Judy malware spreads to 36.5 million Android devices

Judy is the biggest malware outbreak caused by app downloads

A new strain of malware dubbed 'Judy' has infected up to 36.5 million Android users, security researchers have found.

The malware campaign was found spreading through apps available on Google Play, Google's official app store, according to a blog post by Check Point. 

Judy, the auto-clicking adware which was found on 41 apps, used infected devices to generate large amounts of fraudulent clicks on advertisements, generating revenues for the perpetrators behind it. Among the apps included are; Fashion Judy: Snow Queen Style; Fashion Judy: Vampire style; Chef Judy: Character Lunch; and Fashion Judy: Frozen Princess. 

South Korean firm Kiniwini developed more than 40 of the apps, and put them on Google's Play Store under the name Enistudio.

Advertisement - Article continues below
Advertisement - Article continues below

"Some of the apps we discovered resided on Google Play for several years, but all were recently updated. It is unclear how long the malicious code existed inside the apps, hence the actual spread of the malware remains unknown," said the researchers. 

The apps have since been removed by Google but questions have been raised over the detection methods the tech giant employs to prevent malware from entering its app store.

"To bypass 'Bouncer', Google Play's [anti-malware] protection, the hackers created a seemingly benign bridgehead app, meant to establish a connection to the victim's device, and insert it into the app store," said Check Point's advisory.

It explained: "Once a user downloads a malicious app, it silently registers receivers which establish a connection with the C&C server. The server replies with the actual malicious payload, which includes JavaScript code, a user-agent string and URLs controlled by the malware author.

"The malware opens the URLs using the user agent that imitates a PC browser in a hidden web page and receives a redirection to another website. Once the targeted website is launched, the malware uses the JavaScript code to locate and click on banners from the Google ads infrastructure." 

Clicking on ads results in the malware author getting paid by the website developer. 

Advertisement - Article continues below

"It is important to note that the activity conducted by the malware is not borderline advertising, but definitely an illegitimate use of the users' mobile devices for generating fraudulent clicks, benefiting the attackers," Check Point's researchers said.

Featured Resources

What you need to know about migrating to SAP S/4HANA

Factors to assess how and when to begin migration

Download now

Your enterprise cloud solutions guide

Infrastructure designed to meet your company's IT needs for next-generation cloud applications

Download now

Testing for compliance just became easier

How you can use technology to ensure compliance in your organisation

Download now

Best practices for implementing security awareness training

How to develop a security awareness programme that will actually change behaviour

Download now



Hackers abuse LinkedIn DMs to plant malware

25 Feb 2019
Google Android

How to unroot Android

14 Jan 2019

Best smartphone 2019: Apple, Samsung and OnePlus duke it out

24 Dec 2019

Best free malware removal tools 2019

23 Dec 2019

Most Popular

data governance

Brexit security talks under threat after UK accused of illegally copying Schengen data

10 Jan 2020
web browser

What is HTTP error 503 and how do you fix it?

7 Jan 2020
data protection

Currys PC World parent firm hit with £500k fine over historic data breach

9 Jan 2020

Travelex disruption caused by devastating ransomware attack

8 Jan 2020