Android Apps That Are Ad Fraud

It’s common to find out that apps from the Google Play Store are sneaking past protection and collecting user data without permission but a new investigation revealed disturbing behaviour among a particular set of apps. A Buzzfeed report showed that several Android apps which happen to be among the most downloaded on the Google Play Store may be sharing the data they collect with the Chinese government. A selfie app has been downloaded more than 50 million times and the apps are committing large-scale ad fraud and abuse of user permissions.

The apps include Total Cleaner, Smart Cooler, Selfie Camera, WaWaYaYa, AIO Flashlight and Samsung TV Remote Control. The main problem here seems to stem from developers exploiting the Google Play Store’s rules and procedures to hide who they are and to offer up apps that aggressively abuse user permissions and commit ad fraud. Among the collection of apps, it is found that what fit this bill are the TV remote app that says it “might” use the microphone in your phone to record sounds while you watch TV, a Chinese-language app for kids that sends personal data to servers in China, and a flashlight app that you’d think would be pretty basic but nevertheless asks for dozens of sketchy permissions.

A Lifehacker investigation notes the apps in question have been downloaded close to a combined 100 million times, thanks in part to the developers hiding their country of origin and who owns the app. One of the things that should have been a giveaway with apps like these, though, is that they asked users for permission to use everything from a user’s location data to their phone sensors as well as personal contact information.

Consider one of the apps we mentioned above. As Buzzfeed notes, the Selfie Camera app had been downloaded more than 50 million times from the Google Play store, and it also maintained a 4.5-star rating after thousands of reviews. In 2017, the report continues, Google highlighted it as one of the most popular new apps in the UK — all of which, you’d think, would seem to give it a stamp of approval.

The app, however, was found to have code that fraudulently clicks on ads without the user realizing it, something that gobbles up data and drains the phone battery (Google banned the app, and several others, after Buzzfeed report was published).

To keep yourself safe, Lifehacker offers the reminder to be on the lookout for apps that include a high number of permissions, and especially permissions that seem weird for the app to have in the first place. The AIO Flashlight app we mentioned above, for example, asked for almost three dozen permissions, when a simple flashlight app would only need probably a fraction of that number to operate.

Share this post:

Comment what you think!