Tens of thousands of malicious Android apps flooding user devices

(Image credit: Shutterstock / quietbits)

Tens of thousands of dangerous Android apps are putting mobile users at heightened risk of fraud and cyberattack, a report has claimed. 

Mobile security firm Upstream identified over 29,000 malicious Android apps in active use during Q1 2020, double the number logged in the same quarter last year (just over 14,500).

The investigation also showed that almost all (90%) of the ten most malicious apps were - or are still - present on the official Google Play Store. This suggests, according to Upstream, that hackers consistently found ways to dance their way through Google’s vetting system.

In line with this trend, this time period also saw a 55% rise in fraudulent transactions on Android platforms, as well as a spike in the number of malware-infected devices.

Malicious Android apps

The dramatic rise in the number of malicious Android apps in circulation has been put down to the effects of the coronavirus pandemic on the way users consume content and utilise mobile platforms.

According to Geoffrey Cleaves, who leads Upstream’s anti-fraud offering, the rise in dangerous apps correlates directly with the introduction of coronavirus lockdown measures.

“With the majority of the world having shifted indoors, there were some darker forces acting to make a profit from the lockdown situation,” he explained.

“We’ve seen a sharp increase in bad actors publishing ‘leisure’ apps on the Google Play Store, which trick users into subscribing for premium services.”

The firm claims six of the top ten most dangerous apps of the quarter fall under “leisure” - a broad category that includes video and audio, news media, games and social apps. Hackers and fraudsters, it seems, pounced on the opportunity presented by a renewed appetite for ways to pass the time and connect with friends.

The most potent Android app of the quarter was Snaptube, which allows users to download video content to their devices and has been installed more than 40 million times worldwide.

Upstream published a report on the threat posed by Snaptube in October 2019, but the app remains available via a number of third party Android app stores to this day.

Although some dangerous apps make their way onto Google Play Store, Android users are still advised to refrain from downloading software via third party app stores, which likely subject app submissions to a lower level of scrutiny.

Joel Khalili
News and Features Editor

Joel Khalili is the News and Features Editor at TechRadar Pro, covering cybersecurity, data privacy, cloud, AI, blockchain, internet infrastructure, 5G, data storage and computing. He's responsible for curating our news content, as well as commissioning and producing features on the technologies that are transforming the way the world does business.

Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras