15 Million Android Devices in India Infected by Newly Discovered Malware, Check Point Research Claims

Check Point Research has also revealed the top mobile malwares of June 2019.

Advertisement
By Gaurav Shukla | Updated: 11 July 2019 11:00 IST
Highlights
  • The malware was distributed via a popular third-party app store
  • It is similar in activity to CopyCat, Gooligan, HummingBad malwares
  • Agent Smith mainly targeted Arabic, Hindi, Indonesian speakers

Agent Smith replaces existing Android apps with malicious versions to show fake ads

A new smartphone malware called "Agent Smith" has been found that has infected 25 million devices worldwide, including 15 million in India, Check Point Research claims. The malware disguises itself as a Google-related application and then replaces installed applications with malicious versions of them using known Android vulnerabilities without users' knowledge. Separately, the cyber threat intelligence firm has released the top three malware that were active in June, including Lotoor, which is mainly used to display ads, but is also able to get access to sensitive user data.

As per a press note shared by Check Point Research, the Agent Smith malware uses its access to Android devices to show fake ads for financial gain, but given its access, it can also be used for more nefarious purposes. However, it is unclear if the malware has been doing so.

Advertisement

Check Point Research notes that the activity of Agent Smith resembles closely to how other malware like CopyCat, Gooligan, and HummingBad have operated in the recent years. All three malware campaigns have used infected devices to generate fake ad revenue to the tune of millions of dollars.

"Disguised as a Google-related application, the malware exploits known Android vulnerabilities and automatically replaces installed apps with malicious versions without users' knowledge or interaction," the note adds.

Advertisement

According to the research firm, Agent Smith originated on popular third-party app store 9Apps and has targeted mainly Arabic, Hindi, Indonesian, and Russian speakers. Majority of the malware's victims are based in India and neighbouring countries like Bangladesh and Pakistan. Check Point Research has also found infected devices in countries like Australia, UK, and USA.

Agent Smith infection world heat map
Photo Credit: Check Point

Advertisement

Some of the apps that have been used to infect devices via 9Apps store are Color Phone Flash – Call Screen Theme, Photo Projector, Rabbit Temple, Kiss Game : Touch Her Heart, and Girl Cloth XRay Scan Simulator.

This is not all, after the initial attack vector via 9Apps, the creators of Agent Smith moved to Google Play Store and were able to push at least 11 malware laden app in the store. The apps included Blockman Go: Free Realms & Mini Games by Blockman Go Studio, Cooking Witch by Ghost Rabbit, Ludo Master – New Ludo Game 2019 For Free by Hippo Lab, Angry Virus by A-Little Game, Bio Blast – Infinity Battle: Shoot virus! by Taplegend, Shooting Jet by Gaming Hippo, Gun Hero: Gunman Game for Free by Simplefreegames, Clash of Virus by BrainyCoolGuy, Star Range by A-little Game, Crazy Juicer – Hot Knife Hit Game & Juice Blast by Mint Games Global, and Sky Warriors: General Attack.

Advertisement

Android apps infected with Agent Smith in Google Play Store and 9Apps
Photo Credit: Check Point

Some of the infected Google Play apps and games had over 100,000 installs, however two of them managed to clock over 10 million installs. Google has removed all the apps from Google Play, however if you have any of these apps installed you are most likely infected by the Agent Smith malware. You can remove the malware-laden app by going to Settings > Apps and uninstalling the app.

Check Point Research says the Android users should only use trusted app stores to download apps as "third party app stores often lack the security measures required to block adware loaded apps." You can find technical analysis of the Agent Smith malware on Check Point blog.

In a separate press note, Check Point Research says Lotoor, Triada, and Ztorg topped the mobile malware list in June. While Lotoor's main function is displaying ads, Triada is a modular backdoor for Android, which grants super user privileges to downloaded malware. Ztorg, on the other hand, obtains escalated privileges on Android devices and install itself in the system directory. The malware is also able to install any other application on the device.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. iQOO Z11 Global Variant Visits Geekbench With a Different Snapdragon Chip
  2. Sony Issues Statement on New DRM Check for PS5, PS4 Games After Backlash
  3. Moto G87 Launched With 200-Megapixel Main Camera, 5,200mAh Battery
  4. These Four Xiaomi Phones Are Now Eligible to Get Android 17 Beta Updates
  5. Raakaasa OTT Release Date Confirmed: Know When and Where to Watch it Online
  6. You Can Now Turn Your PS5 Into a Linux Gaming PC
  7. House of the Dragon Season 3 OTT Release Date: When and Where to Watch it Online?
  8. Oppo Find X10 Leaks Hint at 165Hz Display, New Periscope Telephoto Camera
  9. Valathu Vashathe Kallan OTT Release: Where to Watch Malayalam Crime Thriller Online
  1. ULA Atlas V Launches 29 Amazon Kuiper Satellites in Return Mission
  2. Moto Buds 2 Plus Launched in India With Hi-Res Audio, Up to 40 Hours of Total Playback Time: Price, Features
  3. iQOO Z11 Global Variant Spotted on Geekbench Database With Snapdragon Chipset, Unlike Chinese Model
  4. Samsung Reportedly Plans to Launch Galaxy Book Models With Android-Based One UI 9 Soon
  5. PS5 Linux Loader Gets Public Release, Allowing Users to Run Steam and PC Games on Console
  6. Nine Crypto Scam Centres Targeting US Users Shut Down in Joint Operation Involving UAE, US and China
  7. Google Photos Unveils New AI-Powered Wardrobe Feature to Help You Decide What to Wear
  8. OpenAI CEO Sam Altman Teases GPT-5.5 Cyber AI Model Rollout, Could Take On Anthropic’s Claude Mythos
  9. Vivo X Fold 6 Leaks Hint at 200-Megapixel Camera, MediaTek Dimensity 9500 Chip and 7,000mAh Battery
  10. Raakaasa OTT Release Date Confirmed: Know When and Where to Watch it Online
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.