Skip to main content
  1. Home
  2. Phones
  3. Android
  4. Mobile
  5. News

FalseGuide malware injects unwanted ads, could have infected 2 million phones

Add as a preferred source on Google

Another week, another Android malware.

Android malware often takes the form of infected apps on the Google Play Store, and a new variant called FalseGuide has been discovered by security company Check Point.

Recommended Videos

While Google has been pushing monthly security updates, manufacturers like Samsung unfortunately often delay on pushing these updates to customers. The result? According to Google, half of Android devices did not receive security updates in 2016. That’s particularly problematic when malware like FalseGuide shows up, as it gives that malware an opportunity to take advantage of more unprotected phones.

“FalseGuide creates a silent botnet out of the infected devices for adware purposes. A botnet is a group of devices controlled by hackers without the knowledge of their owners,” says Check Point in a blog post. “The bots are used for various reasons based on the distributed computing capabilities of all the devices.”

Issues arise when the apps are downloaded, after which they’ll request administrator permissions, which can then be used against the owner of the phone. For now, it appears as though those permissions allow the app to deliver “illegitimate pop-up ads out of context,” but they could also be used to instigate DDoS attacks.

The malware was first discovered a few days ago, and appeared in a hefty 44 game guide apps. Those apps were since removed, but another five apps with the malicious code were then discovered. Scarily enough, some of these apps were uploaded as early as November 2016 — so they stayed on the Google Play Store for around 5 months before being taken down. As far as users impacted by the malware, Check Point estimates between 500,000 to 1.8 million users. Thankfully, of the 49 infected apps, 28 of them were downloaded less than 10 times and seven of them were apparently never downloaded.

It’s unlikely the Google Play Store will ever be totally safe — but it is the safest place to download Android apps. For now, it’s important to download only official apps, and stick with the ones that you trust.

Christian de Looper
Christian de Looper is a long-time freelance writer who has covered every facet of the consumer tech and electric vehicle…
TSMC might set up a price hike that could come straight for your next phone, laptop, or tablet
Here's what TSMC's rumored 10% chip price increase actually means in dollar terms, and why your next phone or laptop could end up costing more.
TSMC Fab

My wallet flinched the second I saw the words "TSMC" and "price increase" in the same headline, and honestly, yours should too.

Turns out the company behind the silicon powering basically every flagship device out there, including Apple’s A-series and Qualcomm’s Snapdragon processors, is reportedly about to make all of it a little pricier.

Read more
Samsung’s free storage doubling for preorders is gone in Austria, and the replacement isn’t as sweet
Samsung's free storage doubling deal might just be history.
The back of the Galaxy Z Fold 7

If you've pre-ordered a Samsung foldable purely for the free storage bump, tomorrow's Unpacked event might sting a little.

For years, pre-ordering a new Galaxy meant automatically getting double the storage at no additional charge. Buy the 128GB model, walk away with 256GB for the same price. The same applied to the 256GB and 512GB models. However, that might change at the upcoming Galaxy Unpacked event. 

Read more
Apple fixes Hide My Email bug that exposed users’ real email addresses
Here's how Apple's Hide My Email flaw leaked real addresses for over a year, and why it only got fixed once the story went public.
apple-merging-sign-in-with-apple-hide-my-email-icloud+

Turns out the "Hide" part of Hide My Email wasn't doing its job quite as advertised, something that I covered early in July. Security researcher Tyler Murphy reported the flaw in June 2025, but despite Apple claiming it was resolved in March 2026, independent tests confirmed it remained exploitable, at least until July 3, 2026.

So how did this bug actually work?

Read more