Researchers recently discovered at least 50 apps in the official Google Play store that made charges for paid services without the users' knowledge or permission. The apps were downloaded up to 4.2 million times. Google quickly removed the apps after the researchers' report, but within a few days, apps from the same malicious family returned and infected more than 5,000 devices.

The apps, all stemming from a family of malicious software that the security company Check Point calls ExpensiveWall, secretly sent phone numbers, locations, and unique device identifiers to servers controlled by an intruder. Then, the apps used the phone numbers to register unwanted users to high-quality services and to send high-quality fake text messages, an activity that caused users to be charged. Check Point researchers did not know how much revenue was generated from the apps. Google Play showed that the apps had between 1 million and 4.2 million downloads.
ExpensiveWall, named after one of the individual apps called LovelyWall, used a common shielding technique. By compressing or encrypting the executable file before uploading it to Play, attackers can hide their malicious nature from Google’s malware scanners. Although the technique has been around for over a decade, Google’s failure to detect the apps even after removing the first batch highlights how effective the technique remains.
Even after Google removes the apps, many phones will remain infected until users explicitly uninstall the malicious titles, according to the Check Point researchers. Google has long said that a security feature known as Play Protect, formerly called Verify Apps, will automatically remove malicious apps from infected phones. Many phones, however, never get disinfected, either because users have disabled the default feature or are running an old version of Android that doesn’t support it, according to the Check Point researchers. A full list of affected apps is included in the Check Point report linked above. Google representatives did not immediately comment for this post.
