New security concerns for Android apps, as more than 140 apps distributed through the Google Play Store were found to be infected with malware. This phenomenon is of course not new, but this time there is something unexpected in the researchers' findings.
A report from Palo Alto Networks reveals that a total of 145 apps published on the Google Play Store were infected not with Android malware, but with malicious executables that can run exclusively on Windows.
It is worth noting that the infected APKs detected pose absolutely no risk to the Android platform, but are specifically targeted at Windows, and therefore can only cause damage when the APK files are unpacked on a computer.
According to the researchers, most of the apps identified were released between October and November 2017, which practically means that they had been available on the Google Play Store for more than half a year.
Currently, all malicious apps have been removed from the Google online store.
The compromised APK files include malicious PE files that can create executable and hidden files in Windows system folders, change the Windows registry to automatically boot at startup, and connect to a specific IP address, potentially waiting for further commands.
Since most apps are installed directly on Android devices, it is not easy to accurately calculate how many users have potentially been affected by the malware.

