Google Removes 38 Adware-Infested Apps From Google Play: White Ops

White Ops’ research claims that these Android apps had over 20 million downloads.

Advertisement
By Abhik Sengupta | Updated: 11 June 2020 19:10 IST
Highlights
  • Apps mainly displayed out-of-context ads, and served no purpose
  • Some apps even made it difficult for users to uninstall them
  • The apps are speculated to be developed by the same developers

Most of these apps on Google Play store focused on beauty features

Google has removed 38 apps from its Google Play store that infested Android smartphones with out-of-context advertisements. According to a research paper, these apps focused on beauty-related features (mostly for taking selfies); however, they served no legitimate purpose and were only intended for displaying malicious ads. It is also noted that the fraudulent apps redirected users to "out-of-context URLs" and in some cases, made it nearly "impossible" for users to delete them. The research paper claims that these apps had amassed more than 20 million downloads.

The findings were published in a research paper by Bot mitigation company White Ops and were reported by ZDNet. The authors of the research paper claim that the all apps on Google Play store were developed by the same group of developers.

Advertisement

How did the malicious apps on Google Play function?

The research points out that the first batch of these apps (21 out of 38) appeared on Google Play in January 2019 and was focused on taking selfies or adding filters to users' photos. But those were quickly removed from the Google Play store after their malware-like behaviour was detected.

"But even with an average of less than three weeks of time on the Play Store, the apps found an audience: the average number of installs for the apps we analysed was 565,833," the research reads.

Advertisement

By September 2019, the developers had changed their tactics and published a batch of 15 apps that had a much slower removal rate. In November 2019, two new apps namely, Rose Photo Editor & Selfie Beauty Camera and Pinut Selife Beauty Camera & Photo Editor were updated with "most of the fraudulent code," to avoid detection, the paper indicated.

How did the apps avoid detection?

The White Ops paper notes that to avoid the malicious ad-bombarding code from being detected, most of these apps used "packers." These packers are hidden in the APK in the form of extra DEX files.

Advertisement

"The bad actor(s) behind this threat tried several packers in the apps, which clearly tells us of their sophistication, resources available, and determination," the research paper reads.

"Historically, packing binaries is a common technique malware developers use to avoid being detected by security software like antivirus. Packed files in Android are not new and can't be assumed to be malicious, as some developers use packing to protect their intellectual property and try to avoid piracy," the paper added.

Advertisement

The second method of avoiding detection comprised using Arabic characters in various places of the apps' source code. This particular methodology of obfuscation essentially helps reducing readability for people not familiar with Arabic, therefore, avoiding further detection.

What's next

As mentioned, these apps displayed out-of-context ads and in some cases, they removed app icons that made it difficult for users to uninstall the app from their Android devices. Although Google has removed these 38 apps from the app store, it is likely that they still are installed on several devices.

You can find the full list of app removed from the Google Play store on the researcher's website.


Which is the bestselling Vivo smartphone in India? Why has Vivo not been making premium phones? We interviewed Vivo's director of brand strategy Nipun Marya to find out, and to talk about the company's strategy in India going forward. We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts or RSS, download the episode, or just hit the play button below.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Moto G37 Power Review: Covers All the Bases and More
  2. Itel Aqua Launched in India With IP67 Rating, 1,200mAh Battery: See Price
  3. Find X9 Ultra Review: Oppo's Crown Jewel
  4. Xiaomi's Phones Now Let You Share Files With iPhone Models via AirDrop
  5. Asus Pad With MediaTek Dimensity 8300 Chip, 9,000mAh Battery Unveiled
  6. Huawei Nova 16, Nova 16z Debut With 50-Megapixel Camera at This Price
  7. iPhone 17 Won't Start After Battery Runs Out? Apple Says iOS 26.5.1 Fixes It
  8. Apple Brings New Wallpaper, Apple Music Playlist Ahead of WWDC 2026
  1. Asus Zenbook 14, Vivobook S14, Vivobook S16, Vivobook S14 Flip and Vivobook S16 Flip Launched at Computex 2026
  2. Asus Pad With MediaTek Dimensity 8300 Chip, 9,000mAh Battery Unveiled at Computex 2026
  3. Amazon Music to Play ‘Limited Ads’ for Prime Members in India as Firm Offers Unlimited Plan With Ad-Free Music Streaming
  4. Apple Rolls Out iOS 26.5.1 Update With Fix for Charging Bug Affecting iPhone Air, iPhone 17 Models
  5. Asus ROG Xbox Ally X20 With Larger 7.4-Inch OLED Display Unveiled at Computex 2026
  6. ViewSonic IN05 Series ViewBoard 4K Displays Launched in India With Android 16, AI Features
  7. Asus ProArt P16, ProArt P14 and New ProArt Mini PC With Nvidia RTX Spark Unveiled at Computex 2026
  8. Computex 2026: MSI Prestige N16 Flip AI+ Announced as Company's First Nvidia RTX Spark-Powered Laptop
  9. Apple Releases New ‘Glow All Out’ Wallpaper, Apple Music Playlist Hinting at Next Week’s WWDC 2026 Theme
  10. Xiaomi's HyperOS 3 Adds AirDrop Support on Select Models With Ability to Share Files With Apple Devices
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.