financetom
Technology
financetom
/
Technology
/
Apps on Google Play with 100 million downloads infected by malware, says report
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
Apps on Google Play with 100 million downloads infected by malware, says report
Apr 17, 2023 2:06 AM

A new Android malware known as "Goldoson" found in 60 genuine apps with a combined total of 100 million downloads has entered Google Play.

According to BleepingComputer, the creators unintentionally inserted a third-party library into all sixty apps containing the harmful malware component.

The research team at McAfee found Android malware that is capable of gathering a variety of private data, including details on the user's installed apps, WiFi and Bluetooth-connected devices, and GPS coordinates.

Some of the affected apps are:

L.POINT with L.PAY - 10 million downloads

Swipe Brick Breaker - 10 million downloads

Money Manager Expense & Budget - 10 million downloads

GOM Player - 5 million downloads

LIVE Score, Real-Time Score - 5 million downloads

Pikicast - 5 million downloads

Compass 9: Smart Compass - 1 million downloads

GOM Audio - Music, Sync lyrics - 1 million downloads

LOTTE WORLD Magicpass - 1 million downloads

Bounce Brick Breaker - 1 million downloads

Infinite Slice - 1 million downloads

SomNote - Beautiful note app - 1 million downloads

Korea Subway Info: Metroid - 1 million downloads

Also Read: Ahead of Apple CEO visit, India is considering slashing import duties

In addition, the report claims that it has the ability to engage in ad fraud by secretly clicking advertisements.

The library registers the device and gets its configuration from an obscured remote server when a user launches a Goldoson-containing app.

The configuration details the data-stealing and ad-clicking activities Goldoson should perform on the infected device, as well as how often.

According to the research, the data collecting mechanism is frequently set to activate every two days and send the C2 server a list of installed apps, a history of past whereabouts, the MAC addresses of devices linked via Bluetooth and WiFi, and other data.

The permissions supplied to the malicious software during installation as well as the Android version affect how much data is collected.

Also Read: WhatsApp bolsters user privacy with new automatic security codes, device verification

Although devices running Android 11 or later are better protected against arbitrary data collection, researchers discovered that Goldoson had enough rights to acquire sensitive data in 10 percent of the apps even in newer versions of the OS, the report mentioned.

"Users who installed an impacted app from Google Play can remediate the risk by applying the latest available update," BleepingComputer said in its report.

Ad revenue is generated by loading HTML code, injecting it into a tailored, hidden WebView, and then utilising that to carry out many URL requests.

The victim's device shows no evidence of this action.

Google's Threat Analysis gang shut down thousands of accounts in January that were connected to the "Dragonbridge" or "Spamouflage Dragon" gang, which spread false information favourable to China on multiple platforms.

The tech giant claims that Dragonbridge purchases new Google Accounts from bulk account vendors and that occasionally they have even utilised accounts that had previously been used by actors with financial motivations and were then used to post blogs and videos that spread misinformation.

(With IANS Inputs)

Also Read: Italy demands ChatGPT changes from OpenAI by end of April

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
Forecast update for Gold -12-06-2025
Forecast update for Gold -12-06-2025
Jun 12, 2025
The price of (Gold) rose in its last intraday trading, after it declined in its early trading in a sudden and quick move, to lean on the support of its EMA50, providing a base that make it gain a positive momentum that assisted it to bounce higher on the short-term basis and its trading alongside a bias line, on the...
Forecast update for crude oil -12-06-2025
Forecast update for crude oil -12-06-2025
Jun 12, 2025
The price of (crude oil) declined in its recent intraday trading, amid the emergence of the negative signals on the (RSI) after reaching overbought levels, attempting to look for a higher low to take it as a base that might assist it to gain the required positive momentum to recover, amid the dominance of the main bullish trend on the...
Forecast update for Silver -12-06-2025
Forecast update for Silver -12-06-2025
Jun 12, 2025
The price of (Silver) rose in its last intraday trading, after getting a strong bullish push due to its lean on the support of its EMA50, accompanied by the stability of the key support at $35.90, providing positive momentum that assisted it to bounce quickly, with the emergence of the positive signals on the (RSI), after reaching oversold levels. ...
Forecast update for Brent crude oil -12-06-2025
Forecast update for Brent crude oil -12-06-2025
Jun 12, 2025
The price of (Brent) declined in its recent intraday trading, looking for a higher low that might assist it to gain the required positive momentum to recover, and it attempts to offload its overbought condition on the (RSI), amid the dominance on the main bullish trend on the short-term basis and its trading alongside a bias line. ...
Copyright 2023-2026 - www.financetom.com All Rights Reserved