logo

New Malicious Clicker found in apps installed by 20M+ users

ID: b60f01c5-4594-5a78-89f0-b8292a0febb3

STIX ID: report--b60f01c5-4594-5a78-89f0-b8292a0febb3

Feed Name: McAfee Labs Blog

Threat Score
65/100

Date Published: 2022-10-19

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

McAfee Mobile Research identified a Clicker Android malware campaign that slipped into Google Play via 16 utility apps (estimated ~20 million installs). The malware uses remote configuration and Firebase Cloud Messaging to trigger background browsing and automated clicks (libraries com.click.cas and com.liveposting), causing ad fraud, heavy network/power usage, and stealthy operation; the report includes IoCs (domains and SHA256 hashes) and recommends removal and use of mobile security.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.