Original Article Text

Click to Toggle View

Over 200 malicious apps on Google Play downloaded millions of times. Google Play, the official store for Android, distributed over a period of one year more than 200 malicious applications, which cumulatively counted nearly eight million downloads. The data was collected between June 2023 and April 2024 by threat intelligence researchers at Zscaler, who identified and analyzed malware families both on Google Play and other distribution platforms. The most common threats the researchers discovered on the official Android app store include: Earlier this year in May, the same researchers alerted of more than 90 malicious apps on Google Play, with a download count of 5.5 million. Although Google has security mechanisms to detect malicious applications, threat actors still have some tricks to bypass the verification process. In a report last year, the Google Cloud security team described the 'versioning', a method that delivers malware through application updates or by loading it from servers controlled by the attacker. Regardless of the method used to deliver malware through Google Play, some campaigns are more successful than others. While Zscaler's report focused on Android malware that is more common, other researchers discovered campaigns that also used Google Play to distribute malware to millions. In one case, the Necro malware loader for Android was downloaded 11 million times through just two apps published on the official store. In another case, the Goldoson Android malware was detected in 60 legitimate apps that cumulatively had 100 million downloads. Last year, the SpyLoan was found in apps on Google Play that had been downloaded more than 12 million times. Nearly half of the malicious apps that Zscaler ThreatLabz discovered were published on Google Play under tools, personalization, photography, productivity, and lifestyle categories. In terms of malware blocks attempted this year, Zscaler reports that the trend shows an overall decline, as measured by blocked transactions. On average, ThreatLabz recorded 1.7 million blocks per month, with 20 million blocks recorded throughout the analysis period, the most common threats being Vultur, Hydra, Ermac, Anatsa, Coper, and Nexus. Zscaler's mobile threats report also shows a significant increase of spyware infections, driven primarily by SpyLoan, SpinOK, and SpyNote families. In the past year, the company registered 232,000 blocks of spyware activity. The most targeted countries by mobile malware in the past year were India and the United States, followed by Canada, South Africa, and the Netherlands. According to the report, mobile malware targeted mostly the education sector, where the amount of blocked transactions increased by 136.8%. The services sector recorded a 40.9% increase, and chemicals and mining a 24% increase. All other sectors showed a general decline. To minimize the chances of getting infected by malware from Google Play, users are advised to read reviews from others to see what problems have been reported and check the application publisher. Users should also check the permissions requested at installation time and abort the process if the app requires permissions that do not fit its activity.

Daily Brief Summary

MALWARE // Over 200 Malicious Apps Found on Google Play, Millions Affected

Over 200 malicious applications were identified on Google Play between June 2023 and April 2024, accounting for nearly eight million downloads.

Zscaler, a threat intelligence research firm, reported these findings, highlighting continued challenges in Android app security.

Malware variants like Necro and Goldoson were distributed through Google Play, affecting millions of users with downloads reaching up to 100 million for some apps.

The Zscaler ThreatLabz also detected a significant spike in spyware infections, with notable malware families including SpyLoan, SpinOK, and SpyNote.

Most malware-infected apps fell under categories such as tools, personalization, and productivity, with several being able to bypass Google's security measures.

India and the United States were the countries most affected by mobile malware, especially targeting the education and services sectors.

Zscaler's analysis period ended with an average of 1.7 million malware blocks per month, showing a descending trend in malware activity.

The report advises users to carefully review app permissions and check user reviews to mitigate risks of downloading malicious apps on Google Play.