Ad End 1 August 2025
Ad Ends 13 July 2025
ad End 25 October 2025
Ad Ends 20 April 2025
Ad expire at 5 August 2024
banner Expire 9 June 2025
banner Expire 25 October 2025
banner Expire 10 May 2025
What's new
Wizard's shop 2.0
Money Club cc shop
banner Expire 15 January 2025
banner Expire 20 October 2024
UniCvv
Yale Lodge
Kfc CLub
adv exp at 30 July 2025
Carding.pw carding forum
BidenCash Shop

Dark_Code_x

TRUSTED VERIFIED SELLER
Staff member
Joined
Jun 28, 2020
Messages
6,776
Reaction score
726
Points
212
Awards
2
  • Somebody Likes you
  • First post
However, when he examined it further, he realized that the apps where the malware was found actually have a fairly large target audience. The apps are available in English-speaking countries and in other language versions as well, and have been downloaded by millions of users, assuming Google Play’s own data on app installs is accurate. Avast out this morning reveals the discovery of a new form of malware on the Google Play store,
which begins to display advertisements disguised as warning messages to end users when they unlock their Android smartphones. What’s interesting about this malware – or adware, as it’s better known – is that some of the applications where it was discovered already have a large number of installs. For instance, a card game app called Durak has 5 to 10 million installs, according to the data on Google Play.


Explains Avast researcher Filip Chytry, the malware was first brought to the company’s attention by way of a comment on the Avast forums, and, initially, he didn’t think much of it.
The apps are fairly clever about how they display the advertisements, too. Instead of beginning to show ads immediately after installation, they wait for several days. In some cases, the ads didn’t appear until after the app had been on the phone for a month.
“After 30 days, I guess not many people would know which app is causing abnormal behavior on their phone, right?” writes Chytry.

The ads also don’t begin showing up until you’ve rebooted your device at least once, he notes. Afterwards, the ads will appear each time the end user unlocks their phone, presenting warnings saying that your device is infected or “out of date” or is full of porn. The user is then asked to take some action, but is instead redirected to downloads of other malware-laden apps, including those that send premium SMSes or those that collect a ton of personal data.


Oddly, users were also sometimes pointed to mobile antivirus apps on Google Play – some from legitimate companies. For instance, antivirus provider Quihoo 360 was one of the targets. It’s not likely that these companies are marketing their services via adware, however. It’s more probable that the malware authors are benefitting from some sort of referral scheme.
Avast tells us that they’re now in touch with the antivirus company which was receiving the redirects, and that company is currently investigating the situation.
Obviously, using the Google Play Store to distribute malware is a violation of Google’s Terms of Service. We’ve reached out to Google to ask if it was aware of the problem Avast uncovered, and if it will investigate or ban the apps and the developers from its app store. We will update this post if and when Google responds.


In addition to the card game, other apps, including an IQ test and a history app, were also found to be infected. The apps are from different developers, but each has the same malicious software installed. The original commenter on Avast’s forums said he found the malware in a dozen infected applications and pointed to several more.
Avast says it has analyzed the three mentioned here, and is currently researching more apps that behave similarly right now. That means that the adware which already has an install base of millions, may actually be even larger still.
 
Ad End 1 February 2024
Top