Google Play Store malware targets porn ads at millions of kids

The malicious code is hidden inside 60 game apps downloaded 'millions of times'

A fresh malware found on theGoogle Play Storedisplays pornographic ads and tries to trick users into installing fake security apps'.

To make matters even worse, the malicious code is said to hide itself inside around 60 game apps, many of which are intended to be used by children, and which have been downloaded between 3 million and 7 million times, the researchers who discovered it said.

Those researchers, fromsecurity firm Check Point Research, said the malware - dubbed AdultSwine' - also induces users to register to premium services at their own expense.

Here's how it works: First, the malicious code contacts its Command and Control (C&C) server to report the successful installation, sends data about the infected device and then receives the configurations, which determine its course of operation.

"These configurations instruct it on whether to hide its icon, which ads to display, over which apps and on what terms," Check Point's researchers explained.

"The malicious code then verifies certain conditions regarding the device's status and checks which app is currently running on screen. Once all its terms are met, it begins to display the illegitimate ads outside of the app's context."

If it is embedded inside a web browser app, the ads will be displayed inside that browser, and if not, they will be displayed inside a designated web view, Check Point said.

"As for the ads being displayed, they come from two main sources; the first is that of the main ad providers, which forbid such illegitimate display of their ads. The second is the malicious code's own ad library, which contains ads of an offensive nature, including pornographic ads."

All of these Check Point highlighted - are displayed to children while playing the game that the app is masquerading as.

"The malicious code can use [also] its infrastructure to broaden its goals to other purposes, such as credential theft," explained Check Point. "Once the malicious app is installed on the device, it waits for a boot to occur or for a user to unlock his screen, upon which it initiates its malicious activity."

"We've removed the apps from Play, disabled the developers' accounts, and will continue to show strong warnings to anyone that has installed them," a Google spokesperson toldReuters.

Featured Resources

How to scale your organisation in the cloud

How to overcome common scaling challenges and choose the right scalable cloud service

Download now

The people factor: A critical ingredient for intelligent communications

How to improve communication within your business

Download now

Future of video conferencing

Optimising video conferencing features to achieve business goals

Download now

Improving cyber security for remote working

13 recommendations for security from any location

Download now

Recommended

MacBook users warned against EvilQuest ransomware
ransomware

MacBook users warned against EvilQuest ransomware

19 Feb 2021
Agent Tesla malware evades security controls to infect systems
malware

Agent Tesla malware evades security controls to infect systems

3 Feb 2021
Your essential guide to internet security
Security

Your essential guide to internet security

27 Jan 2021
Android malware vendor teams with marketer to promote new malware
malware

Android malware vendor teams with marketer to promote new malware

11 Jan 2021

Most Popular

How to connect one, two or more monitors to your laptop
Laptops

How to connect one, two or more monitors to your laptop

25 Feb 2021
How to find RAM speed, size and type
Laptops

How to find RAM speed, size and type

26 Feb 2021
Ransomware operators are exploiting VMware ESXi flaws
ransomware

Ransomware operators are exploiting VMware ESXi flaws

1 Mar 2021