Tuesday, November 19, 2024
HomeSecurity NewsAndroid Users Beware - Hundreds of Faking Popularity Apps Discovered on Google...

Android Users Beware – Hundreds of Faking Popularity Apps Discovered on Google Play

Published on

Tricksters found a new way to boost the popularity of newly uploaded apps by setting the number of installs as their developer names.

When browsing for apps the user seems the user can see three elements app icon, app name and the developer name, tricksters changing the developer’s name to a number of installs to boost the popularity of the apps.

ESET has spotted hundreds of such Faking Popularity apps on Google Play that misleading users about the functionality and most of the apps contain only the advertisements.

The freedom to set any choice of the developer name has been abused by tricksters to set the fake number of downloads as the developer name that appears trustworthy to users.

- Advertisement - SIEM as a Service
Faking Popularity

ESET spotted a “developer change his name from a fake installation number to an actual developer name over time, which might indicate the trick is used as a temporary measure aimed at boosting the popularity of newly uploaded apps.”

Some app developers use phrases like “Legit Apps”, “Verified Applications”, “Trusted Developers App”, checkmark symbol for boosting the popularity of newly uploaded apps.

The trick is very simple but it will mislead users who download apps based on the popularity and it could be used by misused by malware authors in the future.

Google has developed new detection models and techniques that can identify repeat offenders and abusive developer networks at scale.

In the year 2017 Google blocked nearly 700,000 Malicious Apps that violated Google Play Store policies based on the following categories Copycats, Inappropriate content and Potentially Harmful Applications (PHAs).

Users should check for the official number’s of downloads on Google play store and the Google play doesn’t offer verification badge for apps.

Also Read

DNS Hijacking Method Used by Powerful Malware to Hack Android, Desktop & iOS Devices

Android Gamers Beware of Fake Fortnite Game that Contains Spyware and Cryptocurrency

MinerMaikspy – A Spyware Attack on Windows & Android Users via Adult Games

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Zohocorp ManageEngine ADAudit Plus SQL Injection Vulnerability

Zohocorp, the company behind ManageEngine, has released a security update addressing a critical SQL...

Citrix Virtual Apps & Desktops Zero-Day Vulnerability Exploited in the Wild

A critical new vulnerability has been discovered in Citrix’s Virtual Apps and Desktops solution,...

Sonatype Nexus Repository Manager Hit by RCE & XSS Vulnerability

Sonatype, the company behind the popular Nexus Repository Manager, has issued security advisories addressing...

GeoVision 0-Day Vulnerability Exploited in the Wild

Cybersecurity researchers have detected the active exploitation of a zero-day vulnerability in GeoVision devices,...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Critical PDF.js & React-PDF Vulnerabilities Threaten Millions Of PDF Users

A new critical vulnerability has been discovered in PDF.js, which could allow a threat...

LayerX Security Raises $26M for its Browser Security Platform, Enabling Employees to Work Securely From Any Browser, Anywhere

LayerX, pioneer of the LayerX Browser Security platform, today announced $24 million in Series...

Email Header Analysis – Verify Received Email is Genuine or Spoofed

Email Header Analysis highly required process to prevent malicious threats since Email is...