logo

Nasty adware hiding in apps on Google Play Store

ID: 9fa9e7b6-6903-5db0-80a5-bb6f33fc0399

STIX ID: report--9fa9e7b6-6903-5db0-80a5-bb6f33fc0399

Feed Name: Zscaler Security Research Blog

Threat Score
65/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ discovered and analyzed 12+ malicious Android apps on Google Play that act as aggressive adware: they contact a C&C which can instruct them to request device-administrator privileges, download and execute a secondary dex (secondlib.dex), hide the app icon, and perform ad-related actions (fullscreen ads, open links, launch videos/apps, create shortcuts). The report details code injection into a spoofed com.google.android.gms package, obfuscated strings, runtime dex loading, observed download counts (10k–50k for some apps), a full list of malicious package names, and notes the apps were reported and removed in March 2017.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.