Google Play Removes Malware That Were Already Downloaded Half a Million Times

Google has removed a total of 13 supposed racing games from the Google Play store following the discovery that all of them installed malware onto devices that downloaded them.

Malware and security researcher Lukas Stefanko tweeted about the problem a week ago. Apparently, 13 of these apps were all created by the same developer named Luiz O. Pinto. Prior to being removed from the store, the games managed to gain over 560,000 installs, with two apps making their way up onto Google Play’s trending apps list.

The apps in question basically disguised themselves as games, but would repeatedly crash after starting up. This wasn’t a technical error, as the apps were really downloading a different program that would install malware on the user’s device and delete the app icon on the phone’s home screen. It isn’t clear what the malware does to the phone, but it’s a dubious activity that has had Google scrambling to take them down.

Lukas Stefanko also provided a demonstration of how these apps worked:

Google has confirmed that the apps are now gone from the Google Play store. However, the damage has already been done, with more than half a million users turned victim to this lapse in security.

This isn’t the first time Google has had to deal with rampant malware on its mobile store. Last year, an auto-clicking adware called Judy was discovered on 41 apps and said to have affected between 8.5 million and 36.5 million Android devices. Also, another botnet malware called FalseGuide had reportedly infected millions of Android devices via Google Play.

In last year alone, Google pulled down more than 700,000 malicious apps from the Play Store. Despite continuous efforts in improving security, a significant amount of bad apples still get through, which reflects badly on whether the company can keep its consumers safe.

(Source: TechCrunch)

Share this post:

Comment what you think!