Security researchers at Zscaler discovered hundreds of fake (malicious) apps in the Google Play Store last year, warning that millions of users may have had their devices infected with malware.

The researchers' findings were revealed in the company's " ThreatLabz 2024 Mobile, IoT, & OT Threat Report " and cover the period June 2023 - April 2024
Zscaler discovered more than 200 malicious apps on Google Play, Google's official app store. These apps have amassed a total of more than eight million installs.
See also: Apps on Google Play and App Store facilitated “pig butchering” scams
The most malicious applications were associated with Joker malware (38%). Joker enables Wireless Application Protocol (WAP) fraud, secretly enrolling victims in subscription services without their consent.
Adware threat on Google Play (35%), followed by Facestealer (14%), which is designed to harvest Facebook credentials in order to steal accounts.
Zscaler said that mobile banking malware (29%) and mobile spyware (111%) were also significant threats.
Apps infected to trick users were predominantly in the “Tools” category, accounting for almost half (48%) of apps infected with malware. Malicious personalization apps (15%) and photography-related apps (11%) were also quite common.
See also: Google Play: Fake WalletConnect app stole users' crypto

Protection from malicious applications
Although Google Play has defense mechanisms, some malicious apps manage to sneak into the store. For this reason, users should always verify the authenticity of an app before installing it. This can be done reviews user.
Additionally, users can visit the official website of a service and find the link there to download the application from the app store.
See also: Necro malware loader has infected 11 million devices via Google Play
It's also important to check the permissions that apps request, even if they're on Google Play. If an app asks for access to personal information that doesn't seem necessary for it to function, it's best to avoid installing it.
It is also essential to use reliable security software and regularly update the operating system and applications. Finally, users should avoid sharing their personal information with untrusted sources.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: www.infosecurity-magazine.com
