CamScanner App With Over 100 Million Downloads Removed From Google Play Store Over Advertising Malware

The latest version of the CamScanner app lacked the malicious code in its resource files.

Advertisement
By Nadeem Sarwar | Updated: 30 August 2019 09:53 IST
Highlights
  • CamScanner app had over 100 million downloads on the Play Store
  • Some users had already spotted the malicious behaviour in CamScanner
  • The Trojan dropper module could be exploited for seeding ads

CamScanner is one of the most popular OCR apps out there for Android devices

Google Play Store has actively been weeding out apps for engaging in malicious behaviour ranging from ad fraud to seeding harmful code. But despite the vigilant approach, some malware loaded apps are spotted from time to time and are booted off the app repository after raking in a tonne of downloads. The latest app to get booted from the Play Store is CamScanner, an app that converts photos of documents into PDF format and is fairly popular among users. CamScanner was found to contain malware that could seed ads and prompt users into signing up for paid services.

As per the findings of Kaspersky researchers, CamScanner's recent versions shipped with an advertising library containing a malicious module. The malicious Trojan Dropper module, which has been identified as "Trojan-Dropper.AndroidOS.Necro.n”, has previously been observed in some Chinese apps as well. What this module did is it extracted and ran another malicious module from an encrypted file that is found in the app's resources.

Advertisement

The resource-linked module, which is also called a “dropped” module, was found to be a Trojan downloader that downloaded even more harmful modules. After that, it would depend on how a malicious party intends to exploit these modules. One possible use case scenario is that such a malicious module can show intrusive ads and sign up users for paid services. In the case of CamScanner, which has over 100 million downloads, some users came across the app's sketchy behaviour and posted reviews on the Play Store with the intention of preventing them from downloading CamScanner.

Once the Kaspersky researchers came across the advertising dropper in a recent version of the CamScanner app, they reported it and the app was promptly removed from the Play Store. It was also observed that the developers behind CamScanner got rid of the module in the latest version of the app. But since different phones might be running different versions of the app, some of which might contain the malicious code in its resource files, it is better to uninstall the app and download it again only when it is back on the Play Store after due verification.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Tecno Pova 8 to Launch in India With 8,000mAh Battery on This Day
  1. Sahara Meteorite May Be Fragment of a Lost Moon-Sized World, Study Suggests
  2. OpenAI Introduces Smarter ChatGPT Memory, Adds Dreaming Architecture
  3. Tecno Pova 8 India Launch Date Announced; Battery Size, Design, Colour Options Teased
  4. Samsung Reportedly Starts Internal Testing of Android 17-Based One UI 9 for Galaxy S25 Series
  5. Bybit Lists Western Union’s USDPT Stablecoin for Trading and Transfers
  6. Xiaomi Pad 8 Price Hiked in India: Here’s How Much It Costs Now
  7. Instagram Reels Influencing Nearly Half of Purchase Decisions in India, Meta Study Claims
  8. OnePlus Turbo 6X, OnePlus Turbo 6X Pro Colour Options, Price Range, Key Specifications Teased
  9. Sattendru Maarudhu Vaanilai Now Streaming Online: Where to Watch Jai’s Romantic Thriller Movie
  10. Asics GEL-Kayano 33 Launched in India With New Stability Tech, FluidSupport System
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.