Skip to main content

Security firm identifies over 100 malware-infected Android apps, but don't panic

Mobile Malware
Image used with permission by copyright holder
While many users are more aware of the threat of mobile malware today than in years past, and Google has made significant strides in protecting phones from those toxic apps, the risk never completely goes away. Vulnerabilities can present in the unlikeliest of ways, as this report from security firm Palo Alto Networks explains.

The company cites 132 apps on the Google Play Store that feature malware — though not the kind that could actually do any harm to your smartphone. The reason being, these apps attempt to install a Windows executable file, which Android devices do not support.

At first glance, it appears to be a completely ineffectual attempt at attacking users, until you consider the possibility that these apps were actually infected with malicious code unbeknownst to the developer. The malware exploits the apps’ use of Android WebView to link to dangerous HTML sites, that then attempt to install a file designed for Windows onto the device. Palo Alto goes into greater detail, identifying specific lines of code that act as the culprits, but the important point to note is that none of it could actually compromise your phone in any way.

On Windows, the malware would reportedly modify firewall settings, alter the network hosts file, and copy and inject itself into numerous other processes. The apps in question span seven different developers, and security analysts speculate it may have arrived on Android by way of a file-infecting virus. These viruses would in turn seek out and infect HTML files on the developers’ computers, and it’s not hard to imagine how they could then spread to software published on the Play Store. A common online development platform used to produce all of the affected apps may have been the origin.

Ultimately, Google would classify this as a “non-Android threat” — terminology for applications that are unable to harm a user’s device, but are potentially damaging to other platforms. After reporting its findings to Google, Palo Alto says all the offenders were removed from the Play Store.

While it’s not terribly comforting to know your device may have been a conduit for malware without ever realizing it, the work done by Google and security firms like Palo Alto does shed some light on the multitude of ways in which a virus can spread — and that will, in turn, make our devices safer.

Editors' Recommendations

Adam Ismail
Former Digital Trends Contributor
Adam’s obsession with tech began at a young age, with a Sega Dreamcast – and he’s been hooked ever since. Previously…
Google Play Store feature suggests unused apps to uninstall from Android phones
Google Play store on a smartphone in someone's hand.

A new Google Play Store feature is suggesting a list of unused apps that people may want to uninstall from their Android devices to free up some space.

Downloading and installing apps to Android smartphones through the Google Play Store is easy, so it is understandable if people accumulate apps that they do not regularly use.

Read more
The Rabbit R1 is hiding a big secret
The Rabbit R1 standing upright on a wooden railing with its display turned on.

“This is supposed to be a simpler companion to my phone, yet the R1 often tells me to use my phone when asking it to do the most basic of tasks,” wrote Digital Trends’ Section Editor Joe Maring after taking the Rabbit R1 out for a spin. The biggest flaw here is not a slow interface or lack of functions, but what it adds to an average user's life on a day-to-day basis.

At this stage, it's not much, primarily because a budget Android phone can do the same tasks with apps — be it AI chores like summarizing an email chain or ordering a burger. "This could've been an AI app at best." That's a recurring theme in the online forums about the R1. And it seems the R1 itself proves that point.
The Rabbit R1's Android secret

Read more
How to turn off Activity Status on Instagram
Instagram on an iPhone.

Instagram is a popular social networking site that allows users to communicate through text, photos, and videos. One of its features is the app's Activity Status, which lets users know when someone was last active on the app or if they are currently online.

Read more