Joker malware, which enrolls Android users in premium services without their consent, is making things difficult for Google, as new samples continually bypass checks and end up in the Play Store.
The malware is constantly evolving, and the new samples found in the official Android repository appear to have been created specifically to evade Google.
Also known as Bread, the malware is a spyware and premium spyware that can access notifications, read and send SMS. These capabilities are used to invisibly sign up victims for premium.
Joker avoids the US and Canada
Check Point researchers discovered four new samples on the Play Store recently, in apps with cumulative installs of over 130,000. The malware was hidden in camera, wallpaper, SMS, and photo editing software:
- app.reyflow.phote
- race.mely.wpaper
- landscape.camera.plus
- vailsmsplus
To hide malicious functionality in infected applications, a simple XOR encryption with a static key is applied to relevant strings that check for the presence of an initial payload and if not present, it is downloaded from a command and control (C2) server.
The malware does not target devices from the US and Canada, as Check Point discovered a function that reads operator information specifically to filter out those regions.

If the conditions are met, Joker contacts its C2 server to load a configuration file containing a URL for another payload that is executed immediately after download.
The subscription process is invisible to the user, as the URLs for the high-quality services present in the configuration file open in a hidden webview.
The Joker developer often adapts the code to remain undetectable. Google says that many of the samples detected appear to have been created specifically for distribution through the Play Store, as they did not appear elsewhere.
Since Google began tracking Joker in early 2017, the company has removed around 1,700 infected apps from the Play Store. But that hasn't deterred the malware's author, who "has used almost every technique to avoid detection."
New samples of Joker appear almost daily in the Google Play Store, says Aviran Hazum, a mobile security researcher at Check Point.
The purpose of clicker is ad fraud by imitating users' clicks on ads. Mobile ad fraud is an ongoing challenge these days as it can take many forms. For this offense, Google announced yesterday that it has removed nearly 600 apps from the official Android store and also banned them from its ad monetization platforms, Google AdMob and Google Ad Manager.
Named Haken, the new malicious code relies on native code and injection into Facebook and AdMob libraries and gets its configuration from a remote server after going through Google's verification process.

The malware was introduced in apps that provide advertising functionality. A sign of malicious intent is requesting permissions that the compromised app does not need, such as executing code at device startup.
Once it has the necessary permissions, Haken achieves its goal by loading a native library (kagu-lib) and registering two service workers.
The native code registered in the Ad-SDK (software development kit) enables the process of implementing a backdoor into apps already on the Play Store, allowing Haken to maintain a low profile and generate revenue from fraudulent advertising campaigns.
It is unclear how long the malware has been active and how much revenue it has generated, but the low number of installations suggests that it is not widespread. If they are still present on their devices, users are urged to remove the following apps:
- Kids Coloring – com.faber.kids.coloring
- Compass – com.haken.compass
- qrcode – com.haken.qrcode
- Fruits Coloring Book – com.vimotech.fruits.coloring.book
- Soccer Coloring Book – com.vimotech.soccer.coloring.book
- Fruit Jump Tower – mobi.game.fruit.jump.tower
- Ball Number Shooter – mobi.game.ball.number.shooter
- Inongdan – com.vimotech.inongdan
