cxo voice
  • Business
  • Technology
    • Artificial Intelligence
    • Cloud
    • Telecom
    • Data Center
    • BPM
    • Blockchain
  • Finance
    • Banking
  • CXO Insights
  • Cyber Security
  • CXO Interviews
No Result
View All Result
  • Business
  • Technology
    • Artificial Intelligence
    • Cloud
    • Telecom
    • Data Center
    • BPM
    • Blockchain
  • Finance
    • Banking
  • CXO Insights
  • Cyber Security
  • CXO Interviews
No Result
View All Result
Leaders Talk and Latest Tech News | CXO VOICE
No Result
View All Result
Home Cyber Security

Mobile Malware Agent Smith Infected 25 Million Devices: Check Point Report

Deepa Sharma by Deepa Sharma
July 11, 2019
Mobile Malware agent smith infected mobile device

New variant of mobile malware has infected around 25 million devices, in which 15 million are from India, according to cyber security firm Check Point‘s research report. Malware Agent Smith auto replaces already installed apps with malicious version without any user initiation completely silently, users have no idea of this app replacement. This unique on-device, just-in-time (JIT) approach inspired researchers to dub this malware as “Agent Smith”.

It disguised as Google normal apps, mobile malware exploits various known Android devices vulnerabilities and automatically replaces installed apps on the device with malicious versions without the user’s interaction.

Malware Agent Smith broadly using its access to the mobile devices as a resources to show fraudulent, spam ads for financial gain, but could easily be used for far more intrusive and harmful purposes such as financial banking login credential theft and eavesdropping. This activity resembles previous malware campaigns such as Gooligan, Hummingbad and CopyCat.

Mobile malware Agent Smith Attack flow

Mobile Malware agent smith infected mobile device

Head of Mobile Threat Detection Research at Check Point Software Technologies, Jonathan Shimonovich said “The malware attacks user-installed applications silently, making it challenging for common Android users to combat such threats on their own, Combining advanced threat prevention and threat intelligence while adopting a ‘hygiene first’ approach to safeguard digital assets is the best protection against invasive mobile malware attacks like “Agent Smith”. In addition, users should only be downloading apps from trusted app stores to mitigate the risk of infection as third party app stores often lack the security measures required to block adware loaded apps.”

Malware Agent Smith was originally downloaded from the widely-used third party app store, 9Apps and targeted mostly Hindi, Arabic, Russian, Indonesian speaking users. So far, the primary victims are based in India, approx 15 million devices infected with this mobile malware, Pakistan and Bangladesh devices also have been targeted and infected.

There has also been a noticeable number of infected devices in the United Kingdom, Australia and the United States. Check Point has worked closely with Google and at the time of publishing, no malicious apps remain on the Play Store.

Agent Smith malware has a modular structure and consists of the following modules:

  • Loader
  • Core
  • Boot
  • Patch
  • AdSDK
  • Updater

As stated above, the first step of this infection chain is the dropper. The dropper is a repacked legitimate application which contains an additional piece of code – “loader”.

The loader has a very simple purpose, extract and run the “core” module of “Agent Smith”. The “core” module communicates with the C&C server, receiving the predetermined list of popular apps to scan the device for. If any application from that list was found, it utilizes the Janus vulnerability to inject the “boot” module into the repacked application. After the next run of the infected application, the “boot” module will run the “patch” module, which hooks the methods from known ad SDKs to its own implementation.

Mobile Malware agent smith infected mobile device
  • Read More: How to protect your children from advance cyber threats?
Deepa Sharma

Deepa Sharma

Deepa Sharma is CXOVoice’s Managing Editor, overseeing all coverage technology, cybersecurity, banking, and financial coverage. She can be reached at [email protected]

Related Posts

Security Spending India
Cyber Security

Information Security Spending in India to Reach $3.4 Billion in 2026: Gartner

March 9, 2026
AI-enabled cyberattacks
Cyber Security

2026 X-Force Threat Index Warns of AI-Enabled Exploits and Rising Cyberattacks

February 26, 2026
India’s AI
Business

Who Will Dominate India’s AI Infrastructure, Ambani and Adani or Global Tech?

February 20, 2026
Kyndryl cyber
Cyber Security

Kyndryl Launches First Cyber Defense Operations Center in Bengaluru

February 19, 2026
AI Hackathon
News

TCS Hosts AI Hackathon for Non-Engineering Students

February 12, 2026
Palo Alto Acquisition of CyberArk
Cyber Security

Palo Alto Networks Completes Acquisition of CyberArk to Lead in AI-Era Security

February 12, 2026
Cyber Resilience
Cyber Security

Why Identity Will Define Enterprise Cyber Resilience in an AI-First World

February 10, 2026
SAP AI Skills
News

SAP Aims to Help 12 Million Workers Gain AI Skills by 2030

February 6, 2026
Load More

More Articles

Infosys and Incora

Infosys and Incora to Collaborate on AI-Enabled Supply-Chain Operations

by News Desk
March 10, 2026

ABB India

ABB to Invest $75 Million to Expand Manufacturing and R&D in India

by Deepa Sharma
March 10, 2026

Intel Core Series 2

Intel Launches Core Series 2 Processor and Expands Edge AI Offerings

by Deepa Sharma
March 10, 2026

CoinSwitch Survey: Majority of Women Eye Crypto Investments in the Coming Year

CoinSwitch Survey: Majority of Women Eye Crypto Investments in the Coming Year

by Deepa Sharma
March 10, 2026

Get Weekly CXO Intelligence.

Loading

CXO Insights

AI cloud
Cloud

AI Workloads Are Shaping FinOps Priorities: Redefining Cloud Economics in 2026

by Deepak Mittal
March 10, 2026
AI India
Artificial Intelligence

AI as a Public Good: From Democratic Principles to Ground-Level Practice

by News Desk
February 13, 2026
Cyber Resilience
Cyber Security

Why Identity Will Define Enterprise Cyber Resilience in an AI-First World

by Sunil Sharma
February 10, 2026
HDDs storage
Opinion

5 Reasons HDDs Will Continue to Dominate Enterprise Storage in the AI Era

by Owais Mohammed
January 13, 2026

CXO Interviews

1Point1
Business

How 1Point1 Solutions Is Betting Its Future on AI to Redefine BPM

>
NewgenONE
Business

Reimagining Enterprise Transformation: Varun Goswami on the Future of NewgenONE and AI-Driven Automation

>
Jagat Shah, Chairman & CEO of MITSUMI Group
Business

Leadership in Emerging Markets: Exclusive Interview with Jagat Shah, Chairman & CEO of MITSUMI Distribution

>
Tokenization
Blockchain

Revolutionizing Finance: An Exclusive Interview with Sid Ugrankar, Co-founder of Qila.io on the Future of Blockchain and Tokenization

>

CXOVoice.com is a leading online publication for CXOs, entrepreneurs, senior leaders, developers, and industry professionals. We publish informed analysis, news reporting, expert commentary, and expert insights across enterprise technology, digital transformation, cybersecurity, data, AI, sustainability, and governance.

Connect with us

Easy Links

  • Cryptocurrency
  • Company Announcements
  • Event
  • Blockchain
  • Resources & Downloads
Loading
  • Home
  • About Us
  • Contact Us
  • Advertise
  • Privacy & Policy
  • Editorial Policy
  • Feedback

Copyright © 2026 CXOVoice - All Rights Reserved

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

Our Spring Sale Has Started

You can see how this popup was set up in our step-by-step guide: https://wppopupmaker.com/guides/auto-opening-announcement-popups/

No Result
View All Result
  • Home
  • News
  • Business
  • Technology
  • Cyber Security
  • Opinion

Copyright © 2026 CXOVoice - All Rights Reserved