Researchers say that over a million Android users likely affected by Andr/HiddnAd-AJ malware through seven apps in the Play Store, one with 500K+ downloads
Danny Palmer / ZDNet :
Context & Ripple Effects
The HiddnAd-AJ finding lands in the middle of a long-running pattern on Google Play: in 2017 alone, researchers caught 41 apps from a single developer fraudulently clicking ads and more than 50 apps silently charging users via premium SMS, both removed only after the fact. This report adds another entry — hidden adware reaching a million-plus installs through just seven apps.
What makes the pattern notable is its persistence across years and stores: the same playbook later surfaced as SimBad in 200 games, ad-fraud code in children's apps, and Joker infections spreading beyond Play to Huawei's AppGallery.
First-order effects
- Over a million Android users who installed the seven flagged apps are carrying hidden adware, with the largest single app accounting for 500K+ of those installs before any cleanup.
- Google faces another round of post-hoc takedowns on Play, repeating the remove-after-researchers-publish cycle documented in the earlier campaigns.
Second-order effects
- Advertisers funding Play-distributed apps absorb the cost of fraudulent impressions, reinforcing why ad-fraud rather than data theft keeps drawing malware authors to the store.
- Each published finding raises the bar for Google's app review, pushing scrutiny toward the categories these campaigns keep exploiting — games and utility apps with high download velocity.
Third-order effects
- If the cycle holds — researcher discovery, then removal — the structural fix points toward automated, pre-publication scanning at Play scale rather than manual review, since the same distribution channel keeps being reused across campaigns.
- The spread of similar malware to third-party Android stores like Huawei's AppGallery suggests app-store security becomes a competitive differentiator across the Android ecosystem, not just a Google Play problem.
The trend: Android app stores remain locked in a recurring cat-and-mouse where adware campaigns exploit high-download app categories faster than store-side review can catch them.