Is the Google Play Store Safe? Not Yet.

By : Krishna Anindyo | Tuesday, February 25 2020 - 13:05 IWST

Google Play Store (Images by Brands of the World)
Google Play Store (Images by Brands of the World)

INDUSTRY.co.id - Over recent years, there has been a lot of activity on Google’s part to improve the security of its Google Play app store. Why? Because millions of users have inadvertently downloaded thousands of malicious applications from the store which have compromised their data including SMS, credentials, photos, calendars appointments, and emails.

For example, in March 2019, the ‘SimBad’ adware was found in over 200 apps on the store, with a combined download count of nearly 150 million.  

Since the formal formation of the alliance, over 5.2 million installations of malicious apps took place, spanning dozens of different campaigns of four different types of malware. These malware families have a range of capabilities from the ability to steal all information from the device, to taking over the device by popping up advertisements or overlay windows as a form of a phishing attack.

These apps also use a variety of techniques to avoid detection by the alliance’s security teams, including code obfuscation and delayed downloads of malicious payloads. 

One of these campaigns has been uncovered by Check Point researchers. The Haken malware family was installed on over 50,000 Android devices by eight different malicious apps which all appeared to be benign. The apps were mostly camera utilities and children’s games  the apps were Kids Colouring, Compass, QR code, Fruits colouring book, soccer colouring book, fruit jump tower, ball number shooter & Inongdan.

The malware is classified as a “clicker” because of its ability to take control of the user device and click on anything that may appear on the device’s screen. It is important to note that malware can access any type of data, so anything visible on-screen is fair game Hello, work emails!, and any locally stored data.

The impact on users is two-fold:  it can sign them up for premium subscription services without the user realising, earning money illegally for the people behind the app. It could also exfiltrate sensitive data from the user’s device. The good news is, these rogue applications have all been removed from Google Play.

But this does highlight that despite ongoing efforts to secure the Google Play Store against malicious apps, completely eliminating the risk of users getting a malicious download from the store is not going to happen quickly. There are nearly 3 million apps available from the store, with hundreds of new apps being uploaded daily – which makes it difficult to check every single app is safe.

Some app developers have devised ingenious methods to conceal their apps' true intent from Google’s scrutiny. Coupled with a fragmented Android ecosystem, in which a large number of device manufacturers infrequently offer critical OS updates, users cannot rely on Google Play’s security measures alone to ensure their devices are protected. 

They need to deploy security software to ward off malware and other threats, and protect the corporate and personal data on those devices. The security solution has to truly understand malicious behaviour which means it must use numerous advanced techniques that go beyond just signatures or machine-learning based on static indicators.

News Comment

Today's Industry

Wellington College Independent School Jakarta (WCIJ)

Senin, 29 April 2024 - 05:02 WIB

One of the UK’s Most Established Schools Chooses Jakarta for Their Latest Opening

Wellington College Independent School Jakarta (WCIJ) is thrilled to announce its grand opening in September 2024! As the first private UK school to open in Indonesia, WCIJ, a pioneering co-educational…

Presiden Jokowi

Selasa, 23 April 2024 - 10:29 WIB

President Jokowi Reaffirms Commitment to Farmers’ Welfare

President Joko “Jokowi” Widodo on Monday (04/22) inspected corn harvest in Boalemo regency, Gorontalo province. “Our corn import has decreased significantly from 3.5 million tonnes to…

Photo: Aris Nurjani/VOI

Rabu, 28 Februari 2024 - 12:47 WIB

Carsurin and NBRI Strengthen Strategic Alliance to Propel Indonesia’s EV Industry

PT Carsurin Tbk ("Carsurin") and the National Battery Research Institute ("NBRI") are pleased to announce the signing of a pivotal Strategic Alliance Agreement (SAA), marking a significant advancement…

Beras (Foto/Rizki Meirino)

Rabu, 21 Februari 2024 - 08:43 WIB

Gov’t to Continue Disbursing Rice Assistance

President Joko “Jokowi” Widodo has ensured that the Government will continue rolling out the rice assistance program for low-income families. The President made the statement when handing…

Ilustrasi pabrik beras. (Foto: DetikFood)

Rabu, 21 Februari 2024 - 08:40 WIB

Bapanas Head Ensures Availability of Rice Stock Ahead of Ramadan

The National Food Agency (Bapanas) has ensured the availability of rice for the fasting month of Ramadan and Eid al-Fitr 1445 Hijri/2024 CE. “We believe that there is enough rice for the fasting…