The Samsung Galaxy Store is said to host and distribute several apps that could infect customers’ devices with malware. Tipster Max Weinbach first detected the issue in a few Showbox-based apps on the Samsung Galaxy Store. These apps are believed to contain malware, and Google’s Play Protect was able to detect them shortly after they were installed. In addition, the scan performed by the online virus and malware scanning service Virustotal on Showbox-based apps distributed on the Galaxy Store also showed low-quality alerts. Some apps would ask for excessive permissions, including phone access.
According to a report from Android Police, various Showbox movie hacking app clones offered by Samsung through its Galaxy Store may be able to infect devices with malware. Tipster Max Weinbach Point the issue first and posted his experience on Twitter saying that a similar type of issue has already been discovered on Huawei phones. According to him, while downloading Showbox-based apps from the Galaxy store, Google’s Play Protect warning activated, stopping the installation. At least five of the Showbox-based apps may have been malicious, Weinbach explains.
According to the report, Virustotal’s analysis of APKs of suspicious apps indicated several low-quality alerts, including risky software and adware. Some apps would also ask for unnecessary permissions, such as access to contacts, call logs and phone.
The report also says malicious Galaxy Store apps have been further investigated by mobile security analyst. linuxct, who stated that these apps contain ad technology capable of running dynamic code. This means that the application itself as distributed may not directly include malware, but it can download and run other code that may contain malware.
These apps would be clones of the ShowBox app and thus can stream pirated content to users’ devices. According to the Showbox subreddit, Showbox has been down for about two years. “There are no legitimate alternatives with the name ‘ShowBox’. Any websites or apps claiming to be ShowBox are fake,” the post read.