Over 60,000 Android apps disguised as legitimate applications were found to be secretly installing adware on mobile devices and remained undetected for the past six months.
The cybersecurity firm Bitdefender which found this, detected the malicious apps using an anomaly detection feature added to its Bitdefender Mobile Security software last month.
As of now, Bitdefender has discovered 60,000 completely different apps carrying the adware and they expect to find more such in the wild.
The campaign which is believed to have started in October 2022 is being distributed as fake security software, game cracks, cheats, VPN software, Netflix, and utility apps on third-party sites.
The malware campaign mainly targets users in the United States, followed by South Korea, Brazil, Germany, the United Kingdom, and France.
The malicious apps are not hosted on Google Play but on third-party websites in Google Search that push APKs, Android packages that allow you to manually install mobile apps.
When the user visits the sites, they will either be redirected to websites showing advertisements or prompted to download the searched-for app. The download sites are created to distribute the malicious Android apps as an APK which when installed, infect the Android devices with adware.
When the app is installed, it does not configure itself to run automatically. Instead, it relies on the normal Android app installation flow, which prompts users to ‘Open’ an app after it is installed.
The apps also do not have an icon and have a UTF-8 character in the app’s label, making it harder to spot. If a user does not start the app after it’s installed, it likely won’t be launched after.
If launched, the app will display an error message stating that the “Application is unavailable in your region. Tap OK to uninstall.”
However, the app is not uninstalled but simply sleeps for two hours before registering two ‘intents’ that cause the app to launch when the device is booted or when the device is unlocked.
When launched, the app will reach out to the attackers’ servers and retrieve advertisement URLs to be displayed in the mobile browser or as a full-screen WebView ad.
The malicious apps are currently only used to display advertisements; but it is possible for the threat actors to easily swap out the adware URLs for more malicious websites.
It is always better to install your Android apps from the official Android store even though Google Play has its share of malicious apps. It is also strongly advised not to install any Android apps from third-party sites.

















Comments