• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
TechEngage

TechEngage®

Hands-on reviews, research-backed buying guides and technology news.

  • News
    • Internet & Social
    • Gadgets
    • Car Tech
    • Business
    • Science & Health
  • Reviews
  • Buying Guides
  • How-to
  • AI
  • Computing
    • Apps
    • Security
    • Gaming
  • More
    • Tools
    • Puzzles
    • Mobile
  • Launchpad
  • Sign in
TechEngage » Security & Privacy

Google Play Store accidentally sends malware to users’ phones

News

Avatar for Nouman S Ghumman Nouman S Ghumman Follow Nouman S Ghumman on X Published: Nov 21, 2018 · 3:51 PM ET Updated: Dec 29, 2018 · 12:59 PM ET

google play store send malware
Shares106FacebookTweetPinLinkedInPrint
More than half a million users accidentally downloaded malware on to their devices when they tried and downloaded racing games, from the Google Play Store. There were thirteen apps that were guilty of containing malware. Two of these apps were even on the Trending section. This means the games were quite prominent and many users could see them. So the chance of users trying them was quite high. All thirteen of the racing games were made by the same game developer. The exact number of downloads was close to 580,000 at the time of reporting. The malware was reported by ESET malware researcher Lukas Stefanko. The game kept on crashing everytime users tried to open the app. It was definitely what users were expecting. Instead, it was working mischievously and was downloading payload from another server.

Don't install these apps from Google Play – it's malware.

Details:
-13 apps
-all together 560,000+ installs
-after launch, hide itself icon
-downloads additional APK and makes user install it (unavailable now)
-2 apps are #Trending
-no legitimate functionality
-reported pic.twitter.com/1WDqrCPWFo

— Lukas Stefanko (@LukasStefanko) November 19, 2018
The server was hosted by a developer from Istanbul. The app deleted the icon and installed malware behind the scenes. It is not clear at the moment what the malware is supposed to do or what its function is. The app does start up everytime the user starts their phone. This means that the app had full access to the system. So the user could access network data and steal users’ identity or invade users’ privacy. TechCrunch tracked down the domain owner Mert Ozek, who is based from Istanbul. Ozek didn’t respond to TechCrunch’s email. Google spokesperson Scott Westover confirmed that the apps “violated our policies and had been removed from the Play Store.” This is yet another point of criticism for the sear engine behemoth who has shown another lapse of judgment. Many Apple fans will be criticizing their Android friends for this mess up. Apple has the edge over Android devices in some departments. The App Store is one of them. Apple is known for keeping a check and balance on what apps get released on their platform. It rejects more apps than it allows. So the App Store is a fairly competitive place to be. This means that the apps go through proper channels and such incidents are few and far between. The search giant has put in quite a few measures to cut down on malware and malicious apps. The tech company has tried to remove many apps that it found to be malicious in the past. It even tried to improve the security of the Android ecosystem. Google introduced new security features. On top of the list was the way permissions are approved for Android apps. Google wanted to review the way third-party developers developed apps and how they accessed various APIs. Despite these vital measures, there were still so many security flaws that slipped through the cracks. Malicious and harmful apps continue to plague the app store and are the number one threat to Android security. The company has already faced criticisms on other platforms as well. Everyone remembers the Google+ fiasco which left millions of users’ data exposed. Play Store continues to be a hostile territory especially for new users, who are oblivious to clues regarding malicious and shady apps. If this trend continues, many potential new Android will be put off with the world’s most popular mobile operating system. This will be a huge win for Apple, on the other hand, which is considered a far safer platform. Google pulled more than 700,000 apps from their platform last year. These apps were deemed unsuitable and broke the Play Store’s terms of service. This was up by 70 percent from 2016, which shows the menace of harmful apps just keeps snowballing. The company even tried to improve its back-end to prevent stop harmful apps from being published onto the Play Store in the first place. This was clearly to no avail. Harmful apps still get their hands across uninformed users, which leaves a path of destruction for Google to clean. This is bad for both developer and Android users. Google needs to take a cold hard look at how it handles security. Otherwise, there will be a lot of repercussions for such carelessness.

Related reading

  • How to Find and Remove Harmful Software Using Chrome
  • Google pulls down several apps from Play Store for stealing Facebook data
  • Tips to Protect your PC from Malware & Hackers
  • How does a VPN protect user privacy and anonymity?
Something incorrect? Report an error in this article. Include a source if you have one; your name and email are optional.

Filed Under: Security & Privacy, Tech News & Analysis Tagged With: Google Play Store, Malware

Related Stories

  • Openai Pauses Advanced-Model Research After Agent Bypasses Network Restrictions

    OpenAI pauses advanced-model research after agent bypasses network restrictions

    Tech News & AnalysisSep 27, 2026

  • Akamai’s $11.6 Billion Anthropic Cloud Deal: Costs, Timeline And Cpu Strategy

    Akamai’s $11.6 billion Anthropic cloud deal: costs, timeline and CPU strategy

    Tech News & AnalysisSep 27, 2026

  • Three Ceos Asked To Slow Down. The President Said No And The Market Fell 3 Percent. Hassan Taher On What Actually Happened.

    Three CEOs Asked to Slow Down. The President Said No and the Market Fell 3 Percent. Hassan Taher on What Actually Happened.

    AISep 21, 2026

Stay on top of technology

Get TechEngage reviews, buying guides and news in your feed.

Follow on Google News
Shares106FacebookTweetPinLinkedInPrint
Avatar for Nouman S Ghumman

Nouman S Ghumman

VP & Associate General Counsel

Nouman S Ghumman serves as Vice President and Associate General Counsel at TechEngage. He holds an LLM in International Commercial Law from City, University of London and is a Managing Partner at SG Advocates and Legal Consultants. He writes on smartphones, cybersecurity, internet regulation, and the legal dimensions of technology across nearly 80 articles.

Joined TechEngage December 2009First article on TechEngage January 2011

Reader Interactions

Share Your Thoughts Cancel reply

Please read our comment policy before submitting your comment. Your email address will not be used or published anywhere. You will only receive comment notifications if you opt to subscribe below.

Primary Sidebar

Google News

Get TechEngage in your feed

Reviews, news, and buying guides as they publish.

Follow on Google News

Recent Stories

  • Usb C Power Meters Techengage |
    Computing & HardwareBest USB-C Power Meters for Chargers and CablesSep 28, 2026
  • Akamai Anthropic Cloud Techengage |
    Tech News & AnalysisAkamai’s $11.6 billion Anthropic cloud deal: costs, timeline and CPU strategySep 27, 2026
  • Openai Agent Dns Incident Techengage |
    Tech News & AnalysisOpenAI pauses advanced-model research after agent bypasses network restrictionsSep 27, 2026
  • Ai Markets Feat |
    AIThree CEOs Asked to Slow Down. The President Said No and the Market Fell 3 Percent. Hassan Taher on What Actually Happened.Sep 21, 2026
  • Iphone 18 Pro Availability Sept 18 |
    Tech News & AnalysisiPhone 18 Pro and Pro Max Available Today in 65+ CountriesSep 18, 2026

More in Security & Privacy

  • Openai Agent Dns Incident Techengage |
    OpenAI pauses advanced-model research after agent bypasses network restrictionsSep 27, 2026
  • Photo 2023 05 23 19 03 36 Jpg |
    5 Internet Security Suites to Get For Fortifying Your Internet SecurityMay 24, 2023
  • Google Authenticator Gets Cloud Backup Support Jpg |
    Google Authenticator finally gets most awaited cloud sync featureApr 26, 2023
  • Uk Twitter Accounts Hacked Abdugeek Jpg |
    Twitter’s SMS 2FA is going away today, switch before it’s too lateMar 20, 2023
More Security & Privacy stories →

Footer

Discover

  • About TechEngage
  • Company News & Updates
  • Our Team
  • Advertise
  • Send us a tip
  • Submit your company to TechEngage Launchpad Hot
  • TechEngage Brand Kit
  • Contact us
  • Tools & Calculators

Legal pages

  • Editorial Standards
  • Reviews Policy
  • Our Ethics
  • Corrections Policy
  • Affiliate Disclosure
  • Privacy Policy
  • Cookies Policy
  • Terms & Conditions
  • GDPR Compliance
  • Copyright & DMCA

Must reads

  • Best Mechanical Keyboards Under $100
  • Best USB-C Hubs
  • Best Portable SSDs
  • Best Gaming Graphics Cards (GPUs)
  • Best Long-Range Outdoor WiFi Extenders
  • Best Wireless CarPlay Adapters
  • Best Slack Alternatives
  • Best Long-Range Walkie-Talkies

About TechEngage

TechEngage® is an independent technology publication covering tech news, reviews and buying guides.

Founded
2003
Publisher
TechAbout LLC
ISSN
2690-3776
Google NewsRSS feed

© 2026 TechEngage®. All Rights Reserved. TechEngage® is a project of TechAbout LLC.

TechEngage® is a registered trademark in the United States under Trademark Number 6823709 and in the United Kingdom under Trademark Number UK00003417167. It is also ISSN protected under ISSN 2690-3776 and has OCLC Number 1139335774.

Contact team@techengage.com · WhatsApp +1-307-381-8801

Your analytics choice
Allow Google Analytics to help us understand readership? You can use the site without it and change this choice anytime.

Privacy details