Bitdefender IT security specialists have identified more than 30 dangerous Android apps downloaded more than two million times from the official Google Play Store. Once installed, the apps changed their name and icon so that victims could not easily identify them.

BitdefenderPhoto: Bitdefender

Researchers found that more than 30 apps behaved suspiciously after being installed by Android phone owners. The programs then changed their name and icon so that victims could not easily identify them. In addition, once installed, they required special permissions that allowed them to show ads in other open applications.

The discovery was made possible thanks to Bitdefender’s new technology, which analyzes the behavior of applications after they are installed.

The programs discovered during this campaign have accumulated millions of downloads, and the attackers have even developed new versions that allow them to be more effectively hidden on devices.

The main results of the study

  • Some apps downloaded from the official Google app store change their name, icon, and request special permissions to display aggressive ads.
  • The programs are difficult to identify after installation, but can be removed like any other program if found.
  • Although their primary goal is to serve ads, it is very likely that they are trying to mimic user interaction and click on ads themselves.
  • The same advertising system that attackers operate can be used to promote far more dangerous cyber threat campaigns.

Recommendations to users

  • Always be careful what permissions you give to apps you install, especially when they require permissions that have nothing to do with the app’s functionality (like access to your contact list even though they don’t need it).
  • Be especially careful with apps that require special permissions, such as accessibility.
  • Installing an app from official app stores doesn’t mean you’re safe. Use a security solution that can detect abnormal behavior and scans each application during installation or during the update process.
  • Be wary of apps with very low ratings from other users, especially if they are downloaded a lot.