Skip to main content

Google removes 13 malware-infested apps from Play Store

google play store changes android phone smartphone smart generic symbol
Image used with permission by copyright holder
Google has removed 13 malware-ridden apps from the Play Store earlier today, after finding malicious code able to auto-review and seek root privileges on the smartphone.

The code is from the malware family Brain Test, responsible for Shedun, Shuanet, and Shiftybug, according to security firm Lookout. This type of malware has been spotted outside of Google Play before, on third-party app sites. The difference this time is these 13 apps managed to sneak onto the store, making them much more dangerous to the average Android user.

The 13 apps include:

  • Cake Blast
  • Jump Planet
  • Honey Comb
  • Crazy Block
  • Crazy Jelly
  • Tiny Puzzle
  • Ninja Hook
  • Piggy Jump
  • Just Fire
  • Eat Bubble
  • Hit Planet
  • Cake Tower
  • Drag Box

All the apps are games, and targeted at a young audience. If you have them installed, delete them now.

Millions of people have apparently downloaded the apps, but there are still one or two jumps for the malware to make before it can gain root privileges. That means some users might be safe, despite downloading the app.

Google has not said how it missed the malware-ridden apps. In past cases, the developer adds the malware through an update, or hides it inside a legitimate folder or piece of code.

If the malware has gained access to root privileges, the consequences could be dire. Once an infestation gains access to the main controls, it can tamper with all sorts of functionality on the device, including screen watching and tracking keystrokes.

There is ways to remove the malware, including a root explorer or re-flash a manufacturer ROM. That might sound like mumbo jumbo for a non-techie, but there are guides on how to do this — you can also contact your device manufacturer or carrier if you’re really worried.

David Curry
Former Digital Trends Contributor
David has been writing about technology for several years, following the latest trends and covering the largest events. He is…
If you have one of these apps on your Android phone, delete it immediately
The app drawer on the Google Pixel 8 Pro.

The NSO Group raised security alarms this week, and once again, it’s the devastatingly powerful Pegasus malware that was deployed in Jordan to spy on journalists and activists. While that’s a high-profile case that entailed Apple filing a lawsuit against NSO Group, there’s a whole world of seemingly innocuous Android apps that are harvesting sensitive data from an average person’s phone.
The security experts at ESET have spotted at least 12 Android apps, most of which are disguised as chat apps, that actually plant a Trojan on the phone and then steal details such as call logs and messages, remotely gain control of the camera, and even extract chat details from end-to-end encrypted platforms such as WhatsApp.
The apps in question are YohooTalk, TikTalk, Privee Talk, MeetMe, Nidus, GlowChat, Let’s Chat, Quick Chat, Rafaqat, Chit Chat, Hello Chat, and Wave Chat. Needless to say, if you have any of these apps installed on your devices, delete them immediately.
Notably, six of these apps were available on the Google Play Store, raising the risk stakes as users flock here, putting their faith in the security protocols put in place by Google. A remote access trojan (RAT) named Vajra Spy is at the center of these app's espionage activities.

A chat app doing serious damage

Read more
Google just redesigned one of its biggest apps, and it’s bad
Google Chat app on the Play Store.

Google Chat — Google's business-oriented messaging platform that is similar to Slack and Microsoft Teams — just got a big update for its Android and iOS apps. The update dramatically changes how you navigate the app and, uh, well, it sure is something.

Google Chat's mobile app used to be broken up into two pages: Chat (direct messages between you and other users) and Spaces (larger chat rooms for multiple people). As with most apps, you switched between these with a navigation bar at the bottom of your screen.

Read more
Google is killing your passwords, and security experts are (mostly) happy
Logging into a Google account with passkeys on an iPhone.

Google is inching closer to making passwords obsolete. The solution is called "Passkeys," a unique form of password that is stored locally on your phone or PC, just the way a physical security key works. The passkeys are protected behind a layer of authentication, which can be your fingerprint or face scan — or just an on-screen pattern or PIN.

Passkeys are faster, linked across platforms, and save you the hassle of remembering passwords for websites or services that you have subscribed to. There is a smaller scope for human error, and the risks of 2-factor authentication code interception are also reduced.

Read more