Breaking News

Synology Unveils DiskStation DS225 Plus New PS5 system update beta previews DualSense wireless controller pairing across multiple devices EnGenius Multi-Gigabit Switch Delivers 2.5G Performance with 90W PoE Viltrox’s AF 90mm F3.5 Lens for the DJI Inspire 3 EnGenius Announces Affordable ECW520 Access Point

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

New Adware "BeiTaAd" Found Within Popular Applications in Google Play

New Adware "BeiTaAd" Found Within Popular Applications in Google Play

Smartphones Jun 5,2019 0

Over the past year, roughly 440 million Android users have downloaded apps from the official Google Play Store that contained an advertising library that showed out-of-app ads.

This advertising library, called the BeiTaPlugin, was found embedded in 238 applications, Kristina Balaam, Security Intelligence Engineer at Lookout said in a report.

BeiTaAd forcibly displays ads on the user’s lock screen, triggers video and audio advertisements even while the phone is asleep, and displays out-of-app ads that interfere with a user’s interaction with other applications on their device.

Lookout reported the malicious functionality to Google and the BeiTaPlugin has now been removed from all the affected apps on the Play store. Cumulatively, these applications amount to over 440 million installations, making this family unique in its prevalence and the level of obfuscation used to hide the plugin’s existence.

"While the vast majority of free mobile applications monetize their apps through Ad SDKs or plugins, the persistence of the advertisements in this particular family and the lengths to which the developer went to hide its existence make the BeiTaPlugin concerning," Balaam said.

All of the apps released with BeitaPlugin were published by mobile internet company, CooTek, founded in 2008 in Shanghai. CooTek became listed on the NYSE in 2018 and is best known for its popular keyboard app, TouchPal. The BeiTaPlugin package, com.cootek.beita.plugin, is unsurprisingly bundled within TouchPal as well as numerous add-ons to their popular TouchPal keyboard, and several very popular health and fitness apps.

While out-of-app ads are not particularly novel, those served by this plugin render the phones nearly unusable. Users have reported being unable to answer calls or interact with other apps, due to the persistent and pervasive nature of the ads displayed. These ads do not immediately bombard the user once the offending application is installed, but become visible at least 24 hours after the application is launched. For example, obtrusive ads did not present themselves until two weeks after the application, Smart Scan (com.qrcode.barcode.reader.scanner.free), had been launched on a Lookout test device.

Users have documented similar experiences on an Android forum discussion spanning several months, as well as in reviews left on the applications’ Google Play pages.

The BeiTa plugin has been refactored several times since its initial release in early 2018. In more recent iterations, the BeiTa plugin is renamed to the innocuous, icon-icomoon-gemini.renc, and is encrypted using Advanced Encryption Standard (AES). Icomoon is an application that provides vector icon packs for designer and developer use. One Icomoon-compatible icon pack is named Gemini. Malware authors commonly employ this technique of renaming executable files to other file types (pdf, jpg, txt) to hide malicious assets in plain sight.

The loaded plugin is never installed to the device. Therefore, it is not listed as an installed package nor is it possible to simply uninstall the plugin without uninstalling the carrier application.

As of May 23rd, 2019, the 230+ affected applications on Google Play have either been removed or updated to versions without the BeiTa Plugin.

Tags: Google playandroidadware
Previous Post
Sega Genesis Mini Available To Pre-Order
Next Post
Skype's Screen Sharing Goes Mobile

Related Posts

  • Elevate your gameplay across mobile and PC

  • What’s new in Android 15, plus more updates

  • Connecting all things Android at MWC Barcelona

  • New features for businesses in Android 13

  • Lucky number Android 13: The latest features and updates

  • What’s beta than Android 13?

  • HLDS UD Station DVDRW (Preview)

  • YouTube Music Offers Easy Transfer of Your Google Play Music library

Latest News

Synology Unveils DiskStation DS225 Plus
Enterprise & IT

Synology Unveils DiskStation DS225 Plus

New PS5 system update beta previews DualSense wireless controller pairing across multiple devices
Gaming

New PS5 system update beta previews DualSense wireless controller pairing across multiple devices

EnGenius Multi-Gigabit Switch Delivers 2.5G Performance with 90W PoE
Enterprise & IT

EnGenius Multi-Gigabit Switch Delivers 2.5G Performance with 90W PoE

Viltrox’s AF 90mm F3.5 Lens for the DJI Inspire 3
Drones

Viltrox’s AF 90mm F3.5 Lens for the DJI Inspire 3

EnGenius Announces Affordable ECW520 Access Point
Enterprise & IT

EnGenius Announces Affordable ECW520 Access Point

Popular Reviews

be quiet! Light Loop 360mm

be quiet! Light Loop 360mm

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Noctua NH-D15 G2

Noctua NH-D15 G2

Soundpeats Pop Clip

Soundpeats Pop Clip

be quiet! Light Base 600 LX

be quiet! Light Base 600 LX

be quiet! Pure Base 501

be quiet! Pure Base 501

Terramaster F8-SSD

Terramaster F8-SSD

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed