The software and online security company, Sophos has released a damning report revealing 15 Android apps which all have major security issues and malicious behaviour scripts. The apps previously available through the Google Play store have all now been removed from the platform and can no longer be downloaded. Despite this, it is believed that over 1.3million devices still have these apps installed. What’s worse is some users may not even know they have them.
The apps act in different ways, causing issues from general irritation which includes call blocking, screen locking and touch screen issues as well as more serious issues such as data leakage, ad serving and behaviour monitoring.
Depending on the individual app, you may also find it hard to detect or delete given the way the app protects itself. Some of them display fake error messages on attempted use while others hide the icon for the app from the phone’s home screen entirely, leading users to wrongly assume the app isn’t really on their phone.
The list of apps released includes the following:
• Flash On Calls & Messages
• Read QR Code
• Imagine Magic
• Generate Elves
• Savexpense
• QR Artifact
• Find Your Phone: Whistle
• Scavenger - - - speed guard
• Auto Cut Out Pro
• Background Cut Out
• Photo Background
• ImageProcessing
• Background Cut Out New
• Auto Cut Out
The apps are all free and were created to appear as if they provided a basic service many smartphone owners may use or consider mildly useful without fear of their being any additional foul play.
One of the apps, Flash on Calls & Messages - also known as Free Calls & Messages - displays fake error messages when launched. It then redirects you to Google Maps on the Play Store, leading users to believe that is responsible for the programme crash.