Pokemon Go virus is a term used to describe cyber infection that pretends to be the original video game
Pokemon Go virus is type of malware that pretends to be original game based on Nintendo's classic series Pokemon
Pokemon Go virus is a type of dangerous cyber threat that inifltrates users' Android devices when they are trying to download the unofficial version of the mega-popular Pokemon Go video game published by Niantic, Inc. As evident, the malicious version of the game has nothing to do with the original one, as it is safe to use and play.
Questions about Pokemon Go virus
Nevertheless, cybercriminals are often abusing the most popular titles and, due to the gaming industry becoming one of the leading among entertainment sectors, bad actors are looking for ways to infect players with malware. However, Pokemon Go is not the only hacking victim, as titles like Fortnite and Apex Legends are widely abused by cybercriminals.
|Name||Pokemon Go virus|
|Type||Trojan, RAT (Remote access trojan)|
|Infiltration methods||Fake Pokemon Go app from third-party sites, cheat programs, malicious apps in Google Play|
|Date introduced||July 2016|
|Targeted devices||Android and iOS|
|Risk factors||Infiltration of other malware, loss of money, sensitive information disclosure to cybercriminals, etc.|
|Termination||Use reputable security solution to delete Pokemon Go malware|
|Recovery||To restore your mobile device to pre-infection state, scan it with Reimage|
Besides illegitimate versions in the game, which usually results in Remote Access Trojan (RAT) or ransomware installation, the cheat apps and cracks are also present and pose a significant threat to many users. If you downloaded any of such fake versions of cheats, you should remove Pokemon Go virus by scanning your device with reputable security software immediately.
Another variant of malicious Pokemon Go apps include “Install Pokemongo” and “Guide & Cheats for Pokemon Go” – these apps charged considerable amounts of money to help the users collect Pokecoins, Pokeballs, and Lucky Eggs. Google Play reacted quickly, and these apps are no longer available to obtain. Do not be deceived, though, because not all of the programs related to the original app are dangerous. For instance, “Poké Radar” and “Helper for Pokémon Go” are completely legitimate programs which only help the users enhance their gaming experience.
Pokemon Go virus is a type of malware that can give a remote access to hackers
What significantly increases the possibility of smartphones and tablets being infected with a fake Pokemon Go version is that the original one is not yet released in all countries, such as Japan, China or South Korea. The impatient users might be looking for the non-existing game in the app store and that is where the creators of malicious apps have a chance of stepping in.
The very first Pokemon Go virus infections go back to 2016
The first sightings of Pokemon Go virus occurred in July 2016, when users downloaded a fake version of the game on third-party sites. This payload consisted of RAT (remote access trojan) payload called Droidjack, which essentially served as a secret passage to the device, and would allow the attacker to take over it completely.
This malicious version of Pokemon Go was tracked to a dynamic IP that originated in Turkey, which is often used to start botnet chains or used for spam campaigns. The domain name was traced to No-IP.org – am an underground site that was used by cybercriminals for their shady activities previously.
Upon installation, the Pokemon Go virus asks for the following permissions:
- To connect and disconnect from the WiFi;
- View WiFi connections;
- Change network connectivity;
- Retrieve the information about running apps.
Besides these extra permissions, the Pokemon Go virus looked identical to the real game version. If you noticed that the app is asking you to allow the features mentioned above, immediately terminate the installation process as you will be infected with malware.
The very first Pokemon Go virus sightings were observed in 2016, when a fake version of the app installed a RAT trojan Droidjack
Pokemon Go virus was used by cybercriminals to root the device, upload other malicious files and show intrusive ads
Possibly the most renown version of Pokemon Go virus was spotted in September 2016, when Kaspersky security researchers discovered a trojan that slipped into Google Play and was downloaded more than 500,000 times before being taken down.
This version of Pokemon Go virus installed an obfuscated malware payload via the app called “Guide for Pokemon Go New” – it is a supposed helper for the users who want to learn more about Pokemon Go gaming peculiarities. However, what users did not know is that they will allow the malicious payload to root the device, download more malicious files, and display intrusive ads on every site that they visit.
However, malware's capabilities do not end there. This Pokemon Go virus did an excellent job while trying to hide its presence from anti-malware tools by idling before contacting it's Command & Control servers. In the meantime, the infection would determine whether the machine is virtual or not (it is an environment experts analyze malware samples in). After that, the Pokemon Go virus would send information about the infected device, such as its set language, model, software version, etc.
PokemonGo ransomware – a Pokemon-themed cryptovirus that took the code from Hidden Tear
It did not take long for crooks to create a ransomware type virus based on Pokemon Go. Just as previous malware that was based on the game, this threat also used a fake installer to infiltrate players' devices.
As soon as first samples emerged, security researchers noticed right away that PokemonGo ransomware is based on HiddenTear – an open source ransomware project that was initially released for educational purposes, although cybercriminals quickly adapted it as well.
Upon infiltration, PokemonGo ransomware creates a backdoor “Hack3r” account that is assigned to the administrator group, although it is not visible on the login screen due to the registry modification. It also copies its main executable to all removable drives.
PokemonGo virus then encrypts all personal files with AES and uses encryption key “123vivalalgerie.” The ransom note is written in Arabic and demands victims to write an email to email@example.com. Nevertheless, the malware is still in development stages, as plenty of evidence suggests. For example, the virus tries to communicate with a C&C server, although it is not able to because its IP is set to private.
Always be extra careful when installing new apps, even if they seem legitimate
One of the main reasons for mobile device cyber infections comes from the careless installation of various apps from third-party sites. By default, mobile phones, be it iPhones or Androids, would not allow users to install apps from unofficial sources, not without certain modifications at least. Thus, users have to deliberately enable such feature to let potentially dangerous applications in.
Therefore, do not trust any third-party sites and download apps from Google stores or App Store instead. Even there, you cannot be 100% sure because cybercriminals always think of new ways how to bypass set security measures, and some malicious apps still manage to get into official stores. Therefore, always read reviews about the app and research it online.
Finally, it is just as vital keeping your phone updated and running a comprehensive security solution that would prevent malicious programs from entering your device.
Ways to remove Pokemon GO virus from Android and iOS devices
As we have already mentioned, Pokemon Go removal can be carried out using proper antivirus software. Make sure that you obtain a utility compatible with your device. Otherwise, you may not be able to run the system scan. If the program is not malicious, though, antivirus utilities may not register it.
In such a case, you can simply remove Pokemon Go app from your device through the regular device settings. Most importantly, remember always to keep a close watch for potentially dangerous applications.