50 apps with SMS malware found in Play Store. See full app list here.

One of the biggest malware outbreaks on Android has just hit users through Google’s own Play Store.

The malware was found in at least 50 apps installed through Play which all carried a similar version of the malware. It is estimated that millions of devices were affected by the installs, according to Check Point Software.

“This was one of the most extensive malware campaigns to infiltrate Google Play Store, both in size and in its malicious effect,” Daniel Padon, an employee at Check Point.

Unlike most malware, which generates money from pop-up ads, this recent outbreak directly hit users in the pocket by auto-subscribing users to expensive SMS services. Each time a message was recieved from these services a fee was deducted from the user’s balance or charged to their monthly bill.

Malware experts named the malware “ExpensiveWall”, dubbed such due to one of the of the infected apps, “Lovely Wallpaper.” Other notable infected apps included “I Love Filter,” “Tool Box Pro,” and “Horoscope.”

The malware evaded Google’s security filters by using an advanced form of “packing,” which is a method that compresses and encrypts infected code.

Check Point notified Google, after which Google removed the offending apps from the Play Store. Immediately following this another version of the malware popped up and infected 5000 devices before Google took reign again.

[spoiler title=”List of known apps with the SMS malware”]

Package NameApp NameminmaxUploadedto Google Play
com.star.trekI Love Fliter1000000500000018/09/16
com.newac.toolboxTool Box Pro500000100000019/10/15
com.newac.wallpaperX WALLPAPER500000100000027/09/15
com.yeahmobi.horoscopeinterHoroscope500000100000016/03/15
com.gkt.xwallpaperX Wallpaper Pro500000100000002/06/15
com.gwqcv.zsfyBeautiful Camera10000050000011/05/17
com.hdsj.hdeyColor Camera10000050000016/03/17
com.lovephoto.gp.interLove Photo10000050000013/03/17
com.parrot.tidecmrTide Camera10000050000022/03/17
com.zerg.charmingcmrCharming Camera10000050000022/03/17
com.constellation.prophecyHoroscope10000050000030/06/16
com.desktoptools.screenunsubscribeDIY Your Screen10000050000021/07/16
com.gkt.ringtonegpRingtone10000050000002/06/15
com.gpthtwo.horoscopeดวง 12 ราศี Lite10000050000003/11/15
com.guard.defendSafe locker10000050000017/06/16
com.newac.wifiboosterWifi Booster10000050000004/11/15
com.newera.desktopCool Desktop10000050000030/06/16
com.newera.toolboxuseful cube10000050000012/06/16
com.pl.toolboxproTool Box Pro10000050000022/01/16
com.something.someoneUseful Desktop10000050000017/09/16
com.yeahmobi.horoscopeดวง 12 ราศี Lite10000050000020/28/2014
com.yeahmobi.horoscopegpadapHoroscope2.010000050000023/03/15
com.cegqz.uoudYes Star5000010000003/05/17
com.cmr.shinyShiny Camera5000010000003/05/17
com.johg.udradSimple Camera5000010000007/07/17
com.scamera.smilingSmiling Camera5000010000007/06/17
com.cmr.universalUniversal Camera5000010000016/05/17
com.gb.toolboxAmazing Toolbox5000010000023/03/16
com.genesis.awesomeEasy capture5000010000024/10/16
com.newera.memorydoctorMemory Doctor5000010000015/06/16
com.pl.toolboxTool Box Pro5000010000008/12/15
com.sexy.picReborn Beauty5000010000028/07/16
com.joy.photo.gp.interJoy Photo5000010000002/08/16
com.fancy.camera.gp.interFancy Camera5000010000009/08/16
com.amazing.photo.gp.interAmazing Photo5000010000013/09/16
com.amazing.camera.ggiAmazing Camera5000010000005/01/17
com.super.wallpaper.gp.interSuper Wallpaper5000010000030/08/16
com.aolw.maoaDD Player100005000013/03/17
com.bbapcmr.fascinatingFascinating Camera100005000013/04/17
com.coral.museUniversal Camera100005000013/07/17
com.cream.lecoaCream Camera100005000027/03/17
com.dmeq.oopesLooking Camera100005000023/05/17
com.dosl.wthreDD Weather100005000023/05/17
com.fqaf.dlkskGlobal Weather100005000003/05/17
com.ivxz.ykvlfLove Fitness100005000023/05/17
com.jpst.lsykPretty Pictures100005000006/04/17
com.kifb.mifvCool Wallpapers100005000010/01/17
com.magic.beautycmrBeauty Camera100005000004/04/17
com.opaly.nqibLove locker100005000012/05/17
com.real.starghReal Star100005000027/02/17
com.sadcmr.magicMagic Camera100005000014/06/17
com.scamera.wonderWonder Camera100005000014/06/17
com.scmr.funnyFunny Camera100005000002/06/17
com.simon.easyEasy Camera100005000028/02/17
com.smgft.keyboardSmart Keyboard100005000014/06/17
com.xnoc.jdvyTravel Camera100005000002/05/17
com.yiuw.fhlyPhoto Warp100005000020/01/17
com.yjmn.vokleLovely Wallpaper100005000007/07/17
com.ysyg.wtmcaLattice Camera100005000009/06/17
fast.bats.chazQuick Charger100005000008/05/17
com.upcamera.xgcbyUp Camera100005000018/01/17
com.photo.power.gpPhoto Power100005000023/11/16
com.asdf.fg.hdwallpaperHDwallpaper100005000013/12/16
com.gb.wonderfulgamesWonderful Games100005000009/04/16
com.gkt.fileexplorerBI File Manager100005000001/08/16
com.gkt.wallpapershdWallpapers HD100005000003/01/16
com.kevin.beautyvideoBeautiful Video-Edit your Memory100005000022/09/16
com.newera.beautifulphotoWonderful Cam100005000012/06/16
com.next.toolsetuseful cube100005000030/06/16
com.ringtone.freshacRingtone100005000026/11/15
com.gkt.gamebarExciting Games100005000015/09/15
com.replica.adventure.gpReplica Adventure100005000007/07/16
com.gg.player.gpGG Player100005000012/07/16
com.love.camera.gpLove Camera100005000020/10/16
com.oneshot.beautify.gpOneshot Beautify100005000001/08/16
com.pretty.camera.gpPretty Camera100005000018/10/16
com.hygk.hlhyCuteCamera50001000022/02/17
com.kkcamera.akbcartoonCartoon Camera-stylish, clean50001000008/03/17
com.craft.decorateArt Camera5000700013/08/17
com.amazing.video.gpAmazing Video50001000016/11/16
com.fine.photo.gpFine Photo50001000022/12/16
com.applocker.coldwarInfinity safe50001000009/09/16
com.final.horosopeMagical Horoscope50001000021/02/17
com.gp.toolboxcheToolbox50001000028/04/16
com.prettygirl.newyearCute Belle50001000012/01/17
com.roy.cartoonwallpaperCartoonWallpaper50001000006/09/16
com.thebell.newcenturyRingtone50001000001/08/16
com.aypx.ygzpBest Camera1000500016/02/17
com.colorful.lockerColorful Locker1000500009/05/17
com.hlux.wfshaLight Keyboard1000500021/07/17
com.ytkue.oprwSafe Privacy1000500007/06/17
com.qwer.enjoy.enjoywallpaperEnjoy Wallpaper1000500003/11/16
com.file.manager.gpFile Manager1000500013/12/16
com.highfirst.fancylockerFancy locker1000500005/01/17
com.cute.puzzle.gpCute Puzzle1000500005/10/16
com.keyboard.smileSmile Keyboard50070716/05/17
com.owexs.iouertVitality Camera10050004/07/17
com.tools.yidianLock Now10050023/01/17
com.camera.kfcfancyFancy Camera10050020/03/17
com.hhcamera.usefulUseful Camera10022406/03/17
com.owexs.iouertVitality Camera10022404/07/17
com.sec.transferSec Transfer10013614/03/17
com.tools.yidianLock Now10050023/01/17
com.bpmiddle.oneversionMagic Filter10022421/09/16
com.funny.video.gpFunny Video10050007/10/16
com.ads.wowgamesAmazing Gamebox10022422/05/16
com.wtns.superlockerSuper locker105025/04/17
com.musicg.ckiqpMusic Player1206/04/17
Total590451121101567
[/spoiler]

There were some red flags for the malware as users left reviews which reported the issue. However, it is notoriously difficult for Google to detect this form of reporting because of “app review wars,” where competing authors will pay review services to leave bad reviews on a competitor’s app.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *