Experts of ESET found in the Turkish store of Android-applications CepKutusu Trojan program, which was distributed under the guise of legitimate applications.
Bank Trojan called Spy. Banker is designed to steal online banking data. It is able to intercept SMS messages from banking systems, download and install other applications.
Experts note that the link to download the malicious program was from all legitimate applications presented in the store CepKutusu. Each time the "Download" button was clicked, an attempt was made to infect the mobile device.
It is also noteworthy that after installation the Trojan did not even try to simulate the application downloaded by the user - instead it was masked by Adobe Flash Player (this program will cease to exist in 2020).
ESET suggests that the application store could be created specifically to distribute malware. According to the company's employees, it can potentially be implemented in which cybercriminals controlling such a store add malicious functions to all applications.
In order not to become a victim of hackers, the company recommends that users use only official application stores, avoiding alternative sites.