Android malware that sends fake text messages downloaded up to 4.2 million times
Apps removed from the Google Play Store will still be active on users' Android devices and must be deleted manually
Apps removed from the Google Play Store will still be active on users' Android devices and must be deleted manually
Apps removed from the Google Play Store will still be active on users' Android devices and must be deleted manually
More than 50 apps in the Google Play Store were infected with ExpensiveWall, a form of Android malware that sends fake text messages and charges users without their consent.
The malicious software was downloaded between one million and 4.2 million times before it was removed. Some of the impacted apps had been in the Google Play Store since 2015.
According to San Carlos-based cybersecurity firm ExpensiveWall was able to bypass
"What makes ExpensiveWall different than its other family members is that it is ‘packed’ – an advanced obfuscation technique used by malware developers to encrypt malicious code – allowing it to evade Google Play’s built-in anti-malware protections," the company said.
Once the malware is installed, it uses the Android's phone number to sign up for a range of paid services without the victim's knowledge.
Google was notified of the impacted apps in early August and removed them from its marketplace, but hackers uploaded a second strain of ExpensiveWall that infected 5,000 more smartphones within days.
Apps removed from the Google Play Store will still be active on users' Android devices and must be deleted manually. A full list of the affected apps and package names can be
Malware targeting Android-based smartphones continues to be problematic for app developers and consumers. As of March 2016, an actively used Android-based devices across the globe, and 352 million people purchased them during the last .
As the popularity of the Google-developed operating system rises, to steal personal or financial data, falsify revenue and spy on users.
In 2016, SophosLabs processed suspicious Android applications, and more than 50 percent were a form of malicious software or adware.