Breaking News

Razer Hammerhead V3 Wired Earbuds Bring Premium Sound and Comfort to Every Device ASUS ROG Unveils ROG Astral GeForce RTX 5080 Dhahab CORE OC Edition Transcend Introduces 8TB Industrial SSD with Power Loss Protection Viltrox announces AF 85mm F1.4 Pro FE Portrait Lens TerraMaster D4 SSD Unveiled

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Icon-hiding Android Adware May Be Hiding On Your Phone

Icon-hiding Android Adware May Be Hiding On Your Phone

Smartphones Oct 13,2019 0

SophosLabs recently discovered 15 apps on Google’s Play Market that launch intrusive ads on mobile devices.

App developers have been embedding ad-code into their apps as a way to help defray the costs of development, but some developers simply use their apps as a borderline-abusive platform solely to launch ads on mobile devices.
They generate frequent, large, intrusive ads and literally hide their app icons in the launcher in order to make it difficult for you to find and remove them. Several of them go a step further by disguising themselves in the phone’s App settings page.

According to the Play Market pages for these apps, more than 1.3 million devices worldwide have installed at least one of them.

For example, the app free.calls.messages (Flash On Calls & Messages – aka Free Calls & Messages – shown below) engages in some clever trickery to prevent users from uninstalling the app.

When first launched, the app displays a message that says “This app is incompatible with your device!” You might think that the app has crashed, because, after this “crash,” the app opens the Play Store and navigates to the page for Google Maps, to mislead you into thinking that the ubiquitous Maps app is the cause of the problem. It is not. This is a ruse.

The app then hides its own icon so it doesn’t show up in the launcher’s app tray. Others in the list hide their icon, too: Some do this on the first launch, while others simply wait for a while after you install the app.

SophosLabs has also observed these apps pulling a different dirty trick: using one name and icon for the application (which is visible in the phone’s Apps settings page), and a different name and icon for the Main Activity (the running app window).

Nine out of the batch of 15 apps used deceptive application icons and names, most of which appeared to have been chosen because they might plausibly resemble an innocuous system app. (The app icon is still visible in the phone’s “gear” Settings menu, under Apps.)

By hiding their launcher icon, and using an application icon and name that resembles a system app, these apps make a convincing case to a casual observer that there’s nothing unusual installed on the phone.

Other apps make use of a library, called koolib, that installs a service to hide the icon after a predetermined time after the installation of the app.

The package names of the 15 apps are here:


Package Name  Installs Published
free.calls.messages 1,000,000+ Jan 2019
com.a.bluescanner 10,000+ May 2019
com.bb.image.editor 10,000+ May 2019
com.cc.image.editor 100,000+ June 2019
com.d.bluemagentascanner 10,000+ June 2019
com.doo.keeping 1,000+ May 2019
com.e.orangeredscanner 10,000+ July 2019
com.hz.audio 10,000+ June 2019
cos.mos.comprehensive 10,000+ April 2019
com.garbege.background.cutout 10,000+ July 2019
com.hanroom.cutbackground 50,000+ July 2019
com.jiajia.autocut.photo 100,000+ July 2019
com.jiakebull.picture.background 50,000+ July 2019
com.fruit.autocut.photo 10,000+ July 2019
com.huankuai.autocut.picture 10,000+ July 2019

Most of these apps were presented to the user as one kind of utility app or another. QR code readers, image editors, backup utilities, a phone finder, and most ironically. a utility ostensibly to scrub your phone of private data. The apps further disguised themselves using a name representing a harmless app, such as Google Play Store, Update, Back Up, or Time Zone Service. These names appear only in the phone’s settings.

All of these apps appeared during this calendar year. The oldest one among these, free.calls.messages, was published in January; Two months after it appeared, it had more than a million installs. Although these apps were uploaded to the market by different publisher accounts, many shared similar code structure, UI, package names, and behavior — too many for it to be considered a coincidence.

SophosLabs notified Google about these apps in July and they have been taken down.

The usual advice is do not to download trivial utility apps because they seem nifty and free—they’re free for a reason.

Tags: adwareandroid
Previous Post
Sophos Accepts $3.8 Billion Thoma Bravo's Take Over Offer
Next Post
Pixel 4 Series Detailed by Best Buy Canada

Related Posts

  • What’s new in Android 15, plus more updates

  • Connecting all things Android at MWC Barcelona

  • New features for businesses in Android 13

  • Lucky number Android 13: The latest features and updates

  • What’s beta than Android 13?

  • HLDS UD Station DVDRW (Preview)

  • Android Gets a New Keyboard for Typing Braille

  • New Opera for Android Offers More Data Savings, New Blockchain-browsing Features

Latest News

Razer Hammerhead V3 Wired Earbuds Bring Premium Sound and Comfort to Every Device
Consumer Electronics

Razer Hammerhead V3 Wired Earbuds Bring Premium Sound and Comfort to Every Device

ASUS ROG Unveils ROG Astral GeForce RTX 5080 Dhahab CORE OC Edition
GPUs

ASUS ROG Unveils ROG Astral GeForce RTX 5080 Dhahab CORE OC Edition

Transcend Introduces 8TB Industrial SSD with Power Loss Protection
Enterprise & IT

Transcend Introduces 8TB Industrial SSD with Power Loss Protection

Viltrox announces AF 85mm F1.4 Pro FE Portrait Lens
Cameras

Viltrox announces AF 85mm F1.4 Pro FE Portrait Lens

TerraMaster D4 SSD Unveiled
Enterprise & IT

TerraMaster D4 SSD Unveiled

Popular Reviews

be quiet! Light Loop 360mm

be quiet! Light Loop 360mm

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

Arctic Liquid Freezer III 420 - 360

Arctic Liquid Freezer III 420 - 360

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Soundpeats Pop Clip

Soundpeats Pop Clip

Crucial T705 2TB NVME White

Crucial T705 2TB NVME White

be quiet! Light Base 600 LX

be quiet! Light Base 600 LX

Noctua NH-D15 G2

Noctua NH-D15 G2

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed