Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Get unlimited access to dozens of AI models for under $80 this Cyber Week

    Limited time only — get Windows 11 Pro and Office 2021 Pro for just $40

    Anker’s new USB-C dock hides a detachable hub, just like an ’80s toy

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      Apple’s AI chief abruptly steps down

      December 3, 2025

      The issue that’s scrambling both parties: From the Politics Desk

      December 3, 2025

      More of Silicon Valley is building on free Chinese AI

      December 1, 2025

      From Steve Bannon to Elizabeth Warren, backlash erupts over push to block states from regulating AI

      November 23, 2025

      Insurance companies are trying to avoid big payouts by making AI safer

      November 19, 2025
    • Business

      Public GitLab repositories exposed more than 17,000 secrets

      November 29, 2025

      ASUS warns of new critical auth bypass flaw in AiCloud routers

      November 28, 2025

      Windows 11 gets new Cloud Rebuild, Point-in-Time Restore tools

      November 18, 2025

      Government faces questions about why US AWS outage disrupted UK tax office and banking firms

      October 23, 2025

      Amazon’s AWS outage knocked services like Alexa, Snapchat, Fortnite, Venmo and more offline

      October 21, 2025
    • Crypto

      Five Cryptocurrencies That Often Rally Around Christmas

      December 3, 2025

      Why Trump-Backed Mining Company Struggles Despite Bitcoin’s Recovery

      December 3, 2025

      XRP ETFs Extend 11-Day Inflow Streak as $1 Billion Mark Nears

      December 3, 2025

      Why AI-Driven Crypto Exploits Are More Dangerous Than Ever Before

      December 3, 2025

      Bitcoin Is Recovering, But Can It Drop Below $80,000 Again?

      December 3, 2025
    • Technology

      Get unlimited access to dozens of AI models for under $80 this Cyber Week

      December 3, 2025

      Limited time only — get Windows 11 Pro and Office 2021 Pro for just $40

      December 3, 2025

      Anker’s new USB-C dock hides a detachable hub, just like an ’80s toy

      December 3, 2025

      Criteo CEO Michael Komasinski on agentic commerce, experiments with LLMs, and M&A rumors

      December 3, 2025

      Future of TV Briefing: The streaming ad upfront trends, programmatic priorities revealed in Q3 2025 earnings reports

      December 3, 2025
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»Malicious Android ‘Vapor’ apps on Google Play installed 60 million times
    Technology

    Malicious Android ‘Vapor’ apps on Google Play installed 60 million times

    TechAiVerseBy TechAiVerseMarch 19, 2025No Comments4 Mins Read1 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Malicious Android ‘Vapor’ apps on Google Play installed 60 million times
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    Malicious Android ‘Vapor’ apps on Google Play installed 60 million times

    Over 300 malicious Android applications downloaded 60 million items from Google Play acted as adware or attempted to steal credentials and credit card information.

    The operation was first uncovered by IAS Threat Lab, who categorized the malicious activity under the name “Vapor” and said it has been ongoing since early 2024.

    IAS identified 180 apps as part of the Vapor campaign, generating 200 million fraudulent advertising bid requests daily to engage in large-scale ad fraud.

    A newly published report by Bitdefender increased the number of malicious apps to 331, reporting many infections in Brazil, the United States, Mexico, Turkey, and South Korea.

    “The apps display out-of-context ads and even try to persuade victims to give away credentials and credit card information in phishing attacks,” warns Bitdefender.

    Although all of these apps have since been removed from Google Play, there’s a significant risk that Vapor will return through new apps as the threat actors have already demonstrated the ability to bypass Google’s review process.

    Vapor apps on Google Play

    The apps used in the Vapor campaign are utilities offering specialized functionality like health and fitness tracking, note-taking tools and diaries, battery optimizers, and QR code scanners.

    The apps pass Google’s security reviews because they include the promoted functionality and do not contain malicious components at the time of submission. Instead, the malware functionality is downloaded post-installation via updates delivered from a command and control (C2) server.

    Malicious apps on Google Play
    Source: IAS Threat Lab

    Some notable cases highlighted by Bitdefender and IAS are:

    • AquaTracker – 1 million downloads
    • ClickSave Downloader – 1 million downloads
    • Scan Hawk – 1 million downloads
    • Water Time Tracker – 1 million downloads
    • Be More – 1 million downloads
    • BeatWatch – 500,000 downloads
    • TranslateScan – 100,000 downloads
    • Handset Locator – 50,000 downloads.

    They are uploaded on Google Play from various developer accounts, each pushing only a few to the store, so as not to risk high disruption in case of takedowns. For similar reasons, each publisher uses a different ads SDK.

    Most of the Vapor apps were published on Google Play between October 2024 and January 2025, though uploads continued until March.​

    Vapor app submissions on Google Play
    Bitdefender

    Malicious functionality

    The malicious Vapor apps turn off their Launcher Activity in the AndroidManifest.xml file after installation, making them invisible. In some cases, they rename themselves in Settings to appear as legitimate apps (e.g., Google Voice).

    The apps launch without user interaction and use native code to enable a secondary hidden component while keeping the launcher disabled to keep the icon hidden.

    Bitdefender comments that this method bypasses Android 13+ security protections that prevent apps from dynamically disabling their own launcher activities once they are active.

    The malware also bypasses the ‘SYSTEM_ALERT_WINDOW’ permission restrictions on Android 13+ and creates a secondary screen that acts as a fullscreen overlay.

    The ads are displayed on this screen, which is overlayed on top of all other apps, leaving the user with no way to exit as the ‘back’ button is disabled.

    The app also removes itself from ‘Recent Tasks,’ so the user cannot determine which app launched the ad they just got.

    Bitdefender reports that some apps go beyond ad fraud, displaying fake login screens for Facebook and YouTube to steal credentials or prompt users to enter credit card information under various pretenses.

    It is generally recommended that Android users avoid installing unnecessary apps from non-reputable publishers, scrutinize granted permissions, and compare the app drawer with the list of installed apps from Settings → Apps → See all apps.

    The complete list ofof all 331 malicious apps uploaded on Google Play is available here.

    If you discover that you have installed any of those apps, remove them immediately and run a complete system scan with Google Play Protect (or other mobile AV products).

    BleepingComputer has contacted Google for a comment on the Vapor campaign, but a statement wasn’t available by the time of publication.


    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleNew Windows zero-day exploited by 11 state hacking groups since 2017
    Next Article Western Alliance Bank notifies 21,899 customers of data breach
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    Get unlimited access to dozens of AI models for under $80 this Cyber Week

    December 3, 2025

    Limited time only — get Windows 11 Pro and Office 2021 Pro for just $40

    December 3, 2025

    Anker’s new USB-C dock hides a detachable hub, just like an ’80s toy

    December 3, 2025
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025467 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025159 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 202584 Views

    Is Libby Compatible With Kobo E-Readers?

    March 31, 202563 Views
    Don't Miss
    Technology December 3, 2025

    Get unlimited access to dozens of AI models for under $80 this Cyber Week

    Get unlimited access to dozens of AI models for under $80 this Cyber Week Image:…

    Limited time only — get Windows 11 Pro and Office 2021 Pro for just $40

    Anker’s new USB-C dock hides a detachable hub, just like an ’80s toy

    Japanese devs face font licensing dilemma as leading provider increases annual plan price from $380 to $20,000+

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    Get unlimited access to dozens of AI models for under $80 this Cyber Week

    December 3, 20250 Views

    Limited time only — get Windows 11 Pro and Office 2021 Pro for just $40

    December 3, 20250 Views

    Anker’s new USB-C dock hides a detachable hub, just like an ’80s toy

    December 3, 20250 Views
    Most Popular

    Apple thinks people won’t use MagSafe on iPhone 16e

    March 12, 20250 Views

    Volkswagen’s cheapest EV ever is the first to use Rivian software

    March 12, 20250 Views

    Startup studio Hexa acquires majority stake in Veevart, a vertical SaaS platform for museums

    March 12, 20250 Views
    © 2025 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.