Google Play Has At Least 17 Trojan Apps That Can Steal Your Personal Information: Avast

Avast researchers initially discovered a total of 47 apps belonging to the Trojan family HiddenAds, though Google has reportedly removed 30 of them.

Advertisement
By Jagmeet Singh | Updated: 25 June 2020 19:05 IST
Highlights
  • Google Play is found to have Trojan apps from multiple developers
  • The Trojan campaign seems to have initially targeted users in India
  • Google Play has been used on bad actors in the past as well

Google Play is discovered to have apps that are a part of a Trojan campaign

Google Play is said to have at least 17 apps that are a part of a Trojan family called HiddenAds, if cybersecurity firm Avast is to be believed. The apps are found to be a part of a large HiddenAds campaign that initially targeted users in India and Southeast Asia. Avast researchers discovered that these apps are masked as games but are designed to display intrusive ads and can steal personal information of users. The researchers noticed that the Trojan apps have the ability to hide their icons from the affected devices and show timed ads that can't be skipped.

The team of Avast researchers initially discovered a total of 47 apps belonging to the Trojan family HiddenAds. Google, however, removed 30 of those apps upon receiving the report from the antivirus company.

Advertisement

“Once the user downloads the app, a timer starts within the app. The user is allowed to play the game for a set period of time, after which the timer triggers the hide icon feature of the app,” explained Avast Threat Operations Analyst Jakub Vávra, in a blog post. “Once the icon is hidden, the app starts to display ads throughout the device without needing further actions from the user.”

Some of the Trojan apps discovered by the Avast team are claimed to even open the browser to display intrusive ads to users. Since the apps hide their icon after a certain time limit, their victims aren't able to understand the origin of the ads they see on their devices. Having said that, the Trojan apps can still be uninstalled through the app manager of the device.

Advertisement

The Avast team found that each of the discovered apps has a separate developer listed on Google Play, with a generic email address. “Similarly, the Terms of Service are identical across the discovered apps, likely pointing to an organised campaign by one actor,” Vávra added.

In total, the apps carrying the Trojan HiddenAds have been downloaded more than 1.5 crore times. Some of the most downloaded titles that were live at the time of filing this story includes Skate Board - New, Find Hidden Differences, Spot Hidden Differences, Tony Shoot - NEW, and Stacking Guys.

Advertisement

The researchers found that the HiddenAds campaign through the apps were most prevalent in Brazil, India, and Turkey. However, it spread across other regions as well.

An email sent to Google didn't elicit a response at the time of publishing this story.

Advertisement

Not the first time
This is notably not the first time when Google Play is found to have the apps that have the potential to steal user information. In July last year, Avast detected apps that were installed a combined 1,30,000 times with the nature of stalking users. Bot mitigation company White Ops in its research paper published earlier this month also revealed that Google removed at least 38 apps from its Google Play store that infested Android devices with out-of-context advertisements.

As Vávra mentioned in a statement posted on GamesIndustry.biz that it is indeed difficult for Google to prevent adware campaigns as there are single developers for each app. “Campaigns like HiddenAds may slip into the Play Store through obfuscating their true purpose or slowly introducing malicious features once already downloaded by users,” analyst said.

Steps to stay away from such apps
Avast has advised users to carefully look for the permissions of the app requests before installing them on their devices. It is also important to take some time and read the privacy policy and terms and conditions of the apps being installed. Furthermore, users are recommended to reconsider downloading the app that has received a large number of negative reviews.


In 2020, will WhatsApp get the killer feature that every Indian is waiting for? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts or RSS, download the episode, or just hit the play button below.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. OTT Releases This Week (April 13 - April 19): Toaster, Matka King, Assi, and More
  2. Vivo X300 Ultra, Vivo X300 FE Confirmed to Launch in India Soon
  3. DJI Osmo Pocket 4 Debuts With 1-inch CMOS Sensor, Improved Stabilisation
  4. Anthropic's New Claude Opus 4.7 Model Is Still Less Capable Than Claude Mythos
  5. Apple Marketing Chief for Watch, AirPods, Home and Health Retires
  6. Intel Launches Core Series 3 Processors With Up to 40 TOPS AI Compute
  7. OnePlus Nord CE 6 Lite Appears on Geekbench With This MediaTek Chip
  8. Oppo Find X10 Key Specifications Leak as Find X9 Ultra Launch Nears
  1. Bitcoin Holds Near $74,600, Ethereum Trades Around $2,300 as ETF Flows Remain Inconsistent
  2. Pochamma Out on OTT: Know When and Where to Stream This Original Series Online
  3. Amazfit Cheetah 2 Pro Launched With 1.32-Inch AMOLED Screen, Up to 20-Day Battery Life: Price, Features
  4. Vivo X300 Ultra and Vivo X300 FE India Launch and Design Teased: Expected Specifications, Features
  5. Samsung Galaxy S27 Series Tipped to Debut With UFS 5.0 Storage, But Only Select Models Might Get Upgraded
  6. Anthropic Releases Claude Opus 4.7 AI Model, Calls It Less Advanced Than Claude Mythos
  7. 4A Games Reveal Metro 2039 With New Protagonist and the Series' Darkest Story Yet; Launch Set for Winter 2026
  8. Ala Chere Seetha Ramuni Chentaku Now Streaming Online: Where to Watch, Plot, Cast, and More
  9. OnePlus Employees in Europe Preparing to Leave as Firm Reviews Regional Roadmap: Report
  10. Google Chrome Gets AI Mode Update With Side-by-Side Browsing, Contextual Search Tools
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.