ESET researchers discovered 42 Android apps in the Google Play Store that were infected with adware. The apps had millions of downloads. ESET named the adware Ashas (Android/AdDisplay.Ashas).
But the researchers didn't just discover the malicious apps. They also managed to track down their creator, a university student living in Hanoi, the capital of Vietnam.
According to the researchers, some of the apps did not have the Ashas adware in their original versions. The student was making legitimate apps until he decided to run an adware business.
Thus, it added the Ashas adware code to its original applications, which resulted in the display of advertisements to victims.
Researchers say the Vietnamese developer did a great job of disguising the origin of these ads. The ads appeared about 24 minutes after the infected app was opened and often featured the logos of other well-known apps.
The student's apps had been on the Google Play Store since July 2018. Up until the time of ESET's discovery, 21 of the apps were on the store.
Although Google removed the apps, they are still available in third- party.
Investigators were able to track down the Vietnamese programmer because of the sudden change in his plans.
The student, as we mentioned above, was initially designing legitimate applications that were not infected with adware. For this reason, he had not taken care to hide identity his in the first versions of the applications.
Researchers were able to link the emailshe used to register adware domains to his personal accounts on GitHub, YouTube, and Facebook. ESET has published a reportdetailing how it reached the student.
It's not certain whether the student will face justice. agencies don't usually deal with adware-related scams, and if they do, they deal with those hackerswho steal millions, not small attacks.
Below you can see the adware-infected applications. If you still have any of them, remove them from your device immediately.

