Zscaler experts have found in the wild a fake version of the Super Mario Run Android App that could install the Android Marcher banking trojan.
Bad news for mobile gamers, security experts at Zscaler have spotted a strain of the Android Marcher Trojan masqueraded as the recently released Super Mario Run mobile game for Apple’s iOS.
Marcher is a sophisticated banking trojan that was used by cyber criminals to steal financial data from the victims.
“Marcher is a sophisticated banking malware strain that targets a wide variety of banking and financial apps and credit cards by presenting fake overlay pages. Once the user’s mobile device has been infected, the malware waits for victims to open one of its targeted apps and then presents the fake overlay page asking for banking details.” states the analysis published by Zscaler.
Super Mario Run mobile game for iOS device is one of the most interesting projects of the Nintendo, the company developed for Apple devices the notorious game. Anyway, Super Mario Run is still not available for Android, and crooks are taking advantage of this to spread their malicious variant.
The malicious code found by Zscaler installs the Marcher Trojan instead a legitimate version of Super Mario Run for Android.
“In this new strain, the Marcher malware is disguised as the Super Mario Run app for Android. Knowing that Android users are eagerly awaiting this game, the malware will attempt to present a fake web page promoting its release.” continues the blog post published by Zscaler.
The experts also shared the following details related to the threat:
- Name : Super Mario Run
- Package Name : uiq.pizfbwzbvxmtkmtbhnijdsrhdixqwd
- MD5 : d332560f1fc3e6dc58d94d6fa0dab748
- Detections : 12/55(at time of analysis)
When victims try to install the app it asks for multiple permissions including administrative rights.