Google Play removes dozens of Android apps, including Muslim prayer apps with 10M+ downloads, after researchers find malware tied to a US defense contractor
Code placed in consumer-facing apps is tied to U.S. national-security contractors, documents show
Wall Street Journal
Context & Ripple Effects
Google Play has repeatedly removed apps after researchers uncovered abuse, from apps attempting unauthorized downloads and root access to a later cluster used for scam advertising. The current removals extend that enforcement pattern into apps used for religious practice.
The story also follows reporting that U.S. military buyers obtained granular movement data from Muslim dating and prayer apps, making the reported defense-contractor connection consequential beyond ordinary app-store malware enforcement.
First-order effects
Google Play’s removals immediately cut off distribution for the affected developers and force users of the removed prayer and other Android apps to find alternatives.
The reported link between malware code and a U.S. defense contractor puts the contractor’s relationship to consumer-app data collection under intensified scrutiny.
Second-order effects
Android app publishers handling sensitive user audiences face greater pressure to account for embedded third-party code, following earlier removals of malware-laden children’s games and utility apps.
Google’s screening and takedown decisions become more consequential for privacy-sensitive apps, because removal after large-scale adoption leaves users exposed until researchers identify the code.
Third-order effects
If contractor-linked code continues to surface in consumer apps, app-store security will increasingly be treated as a data-provenance and national-security governance problem, not solely a malware-detection problem.
The pattern points toward stronger demands for traceability across the Android software supply chain, particularly where apps can yield sensitive location or religious-practice signals.
The trend: Consumer-app distribution is becoming a contested boundary between platform security enforcement and scrutiny of data flows connected to state and defense actors.
New blog post: https://blog.appcensus.io/... We discovered a spyware SDK that collects various identifiers, the contents of the clipboard, scans home networks to identify devices, as well as hashes of files on the user's phone.
Big news: Starting Nov. 1, 2022, apps that don't target an API level within two years of the latest major OS version won't show up in Play Store search or be available for installation on devices running OS versions higher than the app's target API level! https://android-develope…
“The Panamanian company that wrote the code...is linked through corporate records and web registrations to a Virginia defense contractor that does cyberintelligence...work for U.S. national security agencies.” Big WSJ scoop here. https://www.wsj.com/...
I think this is great and they're is a more technical version in the replies for those interested. The problem is this: Google will not do this for Chinese apps we know are both security nightmares and or linked to the state https://twitter.com/...
It's wild that Google + Apple both continue to pretend like hidden SDKs ingesting user data aren't massive data controller failures in their marketplace app approval + transparency flows. Will the public get a list of the apps Google just banned for using a surveillance SDK?⛈️⚖ ️…
Google has yanked dozens of apps from its Google Play store after determining that they include software that surreptitiously harvests data. The code is linked to U.S. national-security contractors, documents show https://www.wsj.com/...
“The Panamanian company that wrote the code, Measurement Systems S. de R.L., is linked through corporate records and web registrations to a Virginia defense contractor that does cyberintelligence, network-defense and intelligence-intercept work for US national-security agencies.”…
It's being distributed by a Panamanian shell company, Measurement Systems, which appears to be affiliated with a US defense contractor, Vostrom Holdings. Developers are being lied to about what it does, which may induce them to violate various privacy laws.
Google has yanked dozens of apps from its Google Play store after determining that they include software that surreptitiously harvests data. The code is linked to U.S. national-security contractors, documents show https://www.wsj.com/...