Skip to main content

Google Play Store malware hits 42 apps with 8 million downloads

Another day, another batch of Play Store apps found to contain malware.

This time, the 42 adware-infected apps received 8 million downloads in a campaign that lasted more than a year.

ESET, the long-established cybersecurity firm that discovered the adware, said that Google has now removed all of the offending apps, though it added that the software remains available on third-party app stores.

While many apps show ads legitimately, adware is considered a more sinister presence in that it, for example, serves up scam ads, gathers users’ personal information, drains a phone’s battery, and can be annoyingly persistent.

In this case, the malicious software served full-screen ads at random intervals and made it difficult for the user to know which app was responsible for the ads.

It also gathered data from the user’s handset that included device type, OS version, language, number of installed apps, available storage space, battery status, whether the device is rooted and developer mode enabled, and whether Facebook and Facebook Messenger are installed.

The apps were able to remain available on the Play Store for many months because the adware was designed to function in a way that gave it a greater chance of evading detection by Google’s security systems.

The alleged perpetrator

An extensive investigation detailed in its blog post led ESET to conclude the adware is the work of a college student in Vietnam. According to the cybersecurity firm, the developer started out by creating legitimate apps, but later included the adware to boost his income.

“The various stealth and resilience techniques implemented in the adware show us that the culprit was aware of the malicious nature of the added functionality and attempted to keep it hidden,” ESET said.

The most popular of the offending apps was Video Downloader Master, which received 5 million downloads before it was removed from the Play Store. Here are the apps that ESET reported to Google:

Image used with permission by copyright holder

If you have any of the above apps on your Android handset or tablet, the advice is to delete them immediately. Some of the apps were also found in Apple’s App Store but contained no adware, ESET said.

Choosing apps

ESET’s discovery is a timely reminder to take care when choosing apps to download to your device. If the app is new or isn’t well known, it’s worth spending a little time researching reviews or looking online for information on the developer.

Malicious apps have always been an issue for the Play Store, though Google said earlier this year that it’s working constantly to improve its abuse detection technologies and machine learning systems to deal with the issue, and employs a team of human reviewers, too.

In further efforts, the Google Play Protect security platform scans 50 billion apps on users’ devices on a daily basis to check the safety of the installed software.

In 2017, Google deleted 700,000 malicious apps from the Play Store, and banned 100,000 developers from submitting new ones.

Editors' Recommendations

Trevor Mogg
Contributing Editor
Not so many moons ago, Trevor moved from one tea-loving island nation that drives on the left (Britain) to another (Japan)…
Google’s Android monopoly finds its biggest challenge, and Apple might be next
Apps screen on the Google Pixel 7.

The Competition Commission of India slapped Google with two hefty fines over anti-competitive strategies that have allowed it to dominate the mobile ecosystem in India. Totaling over $250 million, the penalties reprimand Google for forcing smartphone makers to avoid Android forks, prefer Google’s web search service, and pre-install popular cash cows like YouTube on phones.

Google was also disciplined for forcing its own billing system on developers that allowed the giant to take up to a 30% share of all in-app purchases for applications listed on the app store. Google is not really a stranger to titanic penalties; The EU handed Google a record-breaking fine of approximately $5 billion in 2018 for abusing its dominant market position — a penalty that was upheld in September this year following Google’s appeal.

Read more
Google overhauls its Family Link app for easier parental controls
Google Family Link app.

Google's Family Link app has been a great resource for parents looking to keep an eye on what their children are up to with their devices. Now, it's getting even better thanks to an app overhaul that puts the focus on safety and communication. While the Google Family Link app has previously been praised for its solid parental control settings, the redesign adds plenty of new features that make it easier than ever for parents to monitor smart device usage while keeping children informed about the parental control settings in place.

In addition to a design update that sorts the app into three main tabs (Highlights, Controls, and Location), there's also a laundry list of new features coming to Family Link. Since safety is a huge part of what makes the app appealing, features such as notification alerts when a device arrives at a specific destination (like school or a friend's house) and the ability to see an individual device's battery life are new additions that give parents peace of mind when their kids leave the house.

Read more
Google wants you to know Android apps aren’t just for phones anymore
Person holding Samsung Galaxy smartphone showing Google Play Store.

When most people think of the Google Play Store, the first thing that comes to mind is smartphones. However, the spread of the Android ecosystem is far broader than that, and Google is taking steps to increase awareness of this and make it easier for folks to find apps on the Play Store for their smart TVs, watches, and even cars.

In a blog post today, the Google Play team announced three significant changes that should make it easier for Android fans to discover apps for all their devices, right from their phone. This includes recommendations of apps for non-phone devices, a search filter to focus on only games optimized for non-phone devices, and even a remote install feature that will let you deliver those apps to your Android TV, Wear OS watch, or Android Automotive-equipped car.

Read more