Skip to content
Droid Tools
Home
About UsContact
Editorial PolicyReview Policy
Privacy PolicyCookie PolicyTerms & Conditions
⌘K
Search
FacebookX (Twitter)InstagramThreadsBlueskyTikTokYouTubeRedditTelegramRSS Feed
Trending:
Galaxy S26•Pixel 10•Android 16•Nothing OS•Gemini AI•Smartwatches•Tech Deals•Latest Reviews•How-to Guides
Droid Tools

Droid Tools covers the latest Android news, device reviews, app updates, and OS guides. Stay informed with hands-on coverage from mobile tech experts.

Explore

  • News
  • Apps
  • OS
  • Phones
  • Reviews

Legal & Info

  • About Us
  • Contact
  • Editorial Policy
  • Review Policy
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy
  • Affiliate Disclosure
  • Disclaimer
  • HTML Sitemap
  • XML Sitemap
© 2026 Droid Tools. All rights reserved.
Home/News/The malware that signs you up for pricey services – Joker
News

The malware that signs you up for pricey services – Joker

Robert Haba
Sep 30, 20204 min read
Robert Haba
Robert Haba
Founder · Editor-in-Chief
Robert Haba is the founder and editor-in-chief of Droid Tools. A lifelong gadget enthusiast with over a decade following the Android ecosystem, he built this publication to cut through the noise and give readers honest, real-world coverage of the tech they actually use.
X
Profile →
The malware that signs you up for pricey services – Joker
0%
Share on XFacebookBluesky
Follow on Google
Advertisement
Trust this source on GoogleAlways see our reviews and tech guides first in search results
Add trusted source

Key Takeaways

Automated Editorial Synthesis
AI Overview
  • Dozens of malicious apps, some available in Play, found in the past couple months.
  • Known as Joker, since late 2016, this family of malicious apps has been targeting Android users and has been one of the most common threats to Android more recently.
  • Joker apps secretly subscribe to costly subscription services once activated and can even steal SMS messages, contact lists, and computer information.

Dozens of malicious apps, some available in Play, found in the past couple months. Joker malware

September has been a busy month for malicious Android apps, with hundreds of them flooding either Google Play or third-party markets from a single malware family alone, researchers from security companies said.

Known as Joker, since late 2016, this family of malicious apps has been targeting Android users and has been one of the most common threats to Android more recently. Joker apps secretly subscribe to costly subscription services once activated and can even steal SMS messages, contact lists, and computer information. Researchers last July said they found Joker lurking about 500,000 times in 11 apparently legitimate apps downloaded from Play.

Advertisement

Late last week, researchers from security firm Zscaler said they discovered a new batch of 120,000 downloads containing 17 Joker-tainted games. Over the course of September, the applications were progressively uploaded to Play. Meanwhile, security firm Zimperium announced on Monday that in September, company researchers discovered 64 new Joker variants, most or all of which were seeded in third-party app stores.

(adsbygoogle = window.adsbygoogle || []).push({});

And, as ZDNet noted, this month and in July, researchers from security firms Pradeo and Anquanke found more Joker outbreaks. Since it first came to light in December 2016, Anquanke said it had located more than 13,000 samples.

“Joker is one of the most prominent malware families that continually targets Android devices,” Zscaler researcher Viral Gandhi wrote in last week’s post. “Despite awareness of this particular malware, it keeps finding its way into Google’s official application market by employing changes in its code, execution methods, or payload-retrieving techniques.”

Advertisement

The roundabout way of attack is one of the keys to the Joker ‘s success. The apps are knockoffs of legitimate apps and contain no malicious code other than a “dropper” when downloaded from Play or a different market. The dropper, which is heavily obfuscated and includes only a few lines of code, installs a malicious part and drops it into the app after a delay of hours or even days.

You May Also Like
Recommended
1

Huawei Kirin 9050 Pro chipset: full specs and what’s new

kirin 9050
2

The 5 biggest phone launches to watch in September 2026

semptember 2026 phones
3

Google’s Scam Detection could be coming to Xiaomi phones, teardown suggests

joker malware

A flow chart that captures the four pivot points each Joker sample uses was given by Zimperium. In order to mask update components as innocuous applications such as games, wallpapers, messengers, translators and photo editors, the malware often uses evasion techniques.

(adsbygoogle = window.adsbygoogle || []).push({});

The evasion techniques include encoded strings inside the samples where an app is to download a dex, which is an Android-native file that comprises the APK package, possibly along with other dexes. The dexes are disguised as mp3 .css, or .json files. To further hide, Joker uses code injection to hide among legitimate third-party packages—such as org.junit.internal, com.google.android.gms.dynamite, or com.unity3d.player.UnityProvider—already installed on the phone.

The purpose of this is to make it more difficult for the malware analyst to spot the malicious code, as third-party libraries generally contain a lot of code and the existence of additional obfuscation will make it much more difficult to spot the injected classes, “wrote Zimperium researcher Aazim Yaswant.” “In addition, the use of valid package names defeats naïve [blocklisting] attempts, but our z9 machine-learning engine allowed the researchers to detect the above-mentioned injection tricks safely.”

Advertisement

Three forms of post-download strategies to circumvent Google’s app-vetting process are detailed in the Zscaler write-up: direct downloads, one-stage downloads, and two-stage downloads. The final payload was the same, despite the delivery variations. If the final payload is downloaded and enabled by an application, the knock-off application has the opportunity to sign up for premium subscriptions using the user’s SMS app.

A Google spokesman declined to comment other than to note that Zscaler reported that the company removed the apps once they were privately reported.

(adsbygoogle = window.adsbygoogle || []).push({});

Using an antivirus app from Malwarebytes, Eset, F-Secure, or another reputable maker is also an option, although they, too, can have difficulty detecting Joker or other malware.

Trust this source on GoogleAlways see our reviews and tech guides first in search results
Add trusted source
Tags:#antivirus#joker#malware#virus
Recommended Deals
1 / 5
Google Pixel Watch 5 (45mm)

Google Pixel Watch 5 (45mm)

5.0
529.99
Buy on Amazon
💎Best Android Device
Samsung Galaxy S26 Ultra

Samsung Galaxy S26 Ultra

4.9
$1,212.85$1,499.99-19%
Buy on Amazon
👑A good choice
Apple iPhone 17 Pro

Apple iPhone 17 Pro

4.8
$1,012.97$1,099.00-8%
Buy on Amazon
Samsung Galaxy Watch 8

Samsung Galaxy Watch 8

4.9
$289.99$349.99-17%
Buy on Amazon
Google Pixel Watch 4

Google Pixel Watch 4

4.8
396.00$499.99-21%
Buy on Amazon
* As an Amazon Associate, Droid Tools earns from qualifying purchases. Read our editorial policy
Robert Haba
Robert HabaFounder · Editor-in-Chief
X

Robert Haba is the founder and editor-in-chief of Droid Tools. A lifelong gadget enthusiast with over a decade following the Android ecosystem, he built this publication to cut through the noise and give readers honest, real-world coverage of the tech they actually use.

Advertisement

Comments & Discussions

Join the conversation! We use Disqus to handle comments. Click the button below to load the comment section.

Advertisement

Latest Stories

Google Messages rolls out Keep Notes integration from the September Android Drop
01

Google Messages rolls out Keep Notes integration from the September Android Drop

02

Honor MagicOS 11 debuts September 15 with Glazed Architecture, faster YOYO

03

OnePlus 16 reservations open in China, revealing design and colors ahead of launch

04

Honor MagicOS 11 to debut with hidden Power Saving Suggestions feature

Advertisement
Amazon Deals
5.0
Google Pixel Watch 5 (45mm)

Google Pixel Watch 5 (45mm)

Best Price
529.99
Buy

Top Deals

Pixel Watch 5 vs. Pixel Watch 4: what actually changed

Deal
Pixel Watch 5 vs. Pixel Watch 4: what actually changed

Apple Watch Series 12 vs Pixel Watch 5: how they compare

Deal
Apple Watch Series 12 vs Pixel Watch 5: how they compare

Garmin Epix Pro Gen 2 Sapphire Edition drops to under $700 at Amazon

Deal
Garmin Epix Pro Gen 2 Sapphire Edition drops to under $700 at Amazon
Advertisement
Advertisement
Recommended stories

Continue reading

More from this category →
kirin 9050
NewsSep 11, 2026

Huawei Kirin 9050 Pro chipset: full specs and what’s new

Huawei has released its new high-performance Kirin 9050 Pro chipset, and details about the silicon's architecture are now available across CPU, GPU, NPU, modem, security, and cooling. CPU, GPU, and NPU upgrades The chip's LinxiCore CPU supports simultaneous multi-threading and delivers a 24% gain in peak single-core performance alongside a 52% gain in multi-core concurrent […]

By Robert Haba
semptember 2026 phones
NewsSep 8, 2026

The 5 biggest phone launches to watch in September 2026

September is usually iPhone season, but this year several Android brands are packing their very best hardware into the same four-week stretch, aiming to steal some of the spotlight. More than 20 phones are expected to launch this month alone, and here's a rundown of five of the biggest phone launches on the calendar for […]

By Luiza Mosneagu
NewsSep 4, 2026

Google’s Scam Detection could be coming to Xiaomi phones, teardown suggests

Google's Scam Detection feature could be coming to Xiaomi phones next, according to a new APK teardown by Android Authority. The AI-powered scam-call warning tool debuted first on Pixel devices, has since expanded to Samsung's Galaxy S26 series, and has shown signs of heading to vivo phones as well, and Android Authority now says it's […]

By Robert Haba
android-trojan
NewsSep 4, 2026

New StreamRat Android banking trojan spreads via fake streaming ads

Cybersecurity researchers at ThreatFabric have disclosed a new Android banking trojan called StreamRat that was pushed to Spanish-speaking users through a fake television-streaming campaign on Meta and can hand its operators near-complete control of an infected device. According to ThreatFabric, the campaign's advertising focused on Spain and reached an estimated 570,950 Meta accounts in the […]

By Robert Haba
Next in queue

Read the next article

The next story loads as you reach the end. You can also load it using the button.