Skip to main content
  1. Home
  2. Phones
  3. Android
  4. Mobile
  5. News

Android malware 'Judy' earns hackers revenue by forcing devices to click on ads

Add as a preferred source on Google

There’s a new strain of Android malware going around, and it might be one of the most annoying yet.

On Tuesday, mobile security analysts at Check Point uncovered the innocuous-sounding Judy, code that’s infected at least 41 different apps on the Google Play Store, Android’s app marketplace. Once installed, Judy opens internet links and imitates the behavior of a PC, using JavaScript to hunt down and fraudulently click on ads served by Google’s advertising platform.

Recommended Videos

Most of Judy’s ad-serving occurs in the background, but the adware also injects a large number of advertisements into applications — in some cases leaving users no option but to click on them.

The endgame is to rake in revenue by infecting as many Android devices as possible, and the Judy hackers are well on their way. The malware bypassed Bouncer, Google’s AI-powered Play Store filter that automatically flags malware, by creating a benign “middleware” app that silently establishes a connection with a remote server and installs Judy’s code.

Making matters worse, many of the infected applications had high average Play Store user ratings — in some cases four out of five stars. “A high reputation does not necessarily indicate that the app is safe for use,” Check Point said. “Hackers can hide their apps’ real intentions or even manipulate users into leaving positive ratings, in some cases unknowingly. Users cannot rely on the official app stores for their safety, and should implement advanced security protections capable of detecting and blocking zero-day mobile malware.”

According to Checkpoint, Judy infected between 4.5 million and 18.5 million devices — some as early as April 2016. Most of the malicious apps were published by Korean company Kiniwini, but it’s unclear whether Enistudio, its parent company, was complicit — Check Point researchers discovered the Judy code in apps from unaffiliated developers, but suspect that it might have been shared by another hacking group.

Given the prevalence of malware like Judy, it’s no wonder that latest version of Android, Android O, doubles down on security. It introduces new and improved device encryption, tamper-resistant hardware, and in-app Safe Browsing, a Chrome browser feature that uses machine learning to alert you to potentially harmful web content.

The new security features build on Google’s efforts to harden Android against attackers. Google’s SafetyNet, which rolled out alongside Android Marshmallow last year, verifies that devices are what they claim to be. And Google is using machine learning and statistical analysis to pinpoint potentially harmful apps.

Google’s real-time, cloud-based security platform consists of more than 20,000 processors, the company said at its Google I/O developer conference in June, and scans more than 50 billion devices every day.

Kyle Wiggers
Kyle Wiggers is a writer, Web designer, and podcaster with an acute interest in all things tech. When not reviewing gadgets…
Vibecoded apps are flooding Apple’s App Store, and users are getting sick of them
App Store submissions have doubled this year as AI tools make it easier than ever to build an app, but downloads haven't kept pace, and for good reason.
Apple App Store homepage on an iPhone

Apple's App Store is in the middle of its steepest submission surge in years. Developers submitted nearly 600,000 new apps last year, marking a 30 percent jump over the previous year. That number has already doubled to roughly 560,000 new apps in just the first six months of this year, according to estimates from analytics firm Sensor Tower cited by the New York Times. The reason behind the spike is vibecoding, which allows people with no prior development experience to create new apps using AI tools.

A familiar boom, with a twist

Read more
Google Photos adds a quick toggle between AI and classic search
Classic search is finally easier to reach for people who enabled Ask Photos
Google's Ask Photos debut.

Google Photos is giving users an easier way to leave its Gemini-powered search when a simple keyword would do. A new toggle now sits at the top of the results page, letting users switch between Ask Photos and classic search without digging through settings.

The change appears to address feedback from people who opted into Ask Photos but wanted a quicker way to return to classic search when Gemini was slower or less useful for a straightforward query.

Read more
Snapseed Camera now lets Android users save original photos and add geotags
Google updates Snapseed Camera with geotag support and non-destructive photo editing
Snapseed App

Google appears to be quietly turning Snapseed into something more than just a photo editing app. Over the past few weeks, the company has been steadily adding new capabilities to Snapseed Camera, its standalone camera app for Android. The latest update introduces two practical features that many smartphone users have come to expect from modern camera apps: the ability to save an untouched copy of every image for future editing and support for embedding location data directly into photos.

Neither feature is flashy, but together they make Snapseed Camera a more capable photography tool, particularly for users who like experimenting with filters without permanently altering their original shots. According to a report by 9to5Google, the features are rolling out with Snapseed Camera version 4.1.1.x on Android.

Read more