Researchers at Symantec say seven malicious apps they detected and reported to Google slipped back into the Play Store after changing their name
Security researchers are reporting that malicious Android apps they have detected and reported to Google the first time, have slipped back into the Play Store after changing their name.
Context & Ripple Effects
The Symantec finding is one entry in a long-running loop between security researchers and Google's Play Store review: back in January 2016, Google pulled 13 apps that made unauthorized downloads and sought root access after researchers flagged them, and in May 2017 Check Point found 41 ad-fraud apps from a single developer with millions of downloads. What makes this report different is the failure mode — the seven apps were already reported once, removed, and then relisted under new names.
First-order effects
- Google has to re-review and re-remove the same seven apps Symantec already reported, meaning its takedown pipeline failed to match the relisted packages to the previously banned ones.
- Android users who installed the renamed versions are exposed to whatever behavior triggered the original report, with no signal distinguishing them from clean listings.
Second-order effects
- Malicious developers get a working playbook — rename and resubmit — which raises the volume of repeat offenders researchers like Symantec have to keep chasing; the same dynamic shows up years later when Malwarebytes finds [[a:984496|four malicious apps from a repeat-offender developer still on Play with millions of downloads]].
- Google's enforcement costs shift from one-time removals to ongoing re-takedown cycles, pressuring it to invest in fingerprinting app code rather than trusting listing metadata.
Third-order effects
- If takedowns key on names and listings instead of code-level identity, Play Store policing stays reactive whack-a-mole — a structure visible across the whole arc from the 2016 root-access removals to the 2021 discovery of bank-credential-stealing scanner and wallet apps with 300K+ downloads.
- Sustained reliance on external researchers as the de facto detection layer points toward third-party security firms becoming permanent infrastructure for app-store trust, not occasional auditors.
The trend: Play Store malware enforcement is settling into a recurring remove-and-relist cycle where researcher reports, not Google's own review, catch malicious apps — and renaming alone defeats the ban.