/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Kaspersky: malware developers are selling malicious Google Play loaders for $2K-$20K on hacker forums; the average price for a loader is $6,975

Malware developers have created a thriving market promising to add malicious Android apps to Google Play for $2,000 to $20,000 …

BleepingComputer Bill Toulas

Context & Ripple Effects

This report puts a price on a distribution problem that had already been visible in Google Play: Android attackers were increasingly using multi-stage droppers to evade store review rather than relying on a single overtly malicious app.

The persistence of malicious apps from a developer with prior malware deployments, including apps that remained available despite millions of downloads, shows why a commercial loader market matters: it can package store-placement expertise for buyers who do not build it themselves.

First-order effects

  • Malware operators can buy a specialized route into Google Play instead of developing and testing their own loader infrastructure, with reported offers spanning $2,000 to $20,000.
  • Google Play users face a higher risk that apparently legitimate apps act as an initial delivery stage for later malicious payloads; Google must identify both the visible app and the loader behavior behind it.

Second-order effects

  • A priced loader market separates malware distribution from payload development, enabling more specialized sellers and buyers and making takedowns of individual malicious apps less durable.
  • Store defenses are pressured toward detecting developer networks, staged delivery, and post-install behavior—not only scanning an app’s initial code submission.

Third-order effects

  • If this market persists, mobile malware distribution may increasingly operate as a service layer, where access to trusted app channels is bought independently of the fraud, spyware, or other payload ultimately delivered.
  • The recurring pattern—from droppers to later large-scale Play malware discoveries such as Necro-infected Play apps—suggests app-store trust will depend more on continuous enforcement after publication, although the scale of this loader market remains unclear.

The trend: This is one data point in the commercialization of mobile-malware distribution, in which app-store evasion capabilities are sold as reusable services.

Discussion

  • @campuscodi@mastodon.social Catalin Cimpanu on mastodon
    Kaspersky has an overview of various Android malware strains and other malicious services sold in the underground markets  —  https://securelist.com/...
  • @securelist @securelist on x
    New research shows that #cybercriminals are playing dirty with fake reviews, installs, & bots to hijack #Google Play's app rankings, visibility, and trust. Some of the most popular fake apps include crypto trackers, financial apps, QR scanners & dating. https://securelist.com/...
  • @kaspersky @kaspersky on x
    Our latest report revealed that #cybercriminals use #Darknet to sell malicious Google Play #apps for up to US$20,000😱💲 #GooglePlay threats⚠️ explained👇 https://kas.pr/yj4n
  • @kaspersky @kaspersky on x
    In 2022, We detected 1,661,743 malware or unwanted software installers, targeting mobile users. With many examples of malicious and unwanted apps on Google Play being discovered after complaints from users, we decided to take a look!!👇 https://kas.pr/5w4t
  • @e_kaspersky Eugene Kaspersky on x
    Overview of Google Play threats sold on the dark web. Highlights: ✅ Loader for app delivery to Google Play = $2-20K ✅ Cryptocurrency trackers most often hide malware Details 👉 https://kas.pr/v7fa https://twitter.com/...
  • @adam_k_levin Adam Levin on x
    $5000 is all it takes to get malware on Google Play: https://www.bleepingcomputer.com/ ...