{"id":135983,"date":"2019-05-23T21:45:31","date_gmt":"2019-05-23T21:45:31","guid":{"rendered":"http:\/\/sftarticles.wpenginepowered.com\/en\/?p=135983"},"modified":"2025-07-01T21:54:25","modified_gmt":"2025-07-02T04:54:25","slug":"android-malware-apps","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/android-malware-apps\/","title":{"rendered":"These apps are leaving malware all over your Android"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-138551\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2021\/05\/700_Android_fpxvdv.jpg\" alt=\"Android \" width=\"700\" height=\"394\" \/><\/p>\n<p>Google recently released its annual <a href=\"https:\/\/source.android.com\/security\/reports\/Google_Android_Security_2018_Report_Final.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">Android security report<\/a>, which covered 2018\u2019s biggest <strong>malware<\/strong> trends.<\/p>\n<p>The report found that there are a lot of scammy apps in the <strong>Play Store<\/strong>, with the amount of downloaded malware <a href=\"https:\/\/www.zdnet.com\/article\/google-malware-in-google-play-doubled-in-2018-because-of-click-fraud-apps\/\" target=\"_blank\" rel=\"noopener noreferrer\">up 100% since the year before<\/a>.<\/p>\n<p>However, Google downplayed the findings, stating that the bulk of the PHAs (potentially harmful apps) available for download were<strong> click-fraud apps<\/strong>.<\/p>\n<p>Yet, it&#8217;s hard to ignore the sheer volume of reports about the platform and the security risks lurking inside seemingly harmless apps. <a href=\"https:\/\/en.softonic.com\/articles\/protect-yourself-from-trickbot\" target=\"_blank\" rel=\"noopener noreferrer\">The malware program <b>Trickbot <\/b>was\u00a0recently found in a large number of devices around tax season.<\/a><\/p>\n<p>For Android, we found the worst offenders and the sheer number of downloads these malicious apps had:<\/p>\n<h2>Android malware list<\/h2>\n<p>The Android malware list just keeps getting longer, proving that Google&#8217;s filters need some work.<\/p>\n<p>Here are the latest developments in Play Store malware news:<\/p>\n<h3>Aggressive adware<\/h3>\n<p>Avast\u2019s cybersecurity team recently found <a href=\"https:\/\/blog.avast.com\/adware-plagues-google-play\" target=\"_blank\" rel=\"noopener noreferrer\">roughly 50 apps in the Play store<\/a> pretending to be \u201clifestyle\u201d apps, but install malware on user devices in an effort to get as many clicks as possible.<\/p>\n<figure id=\"attachment_138556\" aria-describedby=\"caption-attachment-138556\" style=\"width: 700px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-138556\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2021\/05\/HiFit_vledib.jpg\" alt=\"HiFit app\" width=\"700\" height=\"489\" \/><figcaption id=\"caption-attachment-138556\" class=\"wp-caption-text\">One of the apps in question<\/figcaption><\/figure>\n<p>According to the report, the <strong>SDK<\/strong> is easy to spot in the code. However, checking the code for signs of <strong>adware<\/strong> is not necessarily something most people know how to do.<\/p>\n<p>If you&#8217;d like to see what adware looks like in action, here&#8217;s a short clip:<\/p>\n<h3>Check Point<\/h3>\n<p>Check Point researchers<a href=\"https:\/\/research.checkpoint.com\/simbad-a-rogue-adware-campaign-on-google-play\/\" target=\"_blank\" rel=\"noopener noreferrer\"> found a code called Simbad <\/a>in just over 200 Android apps in the Google Play store. They found it had been <strong>downloaded a total of 150 million times.<\/strong><\/p>\n<p>Simbad is an adware code hidden inside a software development kit or SDK. It is designed to i<strong>nstall adware on your phone without your knowledge<\/strong>, then displays ads.<\/p>\n<figure id=\"attachment_138561\" aria-describedby=\"caption-attachment-138561\" style=\"width: 700px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-138561\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2021\/05\/Check_Point_cp02ox.jpg\" alt=\"Check Point infographic\" width=\"700\" height=\"427\" \/><figcaption id=\"caption-attachment-138561\" class=\"wp-caption-text\">Infographic courtesy of Check Point<\/figcaption><\/figure>\n<p>The Check Point investigation found that apps containing the code made it look like the user was clicking on ads repeatedly. The fraudulent clicks are an effort to generate ad revenue, and the activity takes place without the user\u2019s knowledge.<\/p>\n<p>According to <a href=\"https:\/\/www.bullguard.com\/blog\/2019\/04\/over-200-android-apps-infected-by-malware\" target=\"_blank\" rel=\"noopener noreferrer\">Bullguard\u2019s security blog<\/a>, these are the top 10 downloads from this batch:<\/p>\n<ul>\n<li>Snow Heavy Excavator Simulator &#8211; 10 million downloads<\/li>\n<li>Hoverboard Racing \u2013 5 million downloads<\/li>\n<li>Real Tractor Farming Simulator \u2013 5 million downloads<\/li>\n<li>Ambulance Rescue Driving \u2013 5 million downloads<\/li>\n<li>Heavy Mountain Bus Simulator 2018 \u2013 5 million downloads<\/li>\n<li>Fire Truck Emergency Driver \u2013 5 million downloads<\/li>\n<li>Farming Tractor Real Harvest Simulator \u2013 5 million downloads<\/li>\n<li>Car Parking Challenge \u2013 5 million download<\/li>\n<li>Speed Boat Jet Ski Racing \u2013 5 million downloads<\/li>\n<li>Water Surfing Car Stunt &#8211; 5 million downloads<\/li>\n<\/ul>\n<p>You can <a href=\"https:\/\/www.onlinethreatalerts.com\/article\/2019\/3\/15\/remove-these-210-android-apps-they-are-infected-with-adware\/\" target=\"_blank\" rel=\"noopener noreferrer\">read the full list here.\u00a0<\/a>It might be a good idea to check it out if you have a thing for games that let you drive anything from tractors to emergency services vehicles.<\/p>\n<h3>Exodus<\/h3>\n<p>It was recently discovered that <a href=\"https:\/\/securitywithoutborders.org\/blog\/2019\/03\/29\/exodus.html\" target=\"_blank\" rel=\"noopener noreferrer\">hackers hid government spyware<\/a> in plain sight inside Android apps on the Play Store.<\/p>\n<p>While the malicious decoy apps appear to be hidden in the Italian version of the store, this discovery shows that Google&#8217;s filters aren&#8217;t as airtight as they say.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-138429\" title=\"Exodus Italian malware\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2021\/05\/Screen_Shot_2019-05-12_at_11.03.28_PM_k9hn3p.jpg\" alt=\"Exodus in the Play Store\" width=\"700\" height=\"559\" \/><\/p>\n<p>The<strong> government spyware<\/strong>, known as <strong>Exodus<\/strong>, could <a href=\"https:\/\/www.wired.com\/story\/exodus-spyware-ios\/\" target=\"_blank\" rel=\"noopener noreferrer\">extract passwords, chat logs, contacts, and recordings<\/a> from rooted phones. It also collects basic details about a phone.<\/p>\n<p>It&#8217;s worth pointing out that Google patched a <strong>Linux<\/strong> exploit called <strong>DirtyCOW<\/strong> back in 2016 to block access.<\/p>\n<p>This means any new or recently-updated phone is immune to the attack, provided you stick with the phone&#8217;s built-in security settings. It\u2019s when you start messing around with the customization options that you get into trouble.<\/p>\n<h3>Gutstuff<\/h3>\n<p><a href=\"https:\/\/www.investinblockchain.com\/this-new-android-malware-targets-32-crypto-and-100-bank-apps-heres-how-not-to-get-hacked\" target=\"_blank\" rel=\"noopener noreferrer\">Gutstuff is a trojan targeting crypto investing apps.\u00a0<\/a>It is aiming for \u201c<strong>mass infections and maximum profits<\/strong>.\u201d How\u2019s that for a corporate mission statement?<\/p>\n<p>How Gutstuff works is through a good old-fashioned <strong>phishing attack<\/strong> by way of &#8220;web fakes.&#8221; Hackers set up apps that look like regular applications such as <strong>BitPay, Coinbase, and Bitcoin Wallet<\/strong>, as well as traditional banking institutions like <strong>Bank of America <\/strong>and<strong> Wells Fargo.<\/strong><\/p>\n<p>Infected users attempting to use one of the applications will be redirected to a fake page. From there, they&#8217;ll enter sensitive details so that hackers can steal from their accounts.<\/p>\n<h2>Signs that your Android has malware<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-138585\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2021\/05\/700_Malware_phone_mj7hla.jpg\" alt=\"Phone malware\" width=\"700\" height=\"467\" \/><\/p>\n<p>Look, while Google says that most malware isn\u2019t malicious, it can <strong>slow you down.<\/strong><\/p>\n<p>According to <strong>Norton Antivirus<\/strong>, <a href=\"https:\/\/us.norton.com\/internetsecurity-malware-how-to-remove-malware-from-android-phones.html\" target=\"_blank\" rel=\"noopener noreferrer\">malware is often programmed to perform repetitive tasks<\/a> that use up your phone\u2019s resources.<\/p>\n<p>If you\u2019ve been racing a lot of tractors or using third-party lifestyle apps, you might notice the following signs:<\/p>\n<ul>\n<li>Your phone is slower than usual<\/li>\n<li>The battery drains faster than normal<\/li>\n<li>You\u2019re seeing more pop-up ads<\/li>\n<li>You\u2019re going over data limits<\/li>\n<li>You\u2019ve noticed apps on your phone that you don\u2019t remember downloading<\/li>\n<\/ul>\n<p>If you notice malware on your phone, turn your phone on safe mode and <strong>uninstall the apps in question<\/strong>. If you&#8217;re unsure whether your phone is protected, it might be worthwhile to look into a paid antivirus program from a reputable company. After all, many anti-virus apps are adware themselves.<\/p>\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"Malwarebytes\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-logo-l,f_auto,dpr_auto\/p\/04cdb438-96d1-11e6-ac69-00163ed833e7\/2013167558\/malwarebytes-anti-malware-logo.png\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Malwarebytes<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/malwarebytes-anti-malware.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">Download now \u25ba<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--80\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"80\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"8\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\">8<\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/malwarebytes-anti-malware.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n<h2>Do I need antivirus for Android?<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-138588\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2021\/05\/AVG_dcja9r.jpg\" alt=\"AVG android\" width=\"700\" height=\"467\" \/><\/p>\n<p>No, but you do need to be careful.<\/p>\n<p>A report from AV-Comparatives found that <a href=\"http:\/\/en.softonic.com\/articles\/android-antivirus-app-test\/\" target=\"_blank\" rel=\"noopener noreferrer\">most Android antivirus apps don\u2019t do anything<\/a> but take up space. The reason they can get away with this is most malware isn\u2019t a full-on attack. They instead trigger the little stuff like apps that generate pop-ups or collect information about your personal habits.<\/p>\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"AVG AntiVirus Free\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-logo-l,f_auto,dpr_auto\/p\/afedbb98-96d0-11e6-a476-00163ed833e7\/2476911703\/avg-antivirus-free-AVG-Antivirus-logo-256x256.png\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">AVG AntiVirus Free<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/avg-antivirus-free.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">Download now \u25ba<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--80\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"80\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"8\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\">8<\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/avg-antivirus-free.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n<p>Given that most malware apps are a racket, you\u2019ll need to get smart about your security settings and what you choose to download.<\/p>\n<p>Most items in the Google Play Store are vetted by Google\u2019s review system. Most of what slips through the cracks are <strong>data harvesting apps<\/strong> or some kind of advertising scam, as we&#8217;ve mentioned above.<\/p>\n<p>If you want to avoid these apps, keep your wits about you. If something sounds too good to be true or possibly malicious, it probably is.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>These apps were downloaded hundreds of millions of times. Learn what they do, and how to avoid them. <\/p>\n","protected":false},"author":9161,"featured_media":138553,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[1015],"tags":[1082,1734,1627],"usertag":[839],"vertical":[],"content-category":[],"class_list":["post-135983","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-android","tag-apps","tag-malware","usertag-vpn"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/135983","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9161"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=135983"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/135983\/revisions"}],"predecessor-version":[{"id":325992,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/135983\/revisions\/325992"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/138553"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=135983"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=135983"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=135983"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=135983"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=135983"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=135983"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}