Monday, March 3, 2025
HomeMalwareMalicious Code in Kids Game Apps on Google Play Pushing Porn Ads...

Malicious Code in Kids Game Apps on Google Play Pushing Porn Ads – More than 60 Game Apps Infected

Published on

SIEM as a Service

Follow Us on Google News

Cybercriminals started focussing on game apps which are used by children to install fake apps, registering premium services and porn ads.

Security researchers from checkpoint identified the malicious code dubbed “AdultSwine” hides into more than 60 game apps and they are downloaded between 3 million and 7 million times.

How does it Displaying  Porn Ads

The malicious apps targetting victims by displaying inappropriate pornographic ads, tricking to install fake security apps and premium subscriptions.

Once the malicious app is installed on the device, it waits for a boot to occur or for a user to unlock his screen, upon which it initiates its malicious activity, researchers said.

Also Read: A Man Used Fruitfly macOS Malware over 13 Years For Spying Thousand of Computers

Functions of Malicious Code

Displaying pornographic ads

Once the malicious app triggered it contacts the C&C server to report installation and provides the device details and it determines which ads to be displayed on which apps.

Then it verifies what are the apps running on the device, once all the conditions satisfied it will start showing inappropriate apps.

Tricking users to install security apps

It uses to scare use by displaying that your device “infected with a virus” and shows notification “Remove Virus Now” posing a fake virus remover app from the google play store. Even after Google play, crooks find some advanced sophisticated methods to add malicious apps to play store.

Forcing to register For Premium Services

Another technique is forcing users to register for fraudulent premium services charging victims credit account, it initially displays a popup add and attempts to convince the user to register for premium service.

It tricks “that user deserving to win an iPhone by answering short questions” and get the number from users and the ad itself register for premium services.

Common Defences and Mitigations

Researchers from Checkpoint notified to google and the affected apps removed now.

  • Give careful consideration to the permission asked for by applications.
  • Download applications from trusted sources.
  • Stay up with the latest version.
  • Encrypt your devices.
  • Make frequent backups of important data.
  • Install anti-malware on their devices.
  • Stay strict with CIA Cycle.
Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Threat Actors Exploiting AES Encryption for Stealthy Payload Protection

Cybersecurity researchers have uncovered a surge in the use of Advanced Encryption Standard (AES)...

33.3 Million Cyber Attacks Targeted Mobile Devices in 2024 as Threats Surge

Kaspersky's latest report on mobile malware evolution in 2024 reveals a significant increase in...

Routers Under Attack as Scanning Attacks on IoT and Networks Surge to Record Highs

In a concerning trend, the frequency of scanning attacks targeting Internet of Things (IoT)...

Google Launches Shielded Email to Keep Your Address Hidden from Apps

Google is rolling out a new privacy-focused feature called Shielded Email, designed to prevent apps...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Winos4.0 Malware Targets Windows Users Through Malicious PDF Files

A new wave of cyberattacks leveraging the Winos4.0 malware framework has targeted organizations in...

Lotus Blossom Hacker Group Uses Dropbox, Twitter, and Zimbra for C2 Communications

The Lotus Blossom hacker group, also known as Spring Dragon, Billbug, or Thrip, has...

Squidoor: Multi-Vector Malware Exploiting Outlook API, DNS & ICMP Tunneling for C2

A newly identified malware, dubbed "Squidoor," has emerged as a sophisticated threat targeting government,...