Threats Tagged 'google play'
View all threats tagged with 'google play'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'google play'
Click on any threat for detailed analysis and mitigation recommendations
ESET researchers discovered 28 fraudulent Android applications on Google Play, collectively named CallPhantom, that falsely claimed to provide call histories, SMS records, and WhatsApp logs for any phone number. These apps were downloaded over 7.3 million times before removal, primarily targeting users in India and the Asia-Pacific region. The apps generate fabricated data using hardcoded names and random phone numbers, displaying this fake information only after payment. CallPhantom employs three payment methods, with some bypassing Google Play's official billing system through third-party UPI payments or direct card entry, making refunds difficult. The scam exploits user curiosity about private information, charging between €5 and $80 for worthless subscriptions that deliver entirely fabricated communication data. Join the discussion | AlienVault OTX General | 05/07/2026, 17:05:03 UTC Added: 05/08/2026, 09:06:23 UTC |
The 'GhostAd' campaign is a large-scale Android adware threat that infiltrated Google Play with seemingly benign apps embedding persistent background advertising engines. These apps exploited Android foreground services, job schedulers, and continuous ad refreshing to maintain presence and aggressively display ads without user interaction, causing significant battery drain, degraded device performance, and difficulty in removal. Although primarily impacting users in East and Southeast Asia, the adware's use of legitimate advertising SDKs complicates detection and removal. Google has removed the malicious apps and disabled them via Google Play Protect. European organizations with Android device fleets could face indirect impacts such as reduced device availability and user productivity if similar apps spread. Mitigation requires proactive app vetting, enhanced endpoint monitoring for abnormal resource usage, and user education on app permissions and removal techniques. Countries with high Android adoption and significant Google Play usage, such as Germany, France, and the UK, are more likely to be affected if the campaign expands. Given the medium severity rating, the threat poses a moderate risk primarily through resource exhaustion and user disruption without direct data compromise or remote exploitation. Join the discussion | AlienVault OTX General | 11/27/2025, 18:32:25 UTC Added: 11/27/2025, 19:03:18 UTC |
Showing 1 to 2 of 2 results