Skip to main content

A fake ‘Pokémon Go’ app tricked half a million players into downloading malware

The rapid speed at which Pokémon Go became a global phenomenon made it inevitable that the wildly popular smartphone game would quickly catch the attention of hackers, too.

When Pokémon Go launched in July, it was only available in a few countries, a situation that prompted many of those desperate to try the game to turn to third-party download sites. But some of those Pokémon Go downloads had been injected with malware that allowed hackers to take control of the victim’s smartphone.

Now that most countries’ smartphone users have access to the genuine version of the game through mainstream mobile app stores, the malware-infected versions of Pokémon Go have faded away. Security researchers have, however, found a new problem: hacker-designed apps linked to the game.

Cybersecurity firm Kaspersky Lab has found at least one malware-infected Android app, called Guide for Pokémon Go (shown below), that it says has been downloaded more than half a million times.

guide-to-pokemon-go
Image used with permission by copyright holder

Available until recently on the Google Play store, the free app, as its name suggests, explains the augmented-reality game to newcomers and offers tips and tricks on how to become a skilled trainer. But it also contains malware that enables a hacker to take control of the phone.

“Analysis reveals that the app contains a malicious piece of code that downloads rooting malware – malware capable of gaining access to the core Android operating system,” Kaspersky Labs’ Roman Unuchek wrote in a blog post on Wednesday, adding there had so far been “at least 6,000 successful infections.”

The researcher said that while most infections appear to have hit smartphone users in Russia, India, and Indonesia, the fact that the app is in English suggests others users around the world may also be affected.

According to Kaspersky Lab’s Kate Kochetkova, the malware doesn’t immediately activate, though when it does it’ll flood the phone with ads. But worse than that, it can also secretly install additional apps.

“For now, criminals have chosen a relatively mild way to earn money: ads,” Kochetkova said. “Tomorrow, they may decide to increase their income by locking your device and demanding ransom – or stealing money from your bank account.”

For anyone who has the Guide to Pokémon Go app (there are others with the same name but this one is made by an outfit calling itself “Markersel”), Kaspersky Lab suggests immediately deleting it and then running free scanning software to confirm if your device has been infected.

Editors' Recommendations

Trevor Mogg
Contributing Editor
Not so many moons ago, Trevor moved from one tea-loving island nation that drives on the left (Britain) to another (Japan)…
Google Play Store malware hits 42 apps with 8 million downloads
Android Logo

Another day, another batch of Play Store apps found to contain malware.

This time, the 42 adware-infected apps received 8 million downloads in a campaign that lasted more than a year.

Read more
Volgarr the Viking 2 will take you back to your Ghosts ‘n Goblins days
A viking slashes a tree in Volgarr the Viking 2.

Developer Digital Eclipse is working on a surprising project: Volgarr the Viking 2. The 2D retro sequel will launch on August 6 for PlayStation 4, PS5, Xbox One, Xbox Series X/S, Nintendo Switch, and PC.

The news is an out of left field reveal. The first Volgarr the Viking game released in 2013 and was made as an ode to 1080s classics like Ghosts 'n Goblins. Despite being a small release, it sold over 1 million copies over the past decade. As revealed during today's Guerrilla Collective stream, the series is coming back with a new sequel by Digital Eclipse, the team behind this year's Llamasoft: The Jeff Minter Story.

Read more
3 Days of Play PS Plus games to try this weekend (June 7-9)
Key art for Streets of Rage 4.

June 2024 is shaping up to be a pretty great month for PlayStation players. Not only are we coming off an entertaining State of Play showcase, but a new Days of Play initiative surrounding all the video game showcases this month is bringing a lot of new PS Plus additions with it. Many of those games hit PS Plus this week, and three in particular stand out to us.

For owners of Sony's oft-neglected PlayStation VR2, the first game is one of its rare exclusives that take full advantage of the headset's eye-tracking by seeing how often players blink. The next is a new PS Plus Essential game that's a revival of Sega's classic beat-'em-up series for the modern gaming era. Finally, the last title is an atmospheric and eerie fishing game that should entice fans of Lovecraftian horror.
Before Your Eyes

Read more