Beyond the Virus: A First Look at Coronavirus-themed Mobile Malware
Liu Wang, Ren He, Haoyu Wang, Pengcheng Xia, Yuanchun Li, Lei Wu,, Yajin Zhou, Xiapu Luo, Yulei Sui, Yao Guo, Guoai Xu

TL;DR
This study provides the first systematic analysis of coronavirus-themed mobile malware, revealing their trends, behaviors, and origins, and offers a publicly available dataset for future research.
Contribution
It introduces a comprehensive dataset of COVID-19 themed Android apps and malware, and analyzes their characteristics, behaviors, and developer profiles during the pandemic.
Findings
Malicious COVID-19 apps surged with the pandemic's onset.
Most malware camouflages as benign apps using common identifiers.
Majority of malware creators are newcomers, mainly in the US.
Abstract
As the COVID-19 pandemic emerged in early 2020, a number of malicious actors have started capitalizing the topic. Although a few media reports mentioned the existence of coronavirus-themed mobile malware, the research community lacks the understanding of the landscape of the coronavirus-themed mobile malware. In this paper, we present the first systematic study of coronavirus-themed Android malware. We first make efforts to create a daily growing COVID-19 themed mobile app dataset, which contains 4,322 COVID-19 themed apk samples (2,500 unique apps) and 611 potential malware samples (370 unique malicious apps) by the time of mid-November, 2020. We then present an analysis of them from multiple perspectives including trends and statistics, installation methods, malicious behaviors and malicious actors behind them. We observe that the COVID-19 themed apps as well as malicious ones began…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Malware Detection Techniques · Spam and Phishing Detection · Network Security and Intrusion Detection
