logo

Goldoson: Privacy-invasive and Clicker Android Adware found in popular apps in South Korea

ID: f912e889-2589-5447-8d01-1a1e065d1edd

STIX ID: report--f912e889-2589-5447-8d01-1a1e065d1edd

Feed Name: McAfee Labs Blog

Threat Score
72/100

Date Published: 2023-04-12

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

McAfee Mobile Research discovered a malicious third‑party Android library called Goldoson embedded in over 60 apps (over 100 million downloads observed across Google Play and Korea’s ONE store). Goldoson registers devices, retrieves remote configurations, periodically exfiltrates sensitive data (installed apps, Wi‑Fi/Bluetooth MACs, location history) and invisibly loads/injects web content to perform background ad‑click fraud. McAfee reported the findings to Google; some apps were removed or updated. The report includes identified domains and a table of affected package names and statuses, and warns about privacy risks and required permissions such as QUERY_ALL_PACKAGES and runtime location permissions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.