Apple last week removed an anti-malware app from the Apple store after it was discovered that it was collecting critical information without users' permission and sending it to someone in China. The app was called Adware Doctor, and it offered protection to users' devices against malware and adware threats.

This application was the number one solution on the list of paid security applications, with an average rating of 4.8 stars (with a maximum of 5) and over 7,000 reviews.
While it was able to remove malware from Macs, it was discovered to be stealing and uploading user information to a remote address.
This behavior was first discovered by security researcher Privacy 1st, who observed that the app collected history from Chrome, Firefox, and Safari browsers, as well as active processes on the device. After the data was collected, it was stored in a password-protected zip file, which was sent to a remote server.
To show how it works, Privacy 1st created a video and uploaded it to YouTube.
[su_youtube url=”https://www.youtube.com/watch?v=nZ7CVIy5Tq8″ width=”640″ height=”380″]https://www.youtube.com/watch?v=B7o0qA4L4So[/su_youtube]
Adware Doctor has a strange history. Thomas Reed, developer of Malwarebytes for Mac, said that he has been closely following the application since 2015. The reason is because in 2015, a copycat application of Malwarebytes, called Adware Medic, appeared in the Apple Store. So, after Malwarebytes requested Apple to remove Adware Medic. But shortly after, the same application appeared under the name Adware Doctor from the same developer.
Additionally, similar malicious behavior has been identified in other applications, under the names “Open Any Files: RAR Support”, “Dr. Antivirus”, and 'Dr. Cleaner”.
