Thursday, May 1, 2025
HomeMalwareHackers Abuse Microsoft Store & Publish Fake Google Photos App under Google...

Hackers Abuse Microsoft Store & Publish Fake Google Photos App under Google LLC Name

Published on

SIEM as a Service

Follow Us on Google News

Third-party developers abusing Microsoft Apps store & publish fake Google Photos App under the Google LLC name but it is originally an Ad clicker which is running in the back round of the windows system.

It’s a completely malicious app that performs various unwanted actvities once installed on the victim’s machine.

It Seems developers managed to trick Microsoft’s certification and published the app as “Album by Google Photos” under the  Google LLC name in Windows Store.

- Advertisement - Google News

Also, the review which is given by users told that the app performed various malicious actions and trying to install malware, keep popup the various unwanted advertisements.

Fake Google Photos App Malicious Actvities

Lawrence analyzed this App and said, When a user starts the Album by Google Photos app they will be greeted by a screen asking them to login to Google Photos. This is a legitimate login screen from Google and though I did not see any indications that your logins are being stolen, I would still not advise logging into Google Photos with this app.

According to geeklatest, There are some main reasons prove this Fake Google Photos App is a completely malicious app.

  • Album by G Photos is not available for Android.
  • Published by Google LLC while the official publisher is Google Inc.
  • The app was published in May 2018 and Google hasn’t confirmed it anywhere.
  • The resource bundled with the app is Google Photos logo, rest all are accessed via the web.

The malicious advertisement displays by this fake app similar to the tech support scam that leads to compromise user and the attacker trying to gain access to the victim’s computer using various social engineering technique.

Also, it contains various ad banner and trying to connect with some URLs and it was unclear that how it passed to Microsoft anti-abuse check with the name under Google LLC.

Users need to aware about that “Google Inc” is the official Google publisher on the Microsoft Store so any apps published by Google LLC or similar name is fake

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Netgear EX6200 Flaw Enables Remote Access and Data Theft

Security researchers have disclosed three critical vulnerabilities in the Netgear EX6200 Wi-Fi range extender...

Tesla Model 3 VCSEC Vulnerability Lets Hackers Run Arbitrary Code

A high security flaw in Tesla’s Model 3 vehicles, disclosed at the 2025 Pwn2Own...

Quantum Computing and Cybersecurity – What CISOs Need to Know Now

As quantum computing transitions from theoretical research to practical application, Chief Information Security Officers...

Apache ActiveMQ Vulnerability Lets Remote Hackers Execute Arbitrary Code

A high vulnerability in Apache ActiveMQ’s .NET Message Service (NMS) library has been uncovered,...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

New WordPress Malware Disguised as Anti-Malware Plugin Takes Full Control of Websites

The Wordfence Threat Intelligence team has identified a new strain of WordPress malware that...

Konni APT Deploys Multi-Stage Malware in Targeted Organizational Attacks

A sophisticated multi-stage malware campaign, potentially orchestrated by the North Korean Konni Advanced Persistent...

Outlaw Cybergang Launches Global Attacks on Linux Environments with New Malware

The Outlaw cybergang, also known as “Dota,” has intensified its global assault on Linux...