{"id":141166,"date":"2019-06-06T16:32:02","date_gmt":"2019-06-06T16:32:02","guid":{"rendered":"http:\/\/sftarticles.wpenginepowered.com\/en\/?p=141166"},"modified":"2025-07-01T21:49:58","modified_gmt":"2025-07-02T04:49:58","slug":"google-play-store-adware-threat","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/google-play-store-adware-threat\/","title":{"rendered":"Google Play Store adware threat could basically lock up your phone"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-141173\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2021\/04\/Google_Play_Store_apps_malware_r0cpte.jpg\" alt=\"play store app on dark background\" width=\"700\" height=\"394\" \/><\/p>\n<p>Malware found in Google Play Store app stories are becoming so regular you could set your watch by them. There have been a lot in recent memory, but the biggest by far has been the <a href=\"https:\/\/en.softonic.com\/articles\/google-play-store-bans-do-global?ex=BB-859.0\" target=\"_blank\" rel=\"noopener noreferrer\">bulk action Google was forced to take against Chinese app developer DO Global<\/a>. With apps totaling over <strong>half a billion downloads<\/strong>, DO Global\u2019s ban, for a number of reasons including sharing user data with the Chinese government, sent shockwaves through the app world.<\/p>\n<p>It now looks, however, like Google\u2019s problems with apps from China are far from over as a new security report has shed light on some worrying findings. According to the report, Google has a serious problem with the Chinese-based firm Cootek, due to <strong>unauthorized adware that can render victims&#8217; mobile phones almost completely unusable.<\/strong><\/p>\n<div class=\"sc-card-starred-link\">\r\n  <div class=\"sc-card-starred-link__body\">\r\n    <div class=\"sc-card-starred-link__row clearfix\">\r\n      <div class=\"sc-card-starred-link__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-starred-link__img\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2018\/04\/google-play-pantallas-1024x576.jpg\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-starred-link__col-title\">\r\n        <p class=\"sc-card-starred-link__title\">How to detect fake apps in the Google Play Store in just 3 steps<\/p>\r\n        <a class=\"sc-card-starred-link__button\" href=\"https:\/\/en.softonic.com\/articles\/how-to-detect-fake-apps-in-the-google-play-store-in-just-3-steps\/\" target=\"_blank\" rel=\"noopener noreferrer sponsored\">Read now<\/a>\r\n      <\/div>\r\n    <\/div>\r\n    <a class=\"sc-card-starred-link__link\" href=\"https:\/\/en.softonic.com\/articles\/how-to-detect-fake-apps-in-the-google-play-store-in-just-3-steps\/\" target=\"_blank\" rel=\"noopener noreferrer sponsored\"><\/a>\r\n  <\/div>\r\n<\/div>\n<h2>238 apps with over 440 million downloads between them have shipped with an aggressive form of adware<\/h2>\n<p>Security research firm <a href=\"https:\/\/www.lookout.com\/uk\" target=\"_blank\" rel=\"noopener noreferrer\">Lookout<\/a> has released details of a new study its team has performed looking into apps on the Google Play Store. <a href=\"https:\/\/blog.lookout.com\/beitaplugin-adware\" target=\"_blank\" rel=\"noopener noreferrer\">The study\u2019s findings<\/a> show that a particularly nasty piece of adware called <strong>BeiTAd<\/strong> has been found in 238 apps on Google\u2019s app store. 237 of the apps were published by the aforementioned Cootek.<\/p>\n<figure id=\"attachment_141168\" aria-describedby=\"caption-attachment-141168\" style=\"width: 487px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-141168\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2021\/04\/an_infected_app_mxcilz.jpg\" alt=\"infected apps\" width=\"487\" height=\"512\" \/><figcaption id=\"caption-attachment-141168\" class=\"wp-caption-text\">One of the more popular infected apps<\/figcaption><\/figure>\n<p>BeiTAd is a rather invasive piece of adware as it propagates \u201cout of app\u201d ads. After the infected apps are downloaded, <strong>the plug-in lies dormant for up to a couple of weeks but then wakes to cause havoc on the victim\u2019s device.<\/strong> Basically, out-of-app ads start popping up all over the device, not just in the infected app, <strong>including places like the lock screen.<\/strong> Even worse, the plugin could trigger video ads to play while the phone is in sleep mode.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-141169 aligncenter\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2021\/04\/A_negative_review_cbrdfy.jpg\" alt=\"a bad review\" width=\"700\" height=\"237\" \/><\/p>\n<p>In the report, <a href=\"https:\/\/blog.lookout.com\/kristina-balaam\" target=\"_blank\" rel=\"noopener noreferrer\">Lookout researcher Kristina Balaam<\/a> points out just how bad this adware is, \u201cWhile out-of-app ads are not particularly novel, those served by this plugin <strong>render the phones nearly unusable.<\/strong> Users have reported being unable to answer calls or interact with other apps, due to the persistent and pervasive nature of the ads displayed.\u201d In many cases, the onset of ads has been so bad that they\u2019ve interrupted regular use of the device.<\/p>\n<figure id=\"attachment_141172\" aria-describedby=\"caption-attachment-141172\" style=\"width: 350px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-141172\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2021\/04\/apps_affected_by_BeiTAd_eqmsga.jpg\" alt=\"The list of infected apps\" width=\"350\" height=\"309\" \/><figcaption id=\"caption-attachment-141172\" class=\"wp-caption-text\">The list goes on. <a href=\"https:\/\/blog.lookout.com\/beitaplugin-adware\" target=\"_blank\" rel=\"noopener noreferrer\">Click here<\/a> for full list of infected apps.<\/figcaption><\/figure>\n<p>The good news is that Lookout has shared its findings with Google and the internet giant has already taken action. All of the affected apps have either been removed, or updated to new versions that don\u2019t include the BeiTAd plugin. This means if you suspect you might have downloaded a Cootek plugin or you\u2019ve been experiencing problems like those described above, you should <strong>update your apps immediately.<\/strong><\/p>\n<p>Unfortunately, due to the large number of affected apps we can\u2019t list them all here. If, however, you want to <strong>check your apps against the list<\/strong>, <a href=\"https:\/\/blog.lookout.com\/beitaplugin-adware\" target=\"_blank\" rel=\"noopener noreferrer\">you\u2019ll find it here<\/a>.<\/p>\n<div class=\"sc-related-articles-white\">\r\n<p class=\"sc-related-articles-white__title\">Read more<\/p>\r\n  <div class=\"sc-related-articles-white__row\">\r\n    <a title=\"New scam spotted on the Google Play Store \u25ba\" href=\"https:\/\/en.softonic.com\/articles\/google-play-store-scam-app\">\r\n    <div class=\"sc-related-articles-white__article\">\r\n      <div class=\"sc-related-articles-white__image\">\r\n        <div style=\"background-image:url(https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2018\/08\/google-play-192.jpg)\"><\/div>\r\n      <\/div>\r\n      <div class=\"sc-related-articles-white__text\">\r\n        <p>New scam spotted on the Google Play Store \u25ba<\/p>\r\n      <\/div>\r\n    <\/div>\r\n    <\/a>\r\n    <a title=\"Security alert: new Netflix phishing scams \u25ba\" href=\"https:\/\/en.softonic.com\/articles\/security-alert-new-netflix-phishing-scams\">\r\n    <div class=\"sc-related-articles-white__article\">\r\n      <div class=\"sc-related-articles-white__image\">\r\n        <div style=\"background-image:url(https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2019\/02\/netflix-logo-192.jpg)\"><\/div>\r\n      <\/div>\r\n      <div class=\"sc-related-articles-white__text\">\r\n        <p>Security alert: new Netflix phishing scams \u25ba<\/p>\r\n      <\/div>\r\n    <\/div>\r\n    <\/a>\r\n  <\/div>\r\n  <div class=\"sc-related-articles-white__row\">\r\n    <a title=\"This ingenious phishing scam is targeting iPhone users \u25ba\" href=\"https:\/\/en.softonic.com\/articles\/iphone-phishing\">\r\n    <div class=\"sc-related-articles-white__article\">\r\n      <div class=\"sc-related-articles-white__image\">\r\n        <div style=\"background-image:url(https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2018\/10\/iphone-192.jpg)\"><\/div>\r\n      <\/div>\r\n      <div class=\"sc-related-articles-white__text\">\r\n        <p>This ingenious phishing scam is targeting iPhone users \u25ba<\/p>\r\n      <\/div>\r\n    <\/div>\r\n    <\/a>\r\n    <a title=\"New year, new scams: what to watch out for in 2019 \u25ba\" href=\"https:\/\/en.softonic.com\/articles\/online-scams-in-2019\">\r\n    <div class=\"sc-related-articles-white__article\">\r\n      <div class=\"sc-related-articles-white__image\">\r\n        <div style=\"background-image:url(https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2018\/12\/phishing-scam-hacker-malware-192.jpg)\"><\/div>\r\n      <\/div>\r\n      <div class=\"sc-related-articles-white__text\">\r\n        <p>New year, new scams: what to watch out for in 2019 \u25ba<\/p>\r\n      <\/div>\r\n    <\/div>\r\n    <\/a>\r\n  <\/div>\r\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>238 apps with over 440 million downloads between them have shipped with an aggressive form of adware.<\/p>\n","protected":false},"author":9073,"featured_media":114491,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[1015],"tags":[1082,2422,1068,2097,1027],"usertag":[839],"vertical":[],"content-category":[],"class_list":["post-141166","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-android","tag-app-subdomain-redirectiongoogle-play","tag-google","tag-play","tag-security","usertag-vpn"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/141166","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9073"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=141166"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/141166\/revisions"}],"predecessor-version":[{"id":325906,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/141166\/revisions\/325906"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/114491"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=141166"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=141166"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=141166"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=141166"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=141166"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=141166"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}