Joker malware on Google Play Store downloaded half a million times

Joker
(Image credit: Warner Bros)

While Google has been trying its darnedest to run a tight ship on its Play Store, nasty apps created by bad actors still manage to find their way onto the Android storefront.

The latest of these threats has been named ‘the Joker’ – after the iconic and manic Batman villain – and has been found on a total of 24 Android apps that, until recently, could be downloaded from the Google Play Store.

Before Google managed to take down the apps, they were downloaded and installed more than 472,000 times, although it’s unclear how many people remain at risk. Below is a list of the affected apps that you should uninstall immediately if you are currently using them.

  • Advocate Wallpaper
  • Age Face
  • Altar Message
  • Antivirus Security - Security Scan
  • Beach Camera
  • Board picture editing
  • Certain Wallpaper
  • Climate SMS
  • Collate Face Scanner
  • Cute Camera
  • Dazzle Wallpaper
  • Declare Message
  • Display Camera
  • Great VPN
  • Humour Camera
  • Ignite Clean
  • Leaf Face Scanner
  • Mini Camera
  • Print Plant scan
  • Rapid Face Scanner
  • Reward Clean
  • Ruddy SMS
  • Soby Camera 
  • Spark Wallpaper

Discovered by security researcher Aleksejs Kuprins, the virus is intended to leech money out of its victims by way of premium subscription services, simulating the process a user would undergo to sign up.

Specifically, the background component of these apps silently ‘clicks’ on an advertisement within the app and does the same for the sign-up process when on site. It then accesses the victims SMS messages, copying the authorization code they’ve been sent in order to verify the subscription payments.

Kuprins states that the malware has the potential to target users in 37 countries, including the US, UK, and Australia as well as other EU and Asian countries, although some of the apps didn’t have any region restrictions.

The 24 apps listed are just the ones that have been discovered so far, so more could be compromised. However, Kuprins notes that “Google has been removing all of these apps without any note from us”, so it’s not likely that future apps containing the trojan will last long under the tech giant’s watch.

If you had ever installed any of the aforementioned apps, it’s worth checking your transaction history once you’ve uninstalled them, keeping an eye out for any suspicious account activity such as unfamiliar subscription payments.

Harry Domanski
Harry is an Australian Journalist for TechRadar with an ear to the ground for future tech, and the other in front of a vintage amplifier. He likes stories told in charming ways, and content consumed through massive screens. He also likes to get his hands dirty with the ethics of the tech.
Latest in Phones
Apple iPhone 16 Pro Max REVIEW
The latest batch of leaked iPhone 17 dummy units appear to show where glass meets metal on the new designs
Google Pixel 9 Pro XL on peach background with don't miss text overlay
Why wait for the Pixel 9a? Here's a Pixel 9 Pro XL deal that can save you up to $600 at Best Buy
Apple iPhone 16e REVIEW
The iPhone 16e’s 5G performance seemingly has the iPhone 16’s beat
The Google Pixel 9a
The Google Pixel 9a’s AI has a RAM problem
Tim Cook
The EU wants Apple to open iOS to competitors and this is the mother of all bad ideas
The Google Wallet app with a mode for kids shown on-screen.
Google Wallet’s new kid-friendly payment system is a win for parents
Latest in News
Apple iPhone 16 Pro Max REVIEW
The latest batch of leaked iPhone 17 dummy units appear to show where glass meets metal on the new designs
Hornet swings their weapon in mid air
Hollow Knight: Silksong could potentially launch this year and I reckon it could be a great game for an Xbox handheld
ransomware avast
Ransomware attacks are costing Government offices a month of downtime on average
Cassian looking at someone off-camera from a TIE fighter cockpit in Andor season 2
Star Wars: Andor creator is taking a stance against AI by canceling plans to release its scripts, and I completely get why
Nintendo x Seattle Mariners partnership
The Nintendo Switch 2 logo will be featured on the Seattle Mariners' baseball jerseys this season
Apple iPhone 16 Pro Max Review
Siri's chances to beat ChatGPT just got a whole lot better