It's no surprise that the Google Play Store is surrounded by a large number of malicious apps that have the potential to gain users' attention and fall victim, but this time, it's even worse than most people realize.
Researchers at Trend Micro have identified a family of malicious apps, dubbed “Godless,” that has the ability to secretly root nearly 90% of all Android phones.
Well, that’s kind of scary.

Malicious apps are distributed through different methods and across many app stores, including the Google Play Store, which is usually considered a safe option for downloading apps.
The malicious apps that are packed with Godless contain a collection of open-source or distributed Android rooting exploits that work on any device running Android 5.1 Lollipop or earlier.
Since the Android ecosystem is so broken, approximately 90% of all Android devices are vulnerable to this malware. The Godless apps have already been installed on more than 850,000 devices worldwide to date.
Rooting a device could expose the user to several security risks, as it essentially opens the door for unwanted access, hardware failure, data leaks and information theft, and so on.
Based on the source code analyzed, Trend Micro researchers say that once an app with the Godless malware is installed on a victim’s device, it uses a framework known as “android-rooting-tools” to gain root access to the victim’s device.
From there, the malware will verify that the victim’s screen is off before executing the malicious code.
Once Godless gains root privileges, it initiates communication with a C&C server, from where it gets a list of apps to install on the device with root privileges and installs them without the user’s knowledge.
In order to avoid falling victim to such an app, Android users are advised to avoid using third-party app stores and always “check the developer” when downloading apps, even when it comes to the official Google store.
