Tech

19 Million Installs Later: Google Play Removes Dozens of Malicious Android Apps


The Google Play Store, often seen as the safest gateway for Android apps, has once again been infiltrated by malicious software. Security researchers at Zscaler ThreatLabs recently uncovered a wave of harmful apps that together had amassed more than 19 million downloads before Google intervened and removed them. This revelation is a sobering reminder of how persistent cybercriminals have become in exploiting the Android ecosystem.


The Scale of the Threat

In total, 77 malicious apps were identified and pulled from the Play Store. What’s striking is not just the number of apps but the variety of threats they carried. From aggressive adware to banking trojans, the apps used sophisticated techniques to remain hidden long enough to trick millions of unsuspecting users.

More than two-thirds of these apps carried adware designed to flood users with intrusive advertisements. Nearly 25% were infected with the notorious Joker malware, long known for signing victims up for premium subscriptions without consent and harvesting sensitive data.

A variant of Joker called Harly was also uncovered. Unlike older strains, Harly has become more elusive, embedding itself deeper within app code and using clever disguises to bypass Google’s automated scans.


The Rise of the Anatsa (Tea Bot) Trojan

Perhaps the most alarming discovery was the presence of Anatsa, also known as Tea Bot, a sophisticated banking trojan. This malware has rapidly evolved and now targets data from over 830 different banking and cryptocurrency apps worldwide—a sharp increase from the 650 it previously attacked.

Anatsa’s danger lies in how it disguises itself. Malicious actors packaged it inside apps that appeared harmless, such as “Document Reader – File Manager.” Once installed, the trojan unpacked its harmful payload using hidden JSON files and advanced obfuscation methods. Techniques included:

  • Malformed APK structures to confuse scanners.
  • DES-based encryption to hide code strings.
  • On-demand payload downloads that activate after initial installation.

The malware then exploited Android’s Accessibility permissions, giving it near-total control of the device. With these permissions, it could log keystrokes, overlay fake login pages for phishing, and even redirect users to malicious sites.

Alarmingly, Anatsa has now expanded its focus to new regions, including Germany and South Korea, further widening its global footprint.


Google’s Crackdown on Malicious Apps

Once the threat was confirmed, Google quickly removed all 77 apps from its Play Store. This was not the first such purge. In 2024 alone, Google reported blocking 2.36 million policy-violating apps and banning over 158,000 developer accounts tied to malicious activity.

Despite these efforts, the scale of the Android ecosystem makes complete eradication difficult. Cybercriminals often adapt faster than detection systems, using techniques like code obfuscation, delayed payload activation, and hidden app icons to slip through Google’s defenses.

Recently, another large-scale ad fraud operation called IconAds was dismantled, involving 352 Android apps that collectively generated 1.2 billion ad requests per day. This campaign highlighted how malware is not just about stealing data—it can also be about exploiting ad systems for revenue at the user’s expense.


Protecting Yourself as an Android User

While Google is investing heavily in security, users also play a crucial role in safeguarding their devices. Here are a few key steps every Android owner should take:

  1. Enable Play Protect
    • Open the Google Play Store → Tap on your profile → Select Play Protect → Ensure “Scan apps with Play Protect” is turned on.
    • This provides real-time threat detection and can warn you about suspicious apps.
  2. Download Only From Trusted Developers
    • Check developer names, app histories, and reviews before installing.
    • Avoid apps with poor ratings, generic branding, or excessive permission requests.
  3. Limit Accessibility Permissions
    • Unless absolutely necessary, do not grant apps access to Android’s Accessibility services, as these permissions can be exploited by malware like Anatsa.
  4. Be Wary of Utility Apps
    • Cybercriminals often disguise malware inside simple apps such as file managers, calculators, or document readers.
  5. Remove Suspicious Apps Immediately
    • If your phone begins behaving oddly—sluggish performance, excessive ads, or unexplained subscriptions—uninstall recent apps and run a security scan.

The removal of these malicious apps is both a victory and a warning. On one hand, it shows that Google’s security teams and independent researchers remain vigilant in combating cybercriminals. On the other, it demonstrates that no app marketplace is completely immune to infiltration.

As malware like Joker, Harly, and Anatsa continue to evolve, Android users must remain alert. By combining Google’s built-in protections with smart user habits, individuals can significantly reduce their risk of falling victim to these stealthy threats.

In the ever-escalating battle between cybersecurity defenders and malicious actors, vigilance remains the most powerful weapon.


Click to rate this post!
[Total: 0 Average: 0]

About The Author

Leave a Reply

Discover more from NEWS NEST

Subscribe now to keep reading and get access to the full archive.

Continue reading

Verified by MonsterInsights