Delete this VPN now, millions of users warned

VPN
(Image credit: Shutterstock / Elaine333)

Google has removed a popular Android VPN from the Play Store after vulnerabilities were discovered in the service that could allow hackers to redirect users to malicious servers.

SuperVPN - the offending service - has more than 100 million installs and featured among the top five VPN search results in Google’s app store before it was withdrawn.

The VPN contains vulnerabilities that open the door to man-in-the-middle (MITM) attacks, which can expose messages sent between the user and provider and - most critically - redirect users away from bonafide VPN servers.

Rigorous testing also revealed the app allows sensitive data to be delivered over insecure HTTP. While the information passed between the user and the backend is encrypted, the decryption keys are stored within the app itself, making them an easy target for hackers.

SuperVPN privacy concerns

SuperVPN has drawn criticism on multiple occasions over its suspicious practices, and the precise origin of the application remains unclear.

Its publisher SuperSoftTech is listed as Singapore-based, but an investigation into the app’s lineage reveals it is owned by Jinrong Zheng, an independent developer likely based in Beijing.

Zheng is also responsible for LinkVPN - which is ostensibly based in Hong Kong - and is connected with Shenyang Yiyuansu Network Technology, the app developer listed against SuperVPN on the Apple App Store.

SuperVPN was first identified as a security threat in 2016, when Australian researchers ranked it third in an analysis of the most malware-rigged VPN apps, suggesting the app has posed risks since it arrived on Google Play Store. At this point in time, it had been installed only 10,000 times.

The app’s user base has doubled from 50 to 100 million since January, in line with the significant uptick in worldwide VPN usage prompted by the ongoing pandemic, placing vast numbers of users at risk.

The surge in installs can also be attributed in part to manipulation of Google Play Store search rankings. The publisher reportedly flooded its page with a high volume of fake reviews from hidden users and generated illegitimate backlinks to secure an optimal position in the rankings.

The millions of SuperVPN users are advised to delete the application immediately.

Via VPNPro

Joel Khalili
News and Features Editor

Joel Khalili is the News and Features Editor at TechRadar Pro, covering cybersecurity, data privacy, cloud, AI, blockchain, internet infrastructure, 5G, data storage and computing. He's responsible for curating our news content, as well as commissioning and producing features on the technologies that are transforming the way the world does business.

Latest in VPN Privacy & Security
PrivadoVPN running on an iPhone during TechRadar's VPN tests
Why PrivadoVPN Free is still a stellar option for streaming
 In this photo illustration a Google Play logo seen displayed on a smartphone.
Why is there so much spyware hidden in the Play Store?
PrivadoVPN running on an iPhone during TechRadar's VPN tests
Why PrivadoVPN Free is still the best free VPN for streaming
Homepage of CloudFlare website on the display of PC, url - CloudFlare.com.
"Network blocking is never going to be the solution" – Cloudflare slams anti-piracy tactics
Panels at RightsCon 2025 during a press briefing about the latest Access Now report of internet shutdowns
2024 was the worst year on record for internet freedoms – again
Vector illustration of the word Censored in a glitch distorted style
Google, Apple, and internet restriction – how Big Tech is making censorship "much worse" according to experts
Latest in News
Vision Pro Metallica
Apple Vision Pro goes off to never never land with Metallica concert footage
Mufasa is joined by another lion, a monkey and a bird in this promotional image
Mufasa: The Lion King prowls onto Disney+ as it finally gets a streaming release date
An American flag flying outside the US Capitol building against a blue sky
Sean Plankey selected as CISA director by President Trump
An Nvidia GeForce RTX 4060 on a table with its retail packaging
Nvidia RTX 5060 GPU spotted in Acer gaming PC, suggesting rumors of imminent launch are correct – and that it’ll run with only 8GB of video RAM
Indiana Jones talking to a friend in a university setting with a jaunty smile on his face
New leak claims Indiana Jones and the Great Circle PS5 release will come in April
A close up of the limited edition vinyl turntable wrist watch from AndoAndoAndo
This limited-edition timepiece turns the iconic Technics SL-1200 turntable into a watch, and I want one