Connect with us

Apps

A bunch of racing games on the Google Play store were actually just malware

The games had been downloaded over 500,000 times before anything was done.

google play malware games
Image: Twitter (@LukasStefanko)
Giveaway: Enter to win a BLUETTI Charger 1 ($399 value): Enter Here

Just a heads up, if you buy something through our links, we may get a small share of the sale. It’s one of the ways we keep the lights on here. Click here for more.

If you’ve recently installed a driving game from Google Play, you might be in the over 500,000 users that downloaded malware from Google’s app store.

On Monday, Lukas Stefanko who works at ESET as a security researcher tweeted out details of 13 gaming apps infected with malware on the Google Play store. All of the apps were posing as driving games, and all were from the same developer. Two of the apps were trending in the store, which meant more visibility for unsuspecting users.

Over 580,000 installs of the malicious apps took place before Google yanked them from the storefront.

More info about the games and malware

The games all looked like an innocuous truck or car driving game to anyone browsing them in the store. Once downloaded, expectations were dashed with what looks like a buggy app that crashed every time it was opened.

That’s not what was happening, however, with the app downloading a payload from another domain and installing malware on the user’s phone. Then the app deleted its own icon, hiding it from view.

What was the purpose of these malicious apps?

It’s not yet clear what the malicious app was meant to do, with the malware scanners on VirusTotal not agreeing on what the apps are actually infected with. We do know that the app has persistence, which means it will launch every time the Android device is started and has full access to the device’s network traffic, which means the malware author can steal secrets.

Google spokesperson Scott Westover confirmed to TechCrunch that the apps “violated our policies and have been removed from the Play Store.”

In a week where Tumblr had their official app removed from the iOS App Store, it’s clear that Google needs to step up their security efforts on apps the company allows into the Google Play store. Over 700,000 malicious apps were pulled by Google last year alone and that issue shows no sign of slowing down.

Did you download one of these games? Any issues? Let us know down below in the comments or carry the discussion over to our Twitter or Facebook.

Editors’ Recommendations:

Follow us on Flipboard, Google News, or Apple News

Maker, meme-r, and unabashed geek with nearly half a decade of blogging experience at KnowTechie, SlashGear and XDA Developers. If it runs on electricity (or even if it doesn't), Joe probably has one around his office somewhere, with particular focus in gadgetry and handheld gaming. Shoot him an email at joe@knowtechie.com.

Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

More in Apps