Six more apps infected with Joker malware , which were on the Google Play store with a total of over 200,000 downloads, have been discovered by the Cybersecurity team. This is yet another case of dangerous apps that have been plaguing Android users lately.

The Joker malware pretends to be a legitimate app on the Play Store. However, once installed on a device, it performs billing fraud either via SMS messages to a premium number or by using the victim's account to make multiple purchases using WAP billing.
The malware operates underground, without requiring any action on the part of the user, so it is not easy to detect until the user receives their mobile bill and discovers additional charges.
So far, 1,700 apps containing the Joker malware have been removed from the Play Store since 2017, however it appears that the malware continues to resurface.
Of the six apps revealed, one called "Convenient Scanner 2" has been downloaded over 100,000 times, while "Separate Doc Scanner" has been downloaded by 50,000 users.
Another app, “Safety AppLock,” claims to “protect your privacy” and has been installed 10,000 times by users who will eventually find that the app is harming them instead of protecting them.
Two more apps, "Push Message-Texting & SMS" and "Emoji Wallpaper", have received 10,000 downloads each, while one called Fingertip GameBox has been downloaded 1,000 times.

The six apps have now been removed from the Play Store after being disclosed by Pradeo to Google.
Users who have downloaded any of the apps to smartphones are urged to remove them immediately.
According to Google, Joker malware is one of the most persistent threats facing the Play Store, as its creators have used it in many different forms to go unnoticed.
In many cases, malicious apps were able to bypass Play Store protection by initially presenting legitimate functionality.
The creators of Joker are trying to encourage downloads of the malware by inserting fake positive reviews. The person or group behind the Joker malware is most likely still active and trying to trick more users into downloading the malware to continue the scam.
