Warning: 331 Malicious Android Apps on Google Play Store Stealing Credentials — Check Your Device Now!

Security researchers have unraveled a mega-scale threat campaign targeting the Google Play Store.

This includes up to 60 million installs of numerous malicious apps that entered the Play Store and managed to bypass all security protections in place. The Play Store is a common target by threat actors, similar to how they like to target Gmail and Chrome. It’s also a major candidate for criminals searching to upload the malicious lines of coding. This means they can go beyond the existing safeguards in place.

Google has done a great job at making sure many don’t go on evading users' devices but there are many times where even the experts aren’t blowing the whistle at the right moment. The issue is more linked to cybercriminals not being great at adapting and evolving different methods when payloads hit healthy profits. Researchers from Bitdefender highlighted a group of bad actors that are carrying out large-scale campaigns where at least 331 campaigns were launched and they ended up getting downloaded more than 60M times from apps including, Five in a Row, AquaTracker, Massm BMI, ShapeUp, ClickSave Downloader, Body Scale, Daily Spending, Cache Sweep TEL, TranslateScan and many more. The full list of associated package names is provided below. While researchers attempted to include their names/URLs, most may be missing from the Play Store, likely because they have been removed. If you have any of these apps installed, it's best to uninstall them immediately.

"All of the identified apps from this report have been removed from Google Play. Android users are also automatically protected by Google Play Protect, which is on by default on Android devices with Google Play Services.” - A Google spokesperson explained.

To be more accurate, it’s the most active campaign and the latest malware platforms found their way into the Play Store where they went live last week. After the investigations ended, 15 apps were still found for downloads on the Google Play Store. The apps bypassed so many security restrictions and began activities even if they weren’t running in the background and without the permissions needed.

The result is spam for the victim with back-to-back fullscreen ads and serving user interface features to provide phishing attacks. Hundreds of those could give rise to credential theft. This appears as the latest threat campaign to take over the Play Store. The report from experts shared how all highlighted apps were removed at the time they were discovered. But it’s actually much bigger in scale than what it was perceived to be.

Dangers include criminals accessing devices belonging to direct users linked to phishing websites, not just showing them off in terms of big-screen ads. Some of these platforms could even generate phishing activities through fullscreen acts.

Users might be asked to add credentials from the Facebook platform or another online service or even through credit card information on apps or online websites. Still, we are seeing a bunch of apps continually being added to the Play Store and working to create misery without any signs of removal. They are copying the actions of utility apps such as those known for QR Code scanning, tracking expenses, and even providing health-related information.

Experts mentioned how there are several worrisome takeaways here. The app icons were hidden and it’s something that’s not possible any longer technically through the newest Android variants. Bitdefender shared how it was observing several tactics to get around such protections.

Researchers shared how the apps already come embedded with Launcher Activity that is disabled through default means. So they can abuse the startup mechanism and enable a launch. It’s another means to evade detection. So after the setup is done, the platform disables this launcher and the icon ends up vanishing. Hence, malicious developers are more likely to find bugs or abuse the app’s programming interface.

In some cases, the attackers use launchers created for Android Television as well as the platform hiding behind settings and altering the name to Google Apps like Google Voice to prevent getting detected. Lastly, the apps may begin without any kind of user interaction. It’s something else that is not designed to be technically possible through Android 13 as it shows no ads over other apps playing in the background.

Packages
0roshag.chat.enhance.iushx
1com.apples.qrcreator
2com.ion.code.sentry
3com.cannon.physiqueprofiler
4com.trashbuster.cleanhyper
5com.nmyfun.hpaint
6religion.divine.calendar.app
7com.oasis.drinktracker.healthapp
8com.rabbit.glucosediary
9com.tartar.light.lead
10com.codeNow.bgrpictotextapp
11com.letters.bodyfast
12health.care.heart.entry
13com.volleyball.sipsmart
14com.note.nook.nootbook
15com.note.log.notebook.text.trek
16com.dsgdddfsdgf.dvsdcs
17com.tome.answer.book.forandroid
18com.twinkle.note.halfwaytool
19com.bp.navigator.bloodpressure.application
20poaed.virtual.entity.tavbu
21com.everycount.recordexpenses
22com.putt.qrhunter
23com.spiders.turbopdf
24com.befbefsd.syfbfhgggg.ntevboka
25com.fitcalc.healthcare.bmi.fitbmi
26com.tomatoes.qrafter
27com.eareye.armhk.ftt
28com.wave.watcher.health.recorder
29com.skii.dlf
30com.flashlightscanner.creator
31com.dragon.scribe.notebook.myth
32datetime.calculate.time.wise
33com.starce.pulsemap
34com.antac.spritzy
35com.glove.slimbmi
36com.leadlife.knowledge.ark
37com.care.olsk
38com.magnify.sharp.sight
39com.donkey.healthline
40com.Qezxc.Tdfdz.gddp
41com.bloody.buddy.bp.blood
42com.sigture.femplce.cell.cdcd
43com.ufuopo.magic.frame
44com.wallpapersave.beautifulscene
45com.scubam.notes
46com.untang.cardio.care
47com.privatenumber.textphotos.calculator
48com.cartoon.wallpaper.adorable.setup
49com.potato.journeyquill
50com.imageosis.sourcephrame
51com.apparatus.festtrack
52yaiss.date.master.suiue
53com.pets.quickscan
54com.epicwalls.wallpaper.app
55com.magata.charger
56com.dilige.doc
57com.wallart.craft.fusion.canvas
58com.bee.beat.oplayer
59com.crayon.shapeup
60wall.paper.palette.paperpalette
61com.pressurepoint.bloodpressure.android
62com.black.myth.wukong.journal
63com.vedioscene.cutmaker
64date.time.span.comput
65com.image.frame.construction
66com.moreagent.beyour.wonderf
67com.animal.codeking
68com.lokrrclk.maicahaway.bcash
69com.find.myphone.out
70press.tracker.record.app
71com.zoofv.Gwsa.quote
72com.dochecklist.remarkthings
73com.clipclipnote.notebook
74com.school.paintflow
75com.docuflow.pdfinsight.pulse.nexus.adept
76com.writer.dripdropduo
77com.bookAnswers.Answersmaster
78com.gluco.log.blood.health
79com.beautifuland.stunningwall
80ryouab.pixlayer.wallpaper.giestc
81ygsap.electro.magnetic.field.scanner
82com.support.codeblitz
83com.snail.vitaltrace
84com.efldi.bdbhe
85religious.celebration.guide.app
86com.answer.tome.book
87beauty.wallpaper.gallery.app
88com.turan.antitheft.note
89com.sanit.notekeeper.master
90com.whimsywriter.dailynote
91com.friend.sparkdiary
92com.scannertranslate.useful.nloader
93text.score.count.helper
94com.trandsz.gfdweee.tagtag.discsion
95com.note.lively.notebook.android
96com.logdrink.water.wave.android
97com.snorkel.hydro.habit
98com.prose.inkslinger
99prolimatofa.egg.spiral.dash
100com.Capcap.mamp.totoy
101com.gulp.minder.andorid.application
102com.zoo.frarefew.mkey
103com.todaynote.everydaynote
104com.vvkdio.sout.boxo
105com.emojimaker.enjoyemoji
106com.wisdom.life.answer.book
107com.filefetcher.filesavedownloder
108faithful.holidays.finder.app
109qrocr.code.scan.ease
110com.ladybug.sumatrapdf
111com.building.tagreader
112com.qusad.queszh.prpcipcunm.rews
113com.circlestyle.easybrowser
114com.plusrecord.bp.recorder
115com.taste.scanhub
116com.cobweb.torchup
117com.filebrowser.easytouser
118com.fog.flashseeker
119virtual.nexus.aichat.app
120com.framefy.photoart
121com.legac.sipsync
122com.dynasty.qrique
123com.lance.scan.hawk
124ugiso.spiritual.days.yeisf
125offline.wall.art.paper
126com.riptide.torch
127com.breadof.whnowit.werdz
128com.shape.flipbook
129com.gree.cryyonmyeow.gange
130com.drfq.opmnlight.find
131com.swift.glide.stream.pilot
132quick.qrqr.code.scan
133com.badr.dreamstatus
134com.easycircle.online.browser
135com.trtytrrty.tyhbhn.qwewqdfs.gtgthgrt.uert
136com.dinosaurs.bplog
137com.gvvfzf.wdsd
138com.hydra.hub.scribe.h2odrink
139com.schdck.ctct.bid
140tsaid.stealth.apps.finder
141connection.wifi.link.app
142clear.text.ocr.recognize
143com.moontrack.herbrowser
144com.pulse.journalapp.bpussre
145com.eleven.netswift
146com.spectrum.note.book
147com.codhf.peyf.efo
148com.qritranslate.scanertext
149com.chakok.textbkspird.wsszook
150com.quickmark.qrscanmachine
151com.amused.lightup
152com.ansella.photoeditor.frame
153com.fftreds.ghgfgdfdk.dtdt.stt
154com.phopaper.wallto
155com.drum.beamblitz
156com.health.pressure.pilot
157com.dinner.lightbringer
158com.vmraqcu.pld
159com.snap.visionmate.app
160com.prison.grimace
161com.feeling.shapetrack
162com.bp.circulation.check.health
163com.bookbag.pencilt.erer
164com.needle.pixform
165com.eatrg.Rise.Motivate
166com.industry.perfectbmi
167twisty.egg.race.run
168com.btfdf.Nmfd.Rvsd.sdsa
169com.grandfather.waterwhiz
170com.docu.pdftext.flow.draft.piolt
171com.tree.year
172com.erfedfvgf.azxss.erewd.werfvbs
173com.prodigy.aurora.lume
174com.xasasaf.cdsv
175com.truck.xscan
176com.todogalaxy.list
177com.clear.sound.voice.recorder.management
178vgssea.code.capture.deoig
179com.wilderness.hydr8
180com.sugar.scanmaster
181com.text.word.lexicount
182com.loader.downloader.suitable
183com.toolsquik.schetchwat
184com.behavior.wellnessscope
185com.bbb.eewrew
186com.bysedr.poshk.tutu
187com.drink.aqua.tracker
188com.thirstquest.drink.health
189com.writer.drinkup
190com.textdocusheet.pdfreader
191com.hujkr.Gscas.Qrmanager.maker
192com.bmilog.healthrecorder.bmi
193com.phrameselect.nextlevel
194com.pennycharge.accountup
195com.spectrum.notebook.dairy.book
196com.KCDc.cmkd.sGAB
197com.territory.blink
198com.qewqwer.fdsasdsas.zswsdedeoko.jnm
199com.nicebrowser.verifyartical
200com.comfort.flashscan
201com.wrdup.noterecord.upnote
202com.equin.fury.light
203com.vcdfcx.vbghgfgy.tygdasz.daydu
204com.powder.shapesensei
205junk.clean.file.purge
206com.expense.visual.track
207com.slobb.page.pilot
208com.cuddleframe.cutewallpaper
209com.qrfgsd.hjk.fusion
210text.word.quantify.count
211com.gulp.minder.drink.health
212com.cleanpro.device.performance.cleaner
213com.defea.scan.eagle
214com.boys.vitalflow
215com.askoknook.wokfowt.fvsgsbm
216com.onto.drinksmart
217com.tkdodownloader.onlyfacebook
218com.mice.fastpdf
219com.tendency.waterlog
220com.aivou.peyfellti.treffas
221cardio.heart.rate.log
222com.noneedto.waitbrowser
223com.blood.pres.xhur
224com.cup.application.whidpers.sips
225com.dfcs.erwan.beat
226qrcode.ease.identify.app
227com.quarter.pdfpro
228com.dusahif.coaskjgf
229com.lemonlog.tool
230com.monkey.bodyguide
231com.wave.frink.wavelog.sagerak
232com.wetmeter.recorder.drink.water.health
233com.robust.drink
234com.uylm.goatm
235com.wsesas.fgfctre.opomna
236com.drinkhealth.water.wink
237com.vughgnnfg.fdfdgsfgfs.edxssx.adsdfjk
238com.afterthought.thirsttime
239vision.scan.ocrqr.quickly
240com.horn.nitropdf
241com.utfgop.Sagyuh.noteBokk.welkwe
242com.emotionalquotos.fightingwordsbox
243com.ponder.notebook.remindbook
244com.Redsa.ftrds.zxcv.tger
245com.saveall.fbloader.downloader
246com.photo.yellowclolor.frame
247com.clpclp.trefinder
248com.hdh.tewtwe
249com.qrscan.texttranslate
250com.oeredrt.charcha.boardky.ftsasauop
251com.sullen.glide.text
252com.conamoroll.wallpaper.com
253com.findyour.phone.fast
254com.stride.despise
255com.soulpages.wanderanswer
256com.underwatybop.ffdftakepiece.drik
257wallpaper.wall.scape.app
258com.zczcf.gygyu.ffdd.ruer
259com.stridecounter.stepcalculation
260com.shock.glowup
261com.at.scribe.sphere
262com.pophnbn.gfghghaa.libprrrty
263com.deva.insulineer
264com.fairies.codecatcher
265com.ulikerecoder.swifttrack.tmsv
266com.trewreeew.kjhgfpppp.ftghbgfdsa.fdsa
267com.bnmbvdscc.vgfrtgvttt.asawtart.waterokp
268com.overbite.ink.bender
269com.xxdffvc.Fcszrt.okasnm
270com.pennyrecorder.budget
271com.framep.beauttool
272com.ndgf.werew
273com.lively.note.book
274filehive.junk.cleaner.app
275wallpaper.pixel.stacker.app
276faith.dates.festival.app
277com.luxurious.scan.blitz
278com.Video.Maker.VideoEditor
279com.Disate.sentttanzc.dbhnmok.ftbbftas
280ygvas.scanqr.master.udybc
281com.pdfsaver.filedownload
282com.press.watch.bloodpressure
283com.ewqew.mokgfd.cbokp
284com.abk.asoj
285com.ring.find.phone.tool
286com.daojer.cmdcuky
287com.bears.pulsetrack
288com.chairs.hydrovibe
289com.stick.quenchlog
290com.year.fluidfocus
291com.thirst.quest.drink
292com.syncheart.pulsemight
293com.browserzheng.foundernews
294com.cardiac.pixel.panorama
295com.photoah.editorebrey
296com.peso.quicknet
297com.ground.mystory
298generate.bliss.note.blissnote
299com.systolic.scribe.bloodpressure
300com.card.pixelparser
301com.hidden.apps.disguised.spyware.detector
302com.capture.bp.cardio.blood.health
303artistic.wall.magic.background
304com.bfjk.terdpo.passmake
305com.phobi.lean.life
306com.health.pressurepilot
307convenient.text.count.textcount
308com.drain.lifelog
309com.pictureframe.magicdecloration
310com.kitty.echopages
311com.obsi.nrej.axle
312com.raisetgb.ptdowngrw.uplod.crcra
313com.jail.docuease
314com.bp.vitalsphygmo.healthy
315com.physical.index.bmi
316com.bikes.pdfvault
317com.covboe.vrsa.log
318com.hipainpainter.pipienter
319com.sip.psa
320com.servant.puresip
321com.insurance.glucopath
322com.beautiful.dayweather
323com.destinybook.storybook.wistom
324com.drorowsuaz.water
325com.handset.loctor.findphone
326com.rake.bodyscale
327com.cachesweep.clean
328com.fiveinarow.nicegame
329com.rate.massmbmi
330com.water.note.mate.fresh.leaf

Image: DIW-Aigen

Read next: Meta CEO Shares The Company’s Open AI Model Llama Hitting One Billion Downloads
Previous Post Next Post