Google bans 29 apps downloaded 4.3M+ times from the Play Store after researchers discovered they were being used to perform malicious acts like serve scam ads
The 29 apps concealed their malice and were hard for many infected users to uninstall. — Google has banned dozens …
Context & Ripple Effects
This ban is the third act in a pattern Ars Technica has tracked since Google removed 13 root-seeking apps from the Play Store in 2016: outside researchers spot malicious behavior, then Google pulls the apps after millions of installs have already accumulated. What changed by 2019 is scale and stealth — these 29 apps hid their intent and made themselves difficult to uninstall.
The arc only steepens afterward: in 2020 Google removed roughly 600 apps with 4.5B+ installs over ad fraud (banning their developers outright), and by late 2022 researchers found ad-fraud apps running on both Google Play and Apple's App Store with 13M combined installs before both stores removed them.
First-order effects
- Users who installed the 29 apps — 4.3M+ downloads' worth — are exposed to scam ads and face apps engineered to resist uninstalling, making manual cleanup the immediate burden.
- Google loses the revenue-integrity argument it otherwise sells to advertisers: its own storefront was serving fraudulent inventory until external researchers flagged it.
Second-order effects
- Advertisers buying Play-ecosystem inventory face harder questions about where their spend lands, pushing demand toward stores and networks that can prove fraud screening rather than promise it.
- Apple is pulled into the same fight — the 2022 cross-store findings show ad-fraud kits are not an Android-only problem, so both platforms must respond to the same researcher community.
Third-order effects
- If the pattern holds, enforcement shifts from reactive takedowns after researcher reports to preemptive blocking at publish time — the direction Google's own numbers point, with 1M+ policy-violating apps blocked and 190K developer accounts banned in 2021 alone.
- Developer vetting becomes the real control surface: banning accounts, not just apps, signals that repeat offenders behind ad-fraud networks are treated as the unit of enforcement.
The trend: App store security is moving from researcher-triggered takedowns of already-installed malware toward large-scale preemptive blocking and developer-account bans aimed at ad fraud.