• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

Researchers Find 35 Adware Apps on Google Play

You are here: Home / General Cyber Security News / Researchers Find 35 Adware Apps on Google Play
August 18, 2022

Security experts have repeated warnings about malicious applications hiding on official mobile app stores after finding dozens of them on Google Play.

Bitdefender said it identified 35 in total by using behavioral analysis technology to scan the marketplace. They totaled over two million downloads.

The apps perform various malicious activities to achieve persistence on the user’s device and bombard them with advertising, but could also be a conduit for malware, Bitdefender warned.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


“Many legitimate apps offer ads to their users, but these ones show ads through their own framework, which means they can also serve other types of malware to their victims,” it said.

“Most of the time, users can choose to delete the application if they don’t like it. But these new malicious apps trick victims into installing them, only to change their name and icons and even take some extra steps to conceal their presence on the device. Users can still delete them at will, but the developers make it more difficult to find them on the affected devices.”

A “GPS Location Maps” app was the most popular of the bunch, garnering over 100,000 downloads but no reviews.

Immediately after downloading, it apparently changes its label from “GPS Location Maps” to “Settings,” and also changes its icon, making it more difficult for users to find and uninstall it.

Then developer also used heavily obfuscated code and encryption to make reverse engineering more challenging for researchers, Bitdefender claimed.

Other techniques observed by the researchers to hide the adware include ensuring the apps don’t show in the list of those most recently used on Android. Some apps also request permission to bypass the battery optimization feature so they don’t automatically get shut down by the OS, the report noted.

Although the official developer names linked to these 35 apps are all different, Bitdefender noticed that the email addresses and websites associated with them appear similar, indicating they’re the work of a single entity or individual.

The vendor urged user caution, even on official marketplaces, and particularly regarding apps with large download figures but few reviews or ones that request excessive permissions.

“While official stores are usually very good at weeding malicious or dangerous applications out, some history shows that a small number of bad apps manage to get through and make victims until they get reported,” it concluded. 

“Just because we download an app from the official store doesn’t mean it will be safe.”


Some parts of this article are sourced from:
www.infosecurity-magazine.com

Previous Post: «Cyber Security News Suspected Russian Money Launderer Extradited to US
Next Post: Researchers Find 35 Adware Apps on Google Play Cyber Security News»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Freejacking Campaign By PurpleUrchin Bypasses Captchas
  • ChatGPT Used to Develop New Malicious Tools
  • Dark Web Actors Fight For Drug Trafficking and Illegal Pharmacy Supremacy
  • Kinsing Cryptojacking Hits Kubernetes Clusters via Misconfigured PostgreSQL
  • New Study Uncovers Text-to-SQL Model Vulnerabilities Allowing Data Theft and DoS Attacks
  • UK insurer announces ‘world-first’ cyber catastrophe bond
  • Why Do User Permissions Matter for SaaS Security?
  • FCC plans strict overhaul of 15-year-old US data breach regulations
  • Security updates for Windows 7 finally end, users urged to upgrade
  • Global Cyber-Attack Volume Surges 38% in 2022

Copyright © TheCyberSecurity.News, All Rights Reserved.