Over the past couple of months, security researchers identified several applications in Google Play that were designed to download the SharkBot Android trojan.
SharkBot was initially detailed in November 2021, when it was only being distributed through third-party application stores. The threat was mainly focused on initiating unauthorized money transfers via Automatic Transfer Systems (ATS) by auto-filling fields in legitimate applications.
In early March, NCC Group reported that several SharkBot droppers had made their way into Google Play, all of which showed identical code and behavior.