Malicious Android 'Vapor' apps on Google Play installed 60 million times
ID: 54f92f85-a3e3-556a-a05c-823333ab8beb
STIX ID: report--54f92f85-a3e3-556a-a05c-823333ab8beb
Feed Name: Bleeping Computer
A campaign dubbed 'Vapor' distributed at least 331 malicious Android apps through Google Play (many with hundreds of thousands to millions of installs) that downloaded malicious payloads after installation to perform large-scale ad fraud, present fullscreen overlay ads, and carry out phishing-like credential and credit card theft; the malware used techniques such as disabling its launcher, hiding from Recent Tasks, native code to enable hidden components, and bypasses for Android 13 protections. Although Google removed the identified apps, the actors' ability to pass review and deliver malicious updates post-install presents a continued risk; a full list of affected packages is available in the linked CSV and users should remove any listed apps and run mobile AV scans.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
