions a victim answers they never get any goodies. The end result is that scammers profit from affiliate revenues from unscrupulous marketing firms while victims are left at a higher risk of fraud.

"Poor old Flappy. Trojaned apps, survey scams.... he should have just stayed a big puddle of bird goo on the floor," joked Chris Boyd, malware intelligence analyst at Malwarebytes.

Flappy Bird was taken out of IOS and Google App Stores earlier this week.

As well as opportunists selling smartphones loaded with the app for stupid prices on tat bazaar eBay, there are also un-tampered clean .APKs available for those that know how to search for them online, as El Reg previously reported.

Vietnamese developer Dong Nguyen has been crystal clear he doesn't want the game distributed anymore so even these untampered apps are no longer kosher.

And even if that doesn't bother you there's still the malware risk. If you must (really) then at least do yourself a favour by checking that your copy of Flappy Bird for Android won't give you the pox. Check the APK SHA1 hashes for the untampered mobile game against anything you download, recommends a blog post by Finnish security software firm F-Secure here. ®

3 Big data security analytics techniques

More from The Register

next story
This time it's 'Personal': new Office 365 sub covers just two devices
Redmond also brings Office into Google's back yard
Inside the Hekaton: SQL Server 2014's database engine deconstructed
Nadella's database sqares the circle of cheap memory vs speed
Oh no, Joe: WinPhone users already griping over 8.1 mega-update
Hang on. Which bit of Developer Preview don't you understand?
Microsoft lobs pre-release Windows Phone 8.1 at devs who dare
App makers can load it before anyone else, but if they do they're stuck with it
Half of Twitter's 'active users' are SILENT STALKERS
Nearly 50% have NEVER tweeted a word
Internet-of-stuff startup dumps NoSQL for ... SQL?
NoSQL taste great at first but lacks proper nutrients, says startup cloud whiz
IRS boss on XP migration: 'Classic fix the airplane while you're flying it attempt'
Plus: Condoleezza Rice at Dropbox 'maybe she can find ... weapons of mass destruction'
OpenSSL Heartbleed: Bloody nose for open-source bleeding hearts
Bloke behind the cockup says not enough people are helping crucial crypto project
Ditch the sync, paddle in the Streem: Upstart offers syncless sharing
Upload, delete and carry on sharing afterwards?
prev story

Whitepapers

Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
SANS - Survey on application security programs
In this whitepaper learn about the state of application security programs and practices of 488 surveyed respondents, and discover how mature and effective these programs are.