Kaspersky finds a new Necro malware version in Google Play apps with 11M+ total downloads; in 2019, researchers found Necro in Play apps with 100M+ downloads
here's what we know Mark Campbell / OC3D : “Necro” infects 11 million Android devices and hits the Google Play Store Dwaipayan Roy / NewsBytes : This malware has infected 11M Android devices via Play Store Anthony Spadafora / Tom's Guide : 11 million Android users infected with dangerous Necro trojan — how to stay safe Karandeep Singh Oberoi / Android Police : Necro Trojan malware infects millions of Android devices through two Google Play apps Duncan Riley / SiliconANGLE : Necro malware infects 11M+ Android devices via Google Play apps Arol Wright / How-To Geek : This Android Trojan Has Infected at Least 11 Million Devices Michael Kan / PCMag : These 2 Android Apps Spread ‘Necro Trojan’ Malware Via Google Play Store Zak Doffman / Forbes : Google Play Store Warning—Do Not Install These Apps On Your Phone Forums: r/technews : 11 million devices infected with botnet malware hosted in Google Play
Context & Ripple Effects
Necro’s return to Google Play follows a long record of malicious apps reaching users through the store, from adware affecting more than a million users to apps designed to steal bank credentials in 2021.
The reported 11M-plus download footprint is smaller than the 2019 Necro discovery involving more than 100 million downloads, but it shows that distribution through a major app marketplace remains a recurring exposure point.
First-order effects
- Android users who installed the affected Play apps face immediate malware exposure, while Kaspersky’s finding puts the apps and their distribution path under security scrutiny.
- Google Play’s screening and post-publication monitoring are directly implicated because the reported infections were tied to apps available through the store.
Second-order effects
- The recurrence increases pressure on Google Play to detect malicious behavior that may emerge after an app passes initial review, rather than relying only on pre-listing checks.
- Developers of legitimate utility-style apps may face greater user skepticism, particularly after prior credential-stealing scanner and wallet apps used familiar app categories as cover.
Third-order effects
- If repeated high-download incidents persist, mobile-store security will increasingly be judged as an ongoing ecosystem-defense function, not a one-time app-approval process.
- The pattern favors stronger behavioral monitoring and faster remediation across the Android distribution ecosystem, though the corpus does not establish which specific controls Google will adopt.
The trend: Major mobile app stores are becoming a continuing cyber-defense layer as attackers repeatedly use trusted distribution channels to reach large Android audiences.