Skip to main content
  1. Home
  2. Phones
  3. Android
  4. Mobile
  5. News

Android malware 'Judy' earns hackers revenue by forcing devices to click on ads

Add as a preferred source on Google

There’s a new strain of Android malware going around, and it might be one of the most annoying yet.

On Tuesday, mobile security analysts at Check Point uncovered the innocuous-sounding Judy, code that’s infected at least 41 different apps on the Google Play Store, Android’s app marketplace. Once installed, Judy opens internet links and imitates the behavior of a PC, using JavaScript to hunt down and fraudulently click on ads served by Google’s advertising platform.

Recommended Videos

Most of Judy’s ad-serving occurs in the background, but the adware also injects a large number of advertisements into applications — in some cases leaving users no option but to click on them.

The endgame is to rake in revenue by infecting as many Android devices as possible, and the Judy hackers are well on their way. The malware bypassed Bouncer, Google’s AI-powered Play Store filter that automatically flags malware, by creating a benign “middleware” app that silently establishes a connection with a remote server and installs Judy’s code.

Making matters worse, many of the infected applications had high average Play Store user ratings — in some cases four out of five stars. “A high reputation does not necessarily indicate that the app is safe for use,” Check Point said. “Hackers can hide their apps’ real intentions or even manipulate users into leaving positive ratings, in some cases unknowingly. Users cannot rely on the official app stores for their safety, and should implement advanced security protections capable of detecting and blocking zero-day mobile malware.”

According to Checkpoint, Judy infected between 4.5 million and 18.5 million devices — some as early as April 2016. Most of the malicious apps were published by Korean company Kiniwini, but it’s unclear whether Enistudio, its parent company, was complicit — Check Point researchers discovered the Judy code in apps from unaffiliated developers, but suspect that it might have been shared by another hacking group.

Given the prevalence of malware like Judy, it’s no wonder that latest version of Android, Android O, doubles down on security. It introduces new and improved device encryption, tamper-resistant hardware, and in-app Safe Browsing, a Chrome browser feature that uses machine learning to alert you to potentially harmful web content.

The new security features build on Google’s efforts to harden Android against attackers. Google’s SafetyNet, which rolled out alongside Android Marshmallow last year, verifies that devices are what they claim to be. And Google is using machine learning and statistical analysis to pinpoint potentially harmful apps.

Google’s real-time, cloud-based security platform consists of more than 20,000 processors, the company said at its Google I/O developer conference in June, and scans more than 50 billion devices every day.

Kyle Wiggers
Kyle Wiggers is a writer, Web designer, and podcaster with an acute interest in all things tech. When not reviewing gadgets…
Apple’s lease program is just a soft landing for you to spend on pricier iPhones this year
Hand holding iPhone 17 Pro.

A few days ago, Apple introduced a new "Upgrade" program that is essentially a lease program for buying Apple hardware. Instead of paying the full cost up front, you space the monthly installments (12, 24, and 36 month spells), and at the end of the lease period, you can choose to return the device, upgrade to a new one, or pay the remainder cost and keep it forever.

The broad idea is simple. Instead of taking a thousand-dollar hit on the wallet, you space the hit across small monthly payments. For a flagship iPhone, that broadly comes down to a dollar per day, and for budget phones such as the iPhone 17e, it's just half a dollar each day, if you do the breakdown. At least Apple is looking at it that way.

Read more
Pixel 11 leak predicts a weird mix of upgrades and downgrades for a higher price
The Pixel 11 may start at $899 with 256GB of storage, but its camera setup remains unclear.
Google Pixel 10a smartphone

Google may ask Pixel 11 buyers to pay $100 more for a phone that improves the parts they can’t see while leaving a conspicuous camera question unresolved. A new leak from Android Headlines puts the base model at $899, up from the Pixel 10’s $799 starting price.

The extra money would at least buy more capacity. The Pixel 11 reportedly starts at 256GB rather than 128GB, while the leaked specifications list both 12GB and 16GB RAM options. Yet the same list mentions only a main camera and an ultrawide, even though other leaked renders still appear to show three rear camera openings.

Read more
Google’s Pixel 11 Pro Fold could offer Galaxy Z Fold8 Ultra specs for $200 less
Google’s leaked foldable could match the Fold8’s price with Ultra-sized screens and 5x zoom
Electronics, Mobile Phone, Phone

Google may be preparing to challenge Samsung’s most expensive foldable without charging Ultra money. According to Android Headlines, the Pixel 11 Pro Fold will start at $1,899, matching the Galaxy Z Fold8 and undercutting the $2,099 Fold8 Ultra by $200.

Its rumored hardware makes that pricing especially interesting. Google’s foldable appears much closer to Samsung’s Ultra model in display size, even though it would cost the same as the smaller Fold8.

Read more