Report: hidden adware in 238 Play Store apps with 440M+ installs by China-based CooTek made phones nearly unusable; apps now pulled or updated to remove adware
Carefully concealed plugin bombarded users with ads during inopportune times. — If the prevalence of abusive Google Play apps …
Context & Ripple Effects
The CooTek report lands mid-pattern rather than in isolation: just weeks earlier, researchers had surfaced SimBad adware inside more than 200 Android games with 150M+ downloads, and in February Google had banned 29 apps used to serve scam ads. What distinguishes this case is scale and intent — a single China-based developer, 238 apps, 440M+ installs, and a concealed plugin engineered to make phones nearly unusable.
That the affected apps were pulled or updated only after exposure underscores how the abuse evaded Play Store review until researchers intervened. The follow-on coverage confirms the pattern persisted: by late 2020 researchers mapped a fraudulent ad business running through 240+ low-quality Play Store apps, suggesting removals address symptoms more than the underlying distribution model.
First-order effects
- Users across 440M+ installs of CooTek's apps bore the immediate cost — ads served during inopportune times on phones rendered nearly unusable — while CooTek itself now faces pulled or stripped-down apps and a reputational hit across its entire catalog.
Second-order effects
- Google is pushed toward tighter post-publication scanning of already-listed apps, since pre-launch review demonstrably missed a concealed plugin at this scale; advertisers, meanwhile, absorb spend funneled into out-of-context impressions they never knowingly bought.
Third-order effects
- If single-developer catalogs keep turning into ad-fraud vehicles — from the 2017 case of 41 apps by one developer to SimBad to this — app-store economics shift toward policing the SDK and plugin layer, where the abusive code actually hides, rather than judging apps one listing at a time.
The trend: Android adware is converging on a repeatable playbook — legitimate-looking developer catalogs concealing ad-serving plugins at hundred-million-install scale — forcing Google to treat store security as continuous monitoring rather than gatekeeping.