New HiddenAds Malware on Google Play Store Uncovered

Risk:
high
Damage:
high
Platform(s):
Android OS Mobile Networks and Telephones
Advisory ID:
ngCERT-2022-0089
Version:
N/A
CVE:
N/A
Published:
August 8, 2022

Summary


A new type of malware has infiltrated the Google Play Store in the form of several device cleaner or optimization apps. The McAfee Mobile Research Team identified this malware as HiddenAds, and upon installation, it can run malicious services without the user opening the app. It also spams the user with irrelevant advertisements. The apps have received downloads ranging from 100,000 to over a million.

Description & Consequence


Some of the apps HiddenAds masquerades as are:

  1. Junk Cleaner
  2. EasyCleaner
  3. Power Doctor
  4. Carpet Clean
  5. Super Clean
  6. Meteor Clean
  7. Strong Clean
  8. Windy Clean
  9. Fingertip Cleaner
  10. Keep Clean
  11. Full Clean – Clean Cache
  12. Quick Cleaner
  13. Cool Clean

When a user installs any of the aforementioned apps, whether the user has opened the app or not, a malicious service is immediately installed on the device. The app will then attempt to blend into the app tray by changing its icon to the Google Play icon that every Android user is familiar with. Its name will also change to 'Google Play' or 'Setting'. The device will then be bombarded with ads in a variety of deceptive ways, severely impairing the user experience.

Successful installation will result in, among other things, the following:

  1. Device performance will suffer significantly.
  2. Clicking on the ads may result in stealth downloads/installation of other malware.
  3. Users may inadvertently subscribe to services and be billed on a monthly basis.
  4. The privacy of users will be jeopardized.

Solution


  1. Users should avoid downloading questionable apps or apps they are unsure about.
  2. Users who have installed any of the identified malicious apps should delete them right away. If the app's icon and name have changed, it can be identified by the fact that it is removable (the legitimate Google Play app cannot be uninstalled).
  3. Install anti-virus/anti-malware software with a proven track record for detecting and removing malware.

Reference


Revision


Related Articles