Malicious Android apps on Google Play downloaded 42 million times
ID: 8847eb04-d3b9-56e7-8f0d-991d75de50db
STIX ID: report--8847eb04-d3b9-56e7-8f0d-991d75de50db
Feed Name: Bleeping Computer
Zscaler's telemetry between June 2024 and May 2025 found 239 malicious Android apps on Google Play with ~42 million downloads, a 67% YoY rise in mobile-targeting malware, adware accounting for ~69% of detections, a 220% YoY spike in spyware, and continued banking-trojan activity (4.89 million transactions); highlighted families include Anatsa, Android Void (Vo1d), and Xnotice, and the report documents social-engineering TTPs (phishing/smishing, SIM swapping, overlays) plus IoT/router exploitation, concluding with recommendations like applying updates, restricting permissions, zero-trust, and SIM-level monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
