Joker is spyware that collects SMS messages, contact lists, and information about infected devices. Additionally, Joker has the ability to monetize the malware infection by registering the device for premium services without the owner’s approval. In October 2022, Joker was the third most common mobile malware behind Anubis and Hydra.
Delivered via malicious apps available from the Google Play Store, this mobile malware has been detected in a variety of different applications, including messaging, health, and translation apps. Malicious apps are removed from the Play Store after detection, but they commonly rack up thousands of downloads, and the malware authors continue to distribute new apps laced with the malware.
Once the Joker malware has been installed on a device, it commonly requests a number of different permissions. This allows the versatile malware to take various malicious actions on the device, including:
Joker is a trojan that sneaks onto mobile devices by pretending to be a legitimate and desirable app on the Google Play Store. Some means of protecting against Joker malware infections include the following:
Joker poses a serious risk to user privacy and security on infected Android devices. However, it is only one among several types of malware used actively in attack campaigns. Learn more about the current mobile and malware threat landscape in Check Point’s 2023 Cyber Security Report.
Check Point Harmony Mobile provides comprehensive protection for corporate mobile devices. With access to threat intelligence from Check Point ThreatCloud AI, Harmony Mobile has visibility into the latest cyberattack campaigns targeting mobile devices. Learn more about how Harmony Mobile can secure your organization against mobile malware like Joker by signing up for a free demo today.