nerdexam
EC-Council

312-50V12 · Question #21

Don, a student, came across a gaming app in a third-party app store and installed it. Subsequently, all the legitimate apps in his smartphone were replaced by deceptive applications that appeared…

The correct answer is D. Agent Smith attack. Agent Smith attacks are carried out by luring victims into downloading and installing malicious apps designed and published by attackers in the form of games, photo editors, or other attractive tools from third-party app stores such as 9Apps. Once the user has installed the…

Submitted by saadiq_pk· Mar 4, 2026Wireless Network, Mobile, IoT, and OT Hacking

Question

Don, a student, came across a gaming app in a third-party app store and installed it. Subsequently, all the legitimate apps in his smartphone were replaced by deceptive applications that appeared legitimate. He also received many advertisements on his smartphone after installing the app. What is the attack performed on Don in the above scenario?

Options

  • ASIM card attack
  • BClickjacking
  • CSMS phishing attack
  • DAgent Smith attack

How the community answered

(58 responses)
  • A
    3% (2)
  • B
    2% (1)
  • D
    95% (55)

Explanation

Agent Smith attacks are carried out by luring victims into downloading and installing malicious apps designed and published by attackers in the form of games, photo editors, or other attractive tools from third-party app stores such as 9Apps. Once the user has installed the app, the core malicious code inside the application infects or replaces the legitimate apps in the victim’s mobile device C&C commands. The deceptive application replaces legitimate apps such as WhatsApp, SHAREit, and MX Player with similar infected versions. The application sometimes also appears to be an authentic Google product such as Google Updater or Themes. The attacker then produces a massive volume of irrelevant and fraudulent advertisements on the victim’s device through the infected app for financial gain. Attackers exploit these apps to steal critical information such as personal information, credentials, and bank details, from the victim’s mobile device through C&C commands.

Topics

#mobile malware#Agent Smith attack#deceptive applications

Community Discussion

No community discussion yet for this question.

Full 312-50V12 Practice