Over 300 malicious Android apps, with 60 million downloads, were found on Google Play and acted as adware or credential and credit card stealing software. The malicious activity was uncovered by IAS Threat Lab and given the name “Vapor.” According to researchers, the campaign has been ongoing since early 2024.
IAS Threat Lab identified 180 apps as part of the Vapor campaign, which generated 200 million fraudulent requests for advertising offers daily, as part of a ad fraud . However, a recent report from Bitdefender increased the number of malicious apps to 331. Users who downloaded the malicious apps were mainly located in Brazil, the United States, Mexico, Turkey, and South Korea.
“ The apps display out-of-context ads and even try to convince victims to provide credentials and credit card information as part of phishing attacks ,” Bitdefender warns
See also: Malicious OAuth applications target Microsoft 365 accounts
Although all of these apps have now been removed from Google Play, there is a significant risk that new apps will appear, as the attackers behind the Vapor campaign appear to be quite adept at bypassing Google's vetting process.

Vapor Apps on Google Play
The apps used in the Vapor campaign are presented as utilities for health and fitness tracking, note-taking tools and calendars, battery optimization apps, and QR code scanners.
Apps pass Google's security checks because they include normal functionality and do not contain malicious components at the time of submission. Malicious components are introduced by installing updates provided by a command and control (C2) server.
Some of the applications highlighted by Bitdefender and IAS are:
• AquaTracker – 1 million downloads
• ClickSave Downloader – 1 million downloads
• Scan Hawk – 1 million downloads
• Water Time Tracker – 1 million downloads
• Be More – 1 million downloads
• BeatWatch – 500,000 downloads
• TranslateScan – 100,000 downloads
• Handset Locator – 50,000 downloads
The apps were submitted to Google Play by various developer accounts, a few at a time, so as not to cause major disruption to the Vapor campaign in the event of removal.
Most of the Vapor apps were published on Google Play between October 2024 and January 2025, although uploads continued until March.
How do malicious apps work?
According to researchers, the Vapor malicious apps disable Launcher Activity in the AndroidManifest.xml file after installation, thus becoming invisible. In some cases, they are renamed in Settings to appear as legitimate apps (e.g. Google Voice).
See also: Apps on Google Play and App Store are stealing crypto wallets
The apps launch without user interaction and use native code to activate a secondary hidden component, keeping the Launcher Activity disabled.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Bitdefender says this method bypasses security protections that prevent apps from dynamically disabling their launcher activities when they are active.
The malware also bypasses the “SYSTEM_ALERT_WINDOW” permission restrictions on Android 13+ operating systems and creates a secondary screen that acts as a fullscreen overlay.
Ads appear on this screen, which appears above all other apps, preventing the user from leaving, as the “back” button is disabled.
The app is removed from “Recent Tasks” so that the user cannot determine which app displayed the ad they just received.
Bitdefender reports that some apps were not just adware, but displayed fake login screens for Facebook and YouTube to steal credentials or prompt users to enter credit card information.

Protection from malicious applications
The full list of Vapor malicious apps on Google Play is available here. If you have installed any of these apps, remove them immediately, change passwords on services, and run a full system scan with Google Play Protect (or other mobile AV products).
You should always verify the authenticity of an app before installing it. This can be done by checking the app developer and user reviews.
See also: 2024: Google banned 2.3 million dangerous apps from the Play Store
Additionally, visit the official website of a service and find the link there to download the application from the app store.
It's also important to check the permissions that apps request, even if they're on Google Play. If an app asks for access to personal information that doesn't seem necessary for it to function, it's best to avoid installing it.
The use of reliable security software and regular updates of the operating system and applications are also essential .
Source: www.bleepingcomputer.com
