{"id":598,"date":"2025-08-29T23:01:01","date_gmt":"2025-08-29T21:01:01","guid":{"rendered":"https:\/\/blog.digitalonion.ly\/?p=598"},"modified":"2025-08-29T23:01:04","modified_gmt":"2025-08-29T21:01:04","slug":"malicious-android-apps-with-19m-installs-removed-from-google-play","status":"publish","type":"post","link":"https:\/\/blog.digitalonion.ly\/?p=598&lang=en","title":{"rendered":"Malicious Android apps with 19M installs removed from Google Play"},"content":{"rendered":"\n<p>Seventy-seven malicious Android apps with more than 19 million installs were delivering multiple malware families to\u00a0Google Play users. This malware infiltration was discovered by\u00a0Zscaler&#8217;s ThreatLabs\u00a0team while investigating a new infection wave with Anatsa (Tea Bot) banking trojan targeting Android devices. While most of the malicious apps (over 66%) included adware components, the most common Android malware was Joker, which researchers encountered in almost 25% of the analyzed apps. Once Joker malware is installed on a device, it can\u00a0read and send text messages, take screenshots, make phone calls, and steal contact lists, access device information, and subscribe users to premium services. A smaller percentage of the apps included maskware, a term used to define a malicious app that disguises itself as something that would not raise any suspicion. This type of malware may pose as\u00a0a legitimate app that works as advertised. However, it performs malicious activity in the background, such as\u00a0steal\u00a0credentials, banking info, or other sensitive data (location, SMS). Cybercriminals can also use maskware to deliver other malware. Zscaler researchers also found a variant of the Joker malware called Harly, which comes as a legitimate app that has a malicious payload hidden deeper in the code to avoid detection during the review process.<\/p>\n\n\n\n<p>Contact us : <a href=\"tel:00218915579536\u202c\">0915579536\u202c<\/a><\/p>\n\n\n\n<p>Or on the website <a href=\"http:\/\/digitalonion.ly\" target=\"_blank\" rel=\"noreferrer noopener\">digitalonion.ly<\/a><\/p>\n\n\n\n<p><strong>Visit us at our company address: Tripoli \u2013 Andalus Street \u2013 Next to the Iraqi Embassy.<\/strong><\/p>\n\n\n\n<p><a href=\"https:\/\/maps.app.goo.gl\/xtDNpMSSfVe7zC9t9?fbclid=IwZXh0bgNhZW0CMTAAAR0agjJLdY1fw8Svc0z1ODqZbUdA7iBvh0QACYyoRcdYQ4NGTYHbZ6bQGtg_aem_klwdVZms8wjhcVBzxmkYtw\">Company address on the map<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Seventy-seven malicious Android apps with more than 19 million installs were delivering multiple malware families [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":596,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false},"version":2}},"categories":[81,7],"tags":[],"class_list":["post-598","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security-news","category-uncategorized-en"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/blog.digitalonion.ly\/wp-content\/uploads\/2025\/08\/Untitled-4.jpeg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/blog.digitalonion.ly\/index.php?rest_route=\/wp\/v2\/posts\/598","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.digitalonion.ly\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.digitalonion.ly\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.digitalonion.ly\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.digitalonion.ly\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=598"}],"version-history":[{"count":1,"href":"https:\/\/blog.digitalonion.ly\/index.php?rest_route=\/wp\/v2\/posts\/598\/revisions"}],"predecessor-version":[{"id":600,"href":"https:\/\/blog.digitalonion.ly\/index.php?rest_route=\/wp\/v2\/posts\/598\/revisions\/600"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.digitalonion.ly\/index.php?rest_route=\/wp\/v2\/media\/596"}],"wp:attachment":[{"href":"https:\/\/blog.digitalonion.ly\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=598"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.digitalonion.ly\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=598"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.digitalonion.ly\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=598"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}