Google Play Removes 42 Malicious Apps With 8 Million Collective Downloads

Students at a Vietnamese university may be behind the malicious adware apps.

Advertisement
By Indo-Asian News Service | Updated: 25 October 2019 14:32 IST
Highlights
  • Security researchers have detected a massive year-long adware campaign
  • The apps were installed on users' Android devices eight million times
  • We reported the apps to the Google security team: researchers

Photo Credit: ESET

Security researchers have detected a massive year-long adware campaign where the involved apps were installed on users' Android devices eight million times from Google Play alone. Slovak internet security company ESET identified 42 apps on Google Play as belonging to the campaign, which had been running since July 2018. Of those, 21 were still available at the time of discovery.

"We reported the apps to the Google security team and they were swiftly removed. However, the apps are still available in third-party app stores," said the researchers in a statement on Thursday.

Once launched, the "Ashas" adware family app sent "home" key data about the affected device: device type, OS version, language, number of installed apps, free storage space, battery status, whether the device is rooted and Developer mode enabled, and whether Facebook and FB Messenger are installed.

Advertisement

"The app receives configuration data from the command and control server (C&C) server, needed for displaying ads, and for stealth and resilience," said security researcher Lukas Stefanko.

Advertisement

Once a user installed an adware-infected app, the app will show full-screen ads on the device's display at intervals.

First, the malicious app tries to determine whether it is being tested by the Google Play security mechanism.

Advertisement

After dodging Google servers, the malicious app can set a custom delay between displaying ads. Based on the server response, the app can also hide its icon and create a shortcut instead.

"If a typical user tries to get rid of the malicious app, chances are that only the shortcut ends up getting removed. The app then continues to run in the background without the user's knowledge. This stealth technique has been gaining popularity among adware-related threats distributed via Google Play," the researchers noted.

Advertisement

According to the team, students at a Vietnamese university may be behind the malicious adware app.

"Due to poor privacy practices on the part of our culprit's university, we now know his date of birth, we know that he was a student and what university he attended. We retrieved his University ID; a quick googling showed some of his exam grades," said researchers.

"The malicious developer also has apps in Apple App Store. Some of them are iOS versions of the ones removed from Google Play, but none contain adware functionality," said Stefanko.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Google Play, Android
Advertisement

Related Stories

Popular Mobile Brands
  1. Motorola Edge 70 Launched With Snapdragon 7 Gen 4 SoC, Slim 5.99mm Profile
  2. Lava Agni 4 Price Range, Features Leaked; Will Launch in These Colourways
  3. Samsung Galaxy S26 Ultra Spotted in Leaked Renders With Rounder Corners
  4. Moto G67 Power 5G Launched in India With 7,000mAh Battery: See Price
  5. Realme UI 7.0 Launched With Light Glass Design, AI Features
  6. Moto G Play (2026), Moto G (2026) With Dimensity 6300 SoC Launched
  7. Researchers Unveil How Atomic Entanglement Enhances Light Bursts
  8. Apple's Low-Cost MacBook Launch Timeline, Price Leaked Ahead of Debut
  9. OnePlus Ace 6 Pro Max Configurations Leaked; May Feature Up to 16GB of RAM
  1. Realme Will Try to Absorb Increased Cost of Components Ahead of Upcoming Product Launches, Executive Says
  2. Motorola Edge 70 Launched With Snapdragon 7 Gen 4 Chipset, Slim 5.99mm Profile: Price, Specifications
  3. Researchers Unveil How Atomic Entanglement Enhances Light Bursts
  4. Lava Agni 4 Confirmed to Launch in Two Colourways; Tipster Leaks Price Range, Key Features
  5. Google Proposes Play Store Reforms in Settlement With Fortnite Maker Epic Games
  6. Scientists Recreate Cosmic ‘Fireballs’ in Lab to Solve Mystery of Missing Gamma Rays
  7. Realme UI 7.0 Launched With Light Glass Design, AI Notify Brief and AI Gaming Coach: See Eligible Phones, Beta Release Schedule
  8. iOS 26.2 Beta 1 Rolled Out to Developers With Enhanced Safety Alerts, Reminder Alarms
  9. Samsung Galaxy S26 Ultra Spotted in Leaked Design Renders That Hint at Rounder Corners
  10. Call of Duty: Black Ops 7 PC Specifications, Preloading Times Revealed; Activision Confirms Handheld Support
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.