• Login
Whats Current In
No Result
View All Result
  • Blockchain
  • Cyber Security
  • Gadgets & Hardware
  • Startups
    • Angel investing
    • Venture Capital
  • More Tech News
    • AI
    • App Development
    • Cloud & SaaS
    • Gaming
    • Web Development
  • Blockchain
  • Cyber Security
  • Gadgets & Hardware
  • Startups
    • Angel investing
    • Venture Capital
  • More Tech News
    • AI
    • App Development
    • Cloud & SaaS
    • Gaming
    • Web Development
No Result
View All Result
Whats Current In
No Result
View All Result
Home Cyber Security

Shady reward apps on Google Play amass 20 million downloads

Bill Toulas by Bill Toulas
January 30, 2023
Reading Time: 3 mins read
0
Compromised OEM Android platform certificates used to sign malware

Android app

RELATED POSTS

Online sellers targeted by new information-stealing malware campaign

Zyxel shares tips on protecting firewalls from ongoing attacks

Microsoft is killing Cortana on Windows starting late 2023

A new category of activity tracking applications has been having massive success recently on Google Play, Android’s official app store, having been downloaded on over 20 million devices.

The applications promote themselves as health, pedometer, and good habit-building apps, promising to give users random rewards for staying active in their daily lives, reaching distance goals, etc.

According to a report by the Dr. Web antivirus, though, the rewards may be impossible to cash out or are only made available partially after forcing users to watch a large number of advertisements.

Three notable examples listed in Dr. Web’s report are:

  • Lucky Step – Walking Tracker – 10 million downloads
  • WalkingJoy – 5 million downloads
  • Lucky Habit: health tracker – 5 million downloads
Shady pedometer apps on Google Play
Shady pedometer apps on Google Play (BleepingComputer)

Dr. Web says all three apps communicate with the same remote server address, indicating a common operator/developer. At the time of writing, all three remain available on Google Play.

The antivirus firm says the apps do not allow withdrawals before users have accumulated a significant amount of rewards. Even then, they promise to unlock “earnings” after users sit and watch a dozen advertisement videos.

Buy JNews
ADVERTISEMENT

Even after watching a round of ads, the apps push even more ads allegedly to “speed up” the withdrawal process. 

In addition to these signs, Dr. Web reports that an earlier version of ‘Lucky Step – Walking Tracker’ offered the option to convert in-app rewards to gift cards that users could use for purchasing goods in actual online stores.

In recent versions of the app, however, this functionality has been removed from the options, so it’s not clear what the rewards can be converted to anymore.

Some users on Google Play left reviews stating that ‘Lucky Step – Waling Tracker’ acts as adware, loading full-screen ads upon screen unlock, even overriding active windows.

User comments about Lucky Step on Google Play
User comments about Lucky Step on Google Play (BleepingComputer)

Another example of a similar app that’s still available on Google Play is ‘Wonder Time,’ a rewards app that has amassed 500,000 downloads.

The app promises to reward real money for completing various tasks like installing additional applications and games.

However, the tokens users receive for each action are minuscule compared to the minimum earnings withdrawal threshold set by the developer.

Wondertime app on Google Play
Wondertime app on Google Play (BleepingComputer)

Phishing games

In the same report, Dr. Web warned that phishing apps disguised as investment apps and games were found on Google Play, measuring over 450,000 downloads.

The apps connect to a remote server upon launch and receive a configuration instructing them on what to do. Typically, the instructions involve loading phishing pages that request users to enter sensitive details.

The malicious game apps observed by Dr. Web are the following:

  • Golden Hunt – 100,000 downloads
  • Reflector – 100,000 downloads
  • Seven Golden Wolf blackjack – 100,000 downloads (still on Google Play)
  • Unlimited Score – 50,000 downloads
  • Big Decisions – 50,000 downloads
  • Jewel Sea – 10,000 downloads
  • Lux Fruits Game – 10,000 downloads
  • Lucky Clover – 10,000 downloads
  • King Blitz – 5,000 downloads
  • Lucky Hammer – 1,000 downloads
One of the malicious games still on Google Play
One of the malicious games still on Google Play (BleepingComputer)

If you have any of the above phishing apps installed on your Android device, you should uninstall them immediately and then run an AV scan to locate and remove any remnants.

BleepingComputer has contacted Google to ask about the safety of the applications that are still on the Play Store, and we will update this post as soon as we receive a response.

Share54Tweet34Pin12
Bill Toulas

Bill Toulas

Related Posts

Beware: Hackers now use OneNote attachments to spread malware
Cyber Security

Online sellers targeted by new information-stealing malware campaign

June 3, 2023
Zyxel warns of critical vulnerabilities in firewall and VPN devices
Cyber Security

Zyxel shares tips on protecting firewalls from ongoing attacks

June 3, 2023
Microsoft is killing Cortana on Windows starting late 2023
Cyber Security

Microsoft is killing Cortana on Windows starting late 2023

June 2, 2023
Hackers use new, fake crypto app to breach networks, steal cryptocurrency
Cyber Security

The Week in Ransomware – June 2nd 2023 – Whodunit?

June 2, 2023
Microsoft fixes Windows 11 22H2 file copy performance hit
Cyber Security

Windows 11 to require SMB signing to prevent NTLM relay attacks

June 2, 2023
FBI warns of spike in ‘pig butchering’ crypto investment schemes
Cyber Security

NSA and FBI: Kimsuky hackers pose as journalists to steal intel

June 2, 2023

Recommended Stories

Suspects arrested for hacking US networks to steal employee data

IT employee impersonates ransomware gang to extort employer

May 23, 2023
FIL sees increased interest as Filecoin launches virtual machine, details inside

FIL sees increased interest as Filecoin launches virtual machine, details inside

March 15, 2023
The US Securing Open Source Software Act of 2022 is a step in the right direction

Bird still has a long way to go to reach profitability

March 10, 2023

Popular Stories

  • New Python malware backdoors VMware ESXi servers for remote access

    Massive ESXiArgs ransomware attack targets VMware ESXi servers worldwide

    137 shares
    Share 55 Tweet 34
  • Facts and myths about the warriors who raided Europe and explored the New World

    137 shares
    Share 55 Tweet 34
  • Exploit released for actively abused ProxyNotShell Exchange bug

    137 shares
    Share 55 Tweet 34
  • New Windows Server updates cause domain controller freezes, restarts

    136 shares
    Share 54 Tweet 34
  • Bing Chat’s secret modes turn it into a personal assistant or friend

    136 shares
    Share 54 Tweet 34
Whats Current In

We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc. Visit our landing page to see all features & demos.

LEARN MORE »

Recent Posts

  • How Blur achieved a new milestone from an unexpected source
  • Why Bitcoin will not retest $20,000 anytime soon
  • TRON bulls could push for another 5% hike given…

Categories

  • Apple Computer
  • Blockchain
  • Cyber Security
  • Tech News
  • Venture Capital

© 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

No Result
View All Result
  • Blockchain
  • Cyber Security
  • Gadgets & Hardware
  • Startups
    • Angel investing
    • Venture Capital
  • More Tech News
    • AI
    • App Development
    • Cloud & SaaS
    • Gaming
    • Web Development

© 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?