Google Play Store and Apple Store adware downloaded millions of times


Almost a hundred apps across the Android (opens in new tab) and iOS ecosystems have been discovered engaging in advertising fraud, researchers have claimed.
The apps, 80 of which were built for Android, and nine for iOS, have more than 13 million downloads between them, and include games, screensavers, camera apps, and more – some with more than a million downloads.
Research (opens in new tab) from cybersecurity firm HUMAN Security found that by targeting advertising software development kits (SDK), the unknown threat actors were able to compromise these apps for their own personal benefit, in multiple ways: by pretending to be apps they’re not; by rendering ads in places where users wouldn’t be able to see them; and by faking clicks and taps (keeping track of real ad interactions and faking them later).
Evolution of Poseidon
The campaign, which HUMAN dubbed Scylla, is still ongoing, meaning at least some of the apps are still up and running. “These tactics, combined with the obfuscation techniques first observed in the Charybdis operation, demonstrate the increased sophistication of the threat actors behind Scylla,” the researchers say.
The Charybdis operation the researchers mention is an older campaign, out of which Scylla evolved. Charybdis itself evolved from an even older campaign, called Poseidon, leading the researchers to conclude that the threat actors are actively developing these apps and that new variants are bound to appear.
HUMAN says it “worked closely” with both Google and Apple to have all of the identified malicious (opens in new tab) apps removed from the respective app repositories.
However, that doesn’t mean the threat is completely gone – users who have downloaded these apps in the meantime are still vulnerable, and will remain so until they remove them from their endpoints.
The company urges users to go through the entire list of apps found here (opens in new tab) and make sure they remove any apps they might have installed.
Audio player loading… Almost a hundred apps across the Android (opens in new tab) and iOS ecosystems have been discovered engaging in advertising fraud, researchers have claimed. The apps, 80 of which were built for Android, and nine for iOS, have more than 13 million downloads between them, and include…
Recent Posts
- NYT Wordle today — answer and my hints for game #1479, Monday, July 7
- Playdate Season 2 review: Taria & Como and Black Hole Havoc
- 3 features that would actually make me pay for a Samsung Health subscription for my Galaxy Watch – and one big problem it needs to avoid
- 250-million pixel virtual projector sets world record on 280-meter tall building used as a screen
- TikTok’s ‘ban’ problem could end soon with a new app and a sale
Archives
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022