Poker player accused of running Android malware fuelled fake dating agency

Updated happygeek 0 Tallied Votes 468 Views Share

A successful tournament poker player from Japan, with earnings estimated at $1.5 million from his prowess at bluffing and holding his nerve under pressure, has been arrested and charged with being behind an Android malware distribution operation that netted even more: $3.9 million according to Symantec.

The Chiba Prefectural Police in Japan arrested a total of nine people in connection with distributing spam emails with download links to the Android.Enesoluty malware. Symantec reports that one of these was 50 year old Masaaki Kagawa, president of an IT firm from Shibuya, Tokyo. "His passion for taking chances and risks has paid off in the game of Poker" says Symantec employee Joji Hamada, who continues "but it’s not looking good for his gambling with Android malware."

It would appear that the Android malware operation was running between September 2012 and April 2013, with some 150 domains registered to the malicious apps which managed to collect more than 37 million email addresses from over 800,000 Android devices. This address list was then used to spam people in order to lure them to a fake online dating service, which in turn was where the profits of 390 million Yen are thought to have been made.

Dani AI

Generated

Useful practical guidance to follow up on ’s report — focused on what to do now (for users) and what to change long-term (for developers and site operators).

For device owners: assume any unsolicited installer link is untrusted. If a device shows unusual battery or data use, unexpected SMS/charges, or new apps you didn’t install, run a malware scan (Play Protect or a reputable Android AV), reboot into Safe Mode to disable third‑party apps, revoke any Device‑Administrator privileges the suspicious app may have, then uninstall it. Back up photos/contacts first. If an app resists removal, export logs and consider a factory reset as a last resort after saving evidence and credentials. Change passwords for email/financial accounts and enable 2‑factor authentication. If you entered payment details into a dubious site, contact the bank immediately to dispute charges.

For developers, operators and admins: harden signup/payment flows and your email reputation. Enforce SPF/DKIM/DMARC for mail, validate payments server‑side, rate‑limit new registrations, require email verification and CAPTCHAs, and monitor for bulk signups or anomalous IP/domain patterns. Treat stored email lists as high‑value secrets: encrypt at rest, rotate access keys, and log exports. Use device‑attestation or app‑integrity checks where appropriate to reduce automated abuse.

Incident response checklist: preserve device images and server logs before wiping; collect IPs, user agents, timestamps and mail headers; rotate any exposed API keys; notify affected users with remediation steps; and report the case to your national CERT or law enforcement when fraud is suspected.

Quick tip for power users: verify any APK before installing by checking its signature with the Android build tools, for example:

apksigner verify --print-certs app.apk

This complements the original report with practical defenses that help both individual users and service operators reduce harm from similar campaigns.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.