New Android Adware Can Download, Install Apps Without Permission: Report

Advertisement
By Manish Singh | Updated: 23 November 2015 16:20 IST

An adware family has been found to be capable of automatically installing apps on Android devices, targeting a flaw in the way Google's mobile operating system handles accessibility features, a report has found. The adware reportedly installs apps even if a user has cancelled the installation.

Dubbed Shedun, the Android malware has been found to download unwanted apps as well as exploit a vulnerability in Android that makes it possible for the malware to find alternative ways to interact with the infected device, security firm Lookout reports. Shedun is one of the three adware programs Lookout had reported earlier this month. Shedun, Kemoge, and Shaunet are part of the same Android adware family that root infected device to install malicious apps and serve ads. These adware programs have reportedly affected more than 20,000 popular Android apps via unofficial channels. Their official Google Play counterparts were not affected, the firm had added.

But it appears Shedun is capable of doing much more than initially anticipated. The adware attempts to fool users into enabling accessibility features because they are allegedly needed by a utility to help stop inactive apps. To gain a user's trust, the app notes that the notification is a "standard privacy risk reminder."

Advertisement

"By gaining the permission to use the accessibility service, Shedun is able to read the text that appears on screen, determine if an application installation prompt is shown, scroll through the permission list, and finally, press the install button without any physical interaction from the user," wrote Michael Bentley, head of research and response at Lookout in a blog post.

Advertisement

Once a user enables the accessibility feature, Shedun displays a pop-up ad for an app. This is where it gets trickier. Even if a user closes the pop-up, the app is downloaded and installed. This happens because any app with access to accessibility features can determine the text on the screen and scroll through the permissions list and initiate the installation without any interaction from the user. The culprits behind it have likely partnered with clients to guarantee them 100 percent ad display and installation.

"Shedun likely uses this technique in order to increase its revenue by guaranteeing the installation and execution of advertised applications. After all, marketing companies pay more money for advertising campaigns where the user actually interacts with the application after downloading it instead of simply downloading and forgetting about it," Lookout explained in a blog post.

Advertisement

The security firm expects to see more such malware in future. The state of security on Google's Android platform continues to remain alarming.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Best Diwali 2025 Wishes, Quotes, and Facebook Statuses to Share
  1. Mysterious Asteroid Impact Found in Australia, But the Crater is Missing
  2. Thanal Comes to OTT: Everything You Need to Know About This Tamil Action Thriller
  3. Madam Sengupta Is Now Streaming: Know Where to Watch This Bangla Crime Thriller
  4. Ryugu Samples Reveal Ancient Water Flow on Asteroid for a Billion Years
  5. Scientists Create Most Detailed Radio Map of Early Universe Using MWA
  6. Mayor of Kingstown Season 4 OTT Release: Know When, Where to Watch Jeremy Renner's Crime Drama
  7. Our Fault Is Streaming Now: Know All About This Gabriel Guevara and Nicole Wallace Starrer
  8. The Conjuring: Last Rites Is Now Streaming Online: Know Where to Watch the Latest Installment from the Horror Franchise
  9. Delhi Crime Season 3 OTT Release: Know When to Watch This Shefali Shah Thriller Series
  10. Vast Space to Launch Haven-1, the World’s First Private Space Station in 2026
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.