Goldoson: Privacy-invasive and Clicker Android Adware found in popular apps in South Korea
ID: f912e889-2589-5447-8d01-1a1e065d1edd
STIX ID: report--f912e889-2589-5447-8d01-1a1e065d1edd
Feed Name: McAfee Labs Blog
McAfee Mobile Research discovered a malicious third‑party Android library called Goldoson embedded in over 60 apps (over 100 million downloads observed across Google Play and Korea’s ONE store). Goldoson registers devices, retrieves remote configurations, periodically exfiltrates sensitive data (installed apps, Wi‑Fi/Bluetooth MACs, location history) and invisibly loads/injects web content to perform background ad‑click fraud. McAfee reported the findings to Google; some apps were removed or updated. The report includes identified domains and a table of affected package names and statuses, and warns about privacy risks and required permissions such as QUERY_ALL_PACKAGES and runtime location permissions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
