Security researchers at Sophos have discovered that over 600 million users have downloaded and installed devices “fleeceware” apps on their The fleeceware apps were available on the Play Store.
What is fleeceware?
The term fleeceware has recently been added to the cybersecurity vocabulary. The term was coined by Sophos of the United Kingdom last September. It refers to a new type of financial fraud on the official Google Play Store.
Most Android apps offer users the opportunity to try the app for free. Payment begins after the trial period ends.
By default, if users who sign up for an Android app trial want to keep the app, they must manually cancel the trial to avoid being charged. However, most users choose to simply uninstall apps they don't like.
When the application is uninstalled, the application developers interpret the action as a cancellation of the trial period and thus do not proceed with the charge
Last year, however, Sophos discovered that some Android app developers charged users even after the app was uninstalled.
The security firm initially discovered 24 fleeceware Android apps, which charged users (ranging from $100 to $240 per year) for the most basic and simplistic apps, such as QR/barcode readers and calculators.
Sophos published a report the day before yesterday, stating that it discovered other Android fleeceware applications that charge users after uninstalling an application.
What's worrying is that these apps have been installed on the devices of 600 million users . Sophos analyst Jagadeesh Chandraiah suspects that these apps used pay-per-install services to boost install numbers and then bought "fake five-star reviews" to boost their position in the Play Store and attract a large number of users.
Many of the users who downloaded the fleeceware apps may not have signed up for a trial period, but those who did should check history their Play Store payment to see if there are any charges from apps that have now been uninstalled.
In the table below you can see the Android apps that, according to Sophos researchers, exhibit fleeceware behavior. The GO Keyboard Lite app has once again caught the attention of security researchers .

