Autolycos installed 3 million times from Google Play Store

Autolycos installed 3 million times from Google Play Store

Robert Haba
Robert HabaFounder · Editor-in-Chief
PublishedJuly 18, 2022
Read Time2 Mins
Trust this source on Google
Add trusted source

Over 3,000,000 people downloaded a new Android malware family from the Google Play Store that discreetly subscribes users to premium services.

Maxime Ingrao, an Evina security researcher, found the malware, known as “Autolycos,” in at least eight Android applications, of which two are still downloadable from the Google Play Store as of this writing.

The two apps still available are named ‘Funny Camera’ by KellyTech, which has over 500,000 installations, and ‘Razer Keyboard & Theme’ by rxcheldiolola, which counts over 50,000 installs on the Play Store.

Autolycos android malware

The remaining six applications have been removed from the Google Play Store, but those who still have them installed risk being charged with costly subscriptions by the malware’s activities.

  • Vlog Star Video Editor (com.vlog.star.video.editor) – 1 million downloads
  • Creative 3D Launcher (app.launcher.creative3d) – 1 million downloads
  • Wow Beauty Camera (com.wowbeauty.camera) – 100,000 downloads
  • Gif Emoji Keyboard (com.gif.emoji.keyboard) – 100,000 downloads
  • Freeglow Camera 1.0.0 (com.glow.camera.open) – 5,000 downloads
  • Coco Camera v1.1 (com.toomore.cool.camera) –1,000 downloads

During a discussion with Ingrao, the researcher told Droid Tools that he discovered the apps in June 2021 and reported his findings to Google at the time.

Although Google acknowledged receiving the report, it took the company six months to remove the set of six, while two malicious apps remain on the Play Store to this day.

After so much time had passed since the initial reporting, the researcher disclosed his findings publicly.

In place of using Webview, Autolycos uses stealthy malicious behavior to execute URLs on remote browsers and then include the results in HTTP requests.

This behavior is intended to hide its actions from users of infected devices so that they won’t be noticed.

When malicious apps were installed on a smartphone, they frequently asked for authorization to view SMS content, which gave them access to a victim’s SMS text messages.

The Autolycos owners launched various social media advertising campaigns to draw in new users to the apps. Ingrao discovered 74 Facebook ad campaigns for the Razer Keyboard & Theme alone.

Additionally, while some fraudulent apps on the Play Store received unavoidably bad reviews, some with less downloads continue to have positive user ratings thanks to fake reviews.

Android users should have Play Protect activated, monitor background internet data and battery usage, and attempt to install the fewest number of apps possible on their handsets in order to protect themselves against these attacks.

Robert Haba
Founder · Editor-in-Chief
Follow:X
Robert Haba is the founder and editor-in-chief of Droid Tools. A lifelong gadget enthusiast with over a decade following the Android ecosystem, he built this publication to cut through the noise and give readers honest, real-world coverage of the tech they actually use.

Comments & Discussions

Join the conversation! We use Disqus to handle comments. Click the button below to load the comment section.

Google Pixel’s “Take a Message” Feature May Soon Expand to More Countries and Non-Pixel Devices

Google Pixel’s “Take a Message” Feature May Soon Expand to More Countries and Non-Pixel Devices

Being a Pixel owner outside the United States has always come with a catch: a long list of AI features that simply aren’t available in your region. Google has gradually extended some of these to international markets, but the majority remain US-only. That gap may be getting a little smaller, as the company appears to […]

Qualcomm Snapdragon 4 Gen 5 and Snapdragon 6 Gen 5 Announced with Faster GPUs and New Connectivity

Qualcomm Snapdragon 4 Gen 5 and Snapdragon 6 Gen 5 Announced with Faster GPUs and New Connectivity

Qualcomm usually makes headlines for its top-tier Snapdragon 8 Elite series, and while those chips may end up inside the most expensive and desirable phones this year, the company also has a lineup of processors built for more modest hardware. Today, that means two new chips worth paying attention to. The Snapdragon 4 Gen 5 […]

Xiaomi MIX Fold 5 Spotted with XRING O3 Chipset in Mi Code Leak

Xiaomi MIX Fold 5 Spotted with XRING O3 Chipset in Mi Code Leak

Fresh clues from the Mi Code database point to Xiaomi’s next foldable flagship making a comeback. After scrapping last year’s prototype, the company seems more committed than ever to foldables, with a device that hits a key hardware milestone: Xiaomi’s first foldable running its own silicon. The Foldable Comeback and XRING O3 Mi Code data […]

TSMC Breaks 5GHz Barrier on Mobile Chips

TSMC Breaks 5GHz Barrier on Mobile Chips

With its advanced nodes enabling smartphone chipsets to achieve clock speeds of up to 5GHz, TSMC would achieve yet another significant milestone this year. TSMC’s cutting-edge technology have already tremendously benefited companies like Qualcomm, MediaTek, and Apple. Later this year, new chips will achieve peak clock rates of up to 5GHz for the first time […]