logo

Porn Clicker app Masquerading as Dubsmash

ID: 28e71c31-9eef-54c5-bec2-ff834406ce5c

STIX ID: report--28e71c31-9eef-54c5-bec2-ff834406ce5c

Feed Name: Zscaler Security Research Blog

Threat Score
45/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report analyzes an Android "Porn Clicker" malware masquerading as the Dubsmash app on Google Play that hides its icon after first run, continues running in the background, dynamically retrieves porn site URLs from remote servers (e.g., memr.oxti.org/g/getasite/ and memr.oxti.org/z/z2/) and executes JavaScript to generate fraudulent clicks for revenue; observed package names include com.memr.gamess and com.jet.dubsh, the variant has ~5,000 downloads, and users are advised to remove the app via Settings > Apps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.