Dozens of Android Apps Secretly Serve Adware to Millions of Users

Security researchers discover 42 Android apps on the Google Play store that infect millions of devices with adware. The malicious apps hide their icons, mimic legitimate software, and actively avoid detection by Google's security systems.

Security researchers at ESET uncover 42 Android apps on the Google Play store that secretly serve full-screen ads to millions of unsuspecting users. These apps boast over eight million combined downloads since their debut in July 2018 and include popular titles like Video Downloader Master and Ringtone Maker Pro. Despite their innocent appearance, the applications hide malicious adware that triggers at random intervals once installed on a device.

To avoid detection and removal, the adware deletes its shortcut icon from the home screen and mimics the look of official Google and Facebook applications. The malicious software also exhibits evasive behavior by checking if the device connects to Google's servers, effectively hiding its ad-serving payload when Google tests the app. In the background, the apps quietly gather sensitive device data, such as installed applications and security settings, which attackers could use to deploy additional malware.

Google removes all 42 offending applications from the official Play Store following the discovery, though a company spokesperson provides no further comment. Investigators trace the sprawling adware campaign to a Vietnamese college student operating the scheme for profit. However, experts warn that these malicious apps remain available through various third-party app stores, continuing to pose a significant risk to Android users who download software outside of official channels.

Read More at the original source →