HomeSecurityGoogle Play: 77 malicious apps with over 19 million downloads

Google Play: 77 malicious apps with over 19 million downloads

Android users’ security is taking a new hit, as Zscaler ’s ThreatLabs research team identified 77 malicious apps on Google Play with over 19 million downloads . These apps hosted multiple malware families, with some targeting the personal data and banking information of millions of users worldwide.

The discovery came as part of the analysis of a new wave of infections with the banking trojan Anatsa (also known as TeaBot), which has targeted Android devices with the aim of stealing banking information and cryptocurrencies.

The Joker and other threats

The research revealed that about two-thirds of the infected apps contained adware, but the most prevalent malware threat was the malware Joker, found in almost 25% of apps. Joker is particularly dangerous, as it gains access to SMS, contact lists, phone calls, device information, and enrolls users in subscription services without their consent.

See also: Chinese APT group uses Proxy and VPN services

Google Play malicious apps

Researchers also identified variants such as Harly, a version of Joker with a malicious payload hidden deep in the code to evade detection.

A smaller but worrying percentage of apps incorporated maskware – malicious software that camouflages itself as a legitimate app, operates normally to the user, but in the background steals credentials and other sensitive information.

The continuous evolution of Anatsa

The bulk of the investigation fell on the Anatsa trojan, which continues to evolve at an alarming rate. According to Zscaler, its latest version has expanded its target list from 650 to 831 banking and crypto wallet, significantly increasing the risk to users in more countries, now including Germany and South Korea.

Anatsa operators used the “Document Reader – File Manager”, which downloads the malicious payload only after it is installed on the device, thus bypassing Google’s checks. The new campaign installs the malware directly via JSON files, while older samples relied on loading DEX files.

See also: Phishing Attack Uses UpCrypter to Deliver RAT

To evade detection, Anatsa uses techniques such as tampered APKs, runtime string decryption, emulation detection, and frequent changes to packages and hashes. At the operational level, it exploits accessibility permissions to gain near-complete control over the device.

Google Play: 77 malicious apps with over 19 million downloads

In addition to stealing banking information, the latest version also features a keylogger to intercept keystrokes, as well as phishing pages that imitate hundreds of applications, enhancing its ability to deceive users and extract critical data.

Campaign history

This isn’t the first time Anatsa has appeared. In previous campaigns, malware has infiltrated Google Play disguised as PDF viewers, QR code readers, and phone cleaning apps. In fact, last summer one such app was downloaded more than 50,000 times, while in 2024 there were campaigns with tens of thousands of infections at a time. This pattern shows a consistent and methodical effort by attackers to exploit seemingly useful apps to lure unsuspecting users.

The image on Google Play

According to Zscaler, the current research showed that most infected apps belonged to the tools and personalization, followed by entertainment, photography, and design. These categories are now considered high-risk, as they are popular areas for the spread of malicious apps.

See also: SpyNote: Distribution via fake Google Play Store pages

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Himanshu Sharma, a researcher at Zscaler, said: “We are seeing a sharp increase in adware applications, while traditional families like Facestealer and Coper have declined significantly.

In total, the 77 malicious apps garnered 19 million downloads before being removed from Google Play, following a report by Zscaler to Google.

Google Play: 77 malicious apps with over 19 million downloads

What users should do

Although Google has removed the infected apps, users who installed them should take action. Enabling Play Protect is the first step to identify and remove suspicious apps. In case of infection with Anatsa, additional contact with the bank is required to secure accounts and online credentials.

To reduce the risk of future infections, it is recommended that users download apps only from trusted publishers, check reviews from other users, and grant only permissions related to the app's core functionality.

The case of the 77 malicious apps shows that even Google Play, despite its controls, is not immune. Anatsa, Joker and their variants prove that cybercriminals are constantly evolving their methods, targeting Android users en masse. Vigilance and proper “digital hygiene” remain the only shield against this invisible but ever-growing danger.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS