Skip to content

Secure IT

Stay Secure. Stay Informed.

Primary Menu
  • Home
  • Sources
    • Krebs On Security
    • Security Week
    • The Hacker News
    • Schneier On Security
  • Home
  • Security Week
  • 300 Malicious ‘Vapor’ Apps Hosted on Google Play Had 60 Million Downloads
  • Security Week

300 Malicious ‘Vapor’ Apps Hosted on Google Play Had 60 Million Downloads

Ionut Arghire March 20, 2025
0

Security researchers have uncovered an extensive ad fraud scheme relying on hundreds of malicious Android applications hosted on Google Play that amassed over 60 million downloads.

Dubbed Vapor, the campaign was initially flagged by IAS Threat Lab, which identified 180 malicious apps on Google Play designed to “deploy endless, intrusive full-screen interstitial video ads”.

Masquerading as utility, health and fitness, and lifestyle applications, Vapor software infiltrated victims’ devices without raising suspicion: functional when submitted to Google Play, the applications were later updated to generate ad revenue.

The updates, IAS explains in a report (PDF), completely removed the applications’ functionality, hid their icons from the app drawer, and also hid all visible UI elements.

“With the app fully set up, it immediately attempts to barrage the user with full-screen interstitial ads, effectively hijacking the device’s screen and rendering the user’s device largely inoperative,” IAS notes.

The over 180 app IDs identified in Google Play amassed more than 56 million downloads since the beginning of 2024, with significant spikes observed in the third quarter of the year and between November 2024 and January 2025.

According to Bitdefender, however, the number of malicious applications pushed to Google Play as part of the scheme is almost double, at 331, while their combined download count has surpassed 60 million.

In addition to displaying fraudulent ads, the apps engaged in other malicious behavior, such as attempting to collect user credentials and credit card data via phishing.

Advertisement. Scroll to continue reading.

The applications were designed to bypass protections in some of the latest Android iterations, performing restricted actions such as hiding their icons from the launcher, displaying out-of-context ads over other software, and being able to start without user interaction.

Some of the analyzed applications were using a launcher designed for Android TV, and could disable or enable their icon without restriction, while others could hide themselves from the Settings menu, to avoid being removed.

Most of the applications identified by Bitdefender first became available on Google Play between August 2024 and January 2025, while the most recent ones were published in early March 2025.

“To be clear, this is an active campaign. The latest malware published in the Google Play Store went live in the first week of March, 2025. When we finished the investigation, a week later, 15 applications were still available for download on Google Play,” Bitdefender says.

The cybersecurity firm also noticed that the applications can display ads on the foreground without being started, that they could also display custom messages, such as prompts for user credentials, and that they used custom, dedicated command-and-control (C&C) domains.

Both IAS and Bitdefender reported their findings on the Vapor operation to Google, which removed the offending applications from Google Play.

“All of the identified apps from these reports have been removed from Google Play. Android users are also automatically protected by Google Play Protect, which is on by default on Android devices with Google Play Services,” a Google spokesperson told SecurityWeek.

Related: North Korean Hackers Distributed Android Spyware via Google Play

Related: Necro Trojan Infects Google Play Apps With Millions of Downloads

Related: VPN Apps on Google Play Turn Android Devices Into Proxies

Related: Spyware Found in Google Play Apps With Over 420 Million Downloads

About The Author

Ionut Arghire

See author's posts

Original post here

Continue Reading

Previous: Why Continuous Compliance Monitoring Is Essential For IT Managed Service Providers
Next: Six Governments Likely Use Israeli Paragon Spyware to Hack IM Apps and Harvest Data

Trending Now

Hackers Use TikTok Videos to Distribute Vidar and StealC Malware via ClickFix Technique cc.jpg 1

Hackers Use TikTok Videos to Distribute Vidar and StealC Malware via ClickFix Technique

May 23, 2025
ViciousTrap Uses Cisco Flaw to Build Global Honeypot from 5,300 Compromised Devices mm.jpg 2

ViciousTrap Uses Cisco Flaw to Build Global Honeypot from 5,300 Compromised Devices

May 23, 2025
300 Servers and €3.5M Seized as Europol Strikes Ransomware Networks Worldwide ransomware.jpg 3

300 Servers and €3.5M Seized as Europol Strikes Ransomware Networks Worldwide

May 23, 2025
SafeLine WAF: Open Source Web Application Firewall with Zero-Day Detection and Bot Protection safeline.jpg 4

SafeLine WAF: Open Source Web Application Firewall with Zero-Day Detection and Bot Protection

May 23, 2025
U.S. Dismantles DanaBot Malware Network, Charges 16 in $50M Global Cybercrime Operation botnet.jpg 5

U.S. Dismantles DanaBot Malware Network, Charges 16 in $50M Global Cybercrime Operation

May 23, 2025
CISA Warns of Suspected Broader SaaS Attacks Exploiting App Secrets and Cloud Misconfigs saas.jpg 6

CISA Warns of Suspected Broader SaaS Attacks Exploiting App Secrets and Cloud Misconfigs

May 23, 2025

Related Stories

Cybersecurity_News-SecurityWeek.jpg
  • Security Week

Insurance Firm Lemonade Says API Glitch Exposed Some Driver’s License Numbers

Ionut Arghire April 15, 2025 0
ransomware.jpeg
  • Security Week

Kidney Dialysis Services Provider DaVita Hit by Ransomware

Ionut Arghire April 15, 2025 0
Cybersecurity_News-SecurityWeek.jpg
  • Security Week

Conduent Says Names, Social Security Numbers Stolen in Cyberattack

Ionut Arghire April 15, 2025 0
Cybersecurity_News-SecurityWeek.jpg
  • Security Week

2.6 Million Impacted by Landmark Admin, Young Consulting Data Breaches

Ionut Arghire April 15, 2025 0
VC-Funding_China-tech.jpg
  • Security Week

China Pursuing 3 Alleged US Operatives Over Cyberattacks During Asian Games

Associated Press April 15, 2025 0
Satellite-Link-Cybersecurity.jpg
  • Security Week

Blockchain, Quantum, and IoT Firms Unite to Secure Satellite Communications Against Quantum Threats

Kevin Townsend April 15, 2025 0

Connect with Us

Social menu is not set. You need to create menu and assign it to Social Menu on Menu Settings.

Trending News

Hackers Use TikTok Videos to Distribute Vidar and StealC Malware via ClickFix Technique cc.jpg 1
  • The Hacker News

Hackers Use TikTok Videos to Distribute Vidar and StealC Malware via ClickFix Technique

May 23, 2025
ViciousTrap Uses Cisco Flaw to Build Global Honeypot from 5,300 Compromised Devices mm.jpg 2
  • The Hacker News

ViciousTrap Uses Cisco Flaw to Build Global Honeypot from 5,300 Compromised Devices

May 23, 2025
300 Servers and €3.5M Seized as Europol Strikes Ransomware Networks Worldwide ransomware.jpg 3
  • The Hacker News

300 Servers and €3.5M Seized as Europol Strikes Ransomware Networks Worldwide

May 23, 2025
SafeLine WAF: Open Source Web Application Firewall with Zero-Day Detection and Bot Protection safeline.jpg 4
  • The Hacker News

SafeLine WAF: Open Source Web Application Firewall with Zero-Day Detection and Bot Protection

May 23, 2025
U.S. Dismantles DanaBot Malware Network, Charges 16 in $50M Global Cybercrime Operation botnet.jpg 5
  • The Hacker News

U.S. Dismantles DanaBot Malware Network, Charges 16 in $50M Global Cybercrime Operation

May 23, 2025
CISA Warns of Suspected Broader SaaS Attacks Exploiting App Secrets and Cloud Misconfigs saas.jpg 6
  • The Hacker News

CISA Warns of Suspected Broader SaaS Attacks Exploiting App Secrets and Cloud Misconfigs

May 23, 2025
GitLab Duo Vulnerability Enabled Attackers to Hijack AI Responses with Hidden Prompts prompt.jpg 7
  • The Hacker News

GitLab Duo Vulnerability Enabled Attackers to Hijack AI Responses with Hidden Prompts

May 23, 2025

You may have missed

cc.jpg
  • The Hacker News

Hackers Use TikTok Videos to Distribute Vidar and StealC Malware via ClickFix Technique

[email protected] The Hacker News May 23, 2025 0
mm.jpg
  • The Hacker News

ViciousTrap Uses Cisco Flaw to Build Global Honeypot from 5,300 Compromised Devices

[email protected] The Hacker News May 23, 2025 0
ransomware.jpg
  • The Hacker News

300 Servers and €3.5M Seized as Europol Strikes Ransomware Networks Worldwide

[email protected] The Hacker News May 23, 2025 0
safeline.jpg
  • The Hacker News

SafeLine WAF: Open Source Web Application Firewall with Zero-Day Detection and Bot Protection

[email protected] The Hacker News May 23, 2025 0
Copyright © 2025 All rights reserved. | MoreNews by AF themes.