
Dubbed ‘Judy’, it’s an auto-clicking adware found in 41 apps developed by a Korean company named Kiniwini, registered on Google Play as ENISTUDIO corp. The company develops mobile apps for both Android and iOS platforms. There were other apps containing the malware, developed by other developers. It is unknown if there are any significant connections, or if developers borrowed a code knowingly or unknowingly.
The malicious apps appear as casual cooking and fashion games under the “Judy” brand, a name borrowed for the malware itself. The malware would be downloaded through a non Google based server after the app has been downloaded to the victim’s device. The code would then use the infected phone to click on Google ads, generating fraudulent revenue for the attacker.
The malware was discovered and detailed by Checkpoint security, with apps recording between 4.5 million to 18.5 million downloads. Some of the apps has been on the store for several years, with recent updates. As the malware has only been recently discovered, researchers currently do not know how long the malicious code has existed in the apps, making ti difficult to predict an actual spread of the malware.
According to Checkpoint, the oldest app was last updated April 2016 – meaning the code had hid in the Play store for over a year without being detected. Check Point has since notified Google and the apps have now been removed for the Play store.
Checkpoint wrote there were previous cases of apps carrying malware, noting that high reputation apps does not necessarily indicate that the app is safe for use. “Hackers can hide their apps’ real intentions or even manipulate users into leaving positive ratings, in some cases unknowingly. Users cannot rely on the official app stores for their safety, and should implement advanced security protections capable of detecting and blocking zero-day mobile malware.” Checkpoint wrote.



