News about malware in Android apps has become a daily occurrence. The latest incident has Google removing 25 more apps from the Play Store after Symantec discovered that the apps shared a similar malicious code structure. These apps, which were presented as photo and fashion apps, were downloaded by users over 2.1 million times.

Once a user downloads the app, the executed code hides its icon and displays full-screen ads. The ads do not indicate the app that triggers them and appear even when the malicious app is closed, so users have no way of knowing which app is malicious. Symantec cites financial gain from ad revenue as a possible motivation behind the creation of the malware.
Given the similarity between the apps, Symantec believes they may have been created by the same organization. App listings on the Play Store are also quite sneaky: hackers publish two versions of the same app, one is the “clean” version and the other contains the malware. The “clean” version may rank in the top charts or trending category, but when users manually search for the app, they have a 50-50 chance of downloading the ad-enabled variant.

The only difference between the attack and previous malware batches is the way the app icons are hidden. The programming that hides the apps is not hard-coded. Instead, a remote switch is embedded in the configuration files, which means that Google 's security tests do not cover this aspect of the code.
Symantec and other security firms are frequently discovering new malware practices in the Play Store, raising questions about how proactive and secure Google is. Sure, Google has implemented effective security practices, but apps like these continue to trick it. Therefore, additional measures are needed to better protect Android users from malware and adware.
