McAfee: nearly half of all malware on Android are hidden apps, up from 30% in 2018, which abuse accessibility features to create accounts, download apps, more
Esther Shein / TechRepublic :
Context & Ripple Effects
McAfee's finding that hidden apps now make up nearly half of Android malware — up from 30% in 2018 — extends a pattern the corpus has tracked for years: malware that hides rather than announces itself. The 2018 Andr/HiddnAd-AJ outbreak showed the template early, with seven Play Store apps and one carrying 500K+ downloads infecting over a million users through concealment.
Google's countermeasure has been scale-driven scanning — its security reports tout machine learning catching 60.3% of potentially harmful apps and billions of daily reviews — yet malicious apps keep slipping through, as the later Mobile apps Group case showed when four apps from a repeat-offender developer stayed on Play with millions of downloads.
First-order effects
- Android users who grant accessibility permissions to seemingly benign apps face account creation and unwanted app installs they did not authorize, with the abuse running invisibly under legitimate-looking system access.
- Google's Play Protect scanning pipeline is directly challenged: hidden apps are built to defeat exactly the signature- and behavior-based review that caught 60.3% of harmful apps via machine learning in 2017.
Second-order effects
- Developers of legitimate apps requesting accessibility APIs face heightened scrutiny and potential friction in Play review, since the same permission surface is now the dominant malware vector.
- Security vendors like McAfee gain commercial ground by selling behavioral detection that complements Google's store-side scanning, pushing enterprises toward layered mobile defense rather than relying on Play Store hygiene alone.
Third-order effects
- If concealment keeps rising as a share of Android malware, platform governance shifts from scanning what apps contain to policing what permissions they hold — making accessibility-permission gating a structural control point for Google, and persistence techniques like infected system partitions a harder removal problem for defenders.
The trend: Android malware is shifting from overt payloads to permission-abusing hidden apps, turning accessibility features into the platform's central security battleground.