Skip to content
Electronics

Apps with 440 million installs eluded Google Play Protect

By Aiko Tanaka
2 min read
appstore
appstore
In this article (4)

According to Ars Technica, adware named BeiTaAd was hidden in 238 apps found in the Google PlayStore. The apps, which had more than 440 million installs, played ads to help the hackers collect revenue. And with the hundreds of millions of screens at their disposal, the scheme certainly paid off handsomely for those behind it.

Part of the problem is that Android users installing one of the infected apps might not have noticed anything untoward in their behavior for a period of 24 hours to as long as two weeks. Once the adware kicked in, the BeiTaAd plugin started to deliver what is known as out-of-app-ads. These appear on lock screens, not inside an app (hence the name) and run audio and video at haphazard times.

A post in the Android Forum from November was written by someone with a friend using the Samsung Galaxy S8 on AT&T. The post noted that this person had the BeiTaAd plugin on her phone and couldn’t remove it. Another post was made by a gentleman whose wife also had the BeiTaAd plugin installed on her handset, running ads at random times. The malware, said the husband, made his wife’s phone “unusable.”

“My wife is having the exact same issue. This will bring up random adds in the middle of phone calls when her alarm clock goes off or anytime she uses any other function o(n) her phone. We are unable to find any other information on this. It is extremely annoying and almost making her phone unusable.”-DazDilinger45, Android Forum.

Mobile security firm Lookout noted that those behind the 238 malicious apps went to great lengths to hide the presence of the plugin. All of the apps involved were published by a Chinese-based company called CooTek and all CooTek apps contained the plugin. The lookout reported the names of the 238 apps to Google, and the latter removed all of them from the Google Play Store. Since this scheme had been running for months, we wonder how these malware filled apps managed to elude detection from Google’s Play Protect system.

Questions & Answers

Q.

Which company was responsible for publishing the apps containing the BeiTaAd adware?

A.

All the apps found to contain the BeiTaAd plugin were published by a Chinese-based company named CooTek. Lookout reported the names of these 238 apps to Google.

Q.

How did the BeiTaAd adware affect users' phones, according to the article?

A.

The adware delivered out-of-app ads that appeared on lock screens and ran audio and video at random times. One user reported their wife's phone became almost unusable due to the ads.

Q.

How many apps were affected by the BeiTaAd adware and how many times had they been installed?

A.

The BeiTaAd adware was hidden in 238 apps found in the Google PlayStore. These apps combined had amassed more than 440 million installs from users.

Reader pulse

How concerned are you about app store security?

23,678 votes so far

Weekly Briefing

Asia's retail intelligence, in your inbox

Monday, Wednesday and a Friday Weekly Wrap: the retail stories, numbers and moves that mattered across Asia. Nothing else, and you can unsubscribe in one click.

  • Top industry moves and market shifts
  • Weekly data-driven analysis from across Asia
  • Monday, Wednesday and the Friday Weekly Wrap

Read by retail operators, investors and brand teams across Asia.

Protected by a quick human check. No spam, ever. Unsubscribe in one click.

SecureGDPR ready