Cybersicherheit

Dangerous Android Malware: “Vapor” Apps Infected Millions of Devices

A large-scale malware campaign known as “Vapor” has reached over 60 million downloads on Google Play. More than 300 malicious Android apps served either as adware or attempted to steal login credentials and credit card information. Although Google has since removed all affected apps, the threat remains, as the attackers have already proven they can bypass Google’s security checks.

Background of the “Vapor” Campaign

The malware campaign was first discovered by the security firm IAS Threat Lab, which identified 180 infected apps. These apps generated around 200 million fraudulent ad requests per day, pointing to a far-reaching ad fraud network. A new report from Bitdefender raised the number of affected apps to 331 and found that infections were especially common in Brazil, the United States, Mexico, Turkey and South Korea.

Most Vapor apps were published on Google Play between October 2024 and January 2025. Individual uploads, however, continued until March 2025. The apps were uploaded through various developer accounts to minimize the risk of a mass ban. In addition, they used different advertising SDKs to make detection more difficult.

How the Malware Works and Spreads

The malicious apps disguised themselves as useful programs such as fitness trackers, note-taking apps, battery optimizers or QR code scanners. When submitted to the Google Play Store, they initially contained no malicious functions, allowing them to pass the security review without issue. Only after installation did they download malicious code from a command-and-control server (C2).

The most prominent infected apps included, among others:

  • AquaTracker – 1 million downloads
  • ClickSave Downloader – 1 million downloads
  • Scan Hawk – 1 million downloads
  • Water Time Tracker – 1 million downloads
  • Be More – 1 million downloads
  • BeatWatch – 500,000 downloads
  • TranslateScan – 100,000 downloads
  • Handset Locator – 50,000 downloads

After installation, the apps disabled their launcher activity, causing them to disappear from the app overview. In some cases, they changed their name in the settings and posed as legitimate Google services such as “Google Voice.” They used native code techniques to bypass the security measures of Android 13+ and concealed their activities through the use of hidden background processes.

Impact and Fraud Mechanisms

The Vapor apps were primarily designed for ad fraud. They forced the display of advertisements through screen overlays that could not be closed easily. In the process, the “back” button was disabled and the apps were removed from the “recent apps” view, so users often could not determine which app was triggering the ads.

Some of the apps, however, went even further: they displayed fake login pages for Facebook and YouTube to steal credentials. Others prompted users to enter credit card information by posing as reputable payment processors.

Protective Measures and Google’s Response

After the malware was discovered, Google removed all identified apps from the Play Store. A company spokesperson confirmed that Android users are automatically protected by Google Play Protect. This protection mechanism is enabled by default on all devices with Google Play services.

Security researchers warn, however, that similar malware campaigns can resurface at any time. Users should therefore be cautious and only install apps from trustworthy sources. It is advisable to carefully review the permissions of every app and to regularly compare the list of installed applications with the apps actually visible in the app drawer.

If one of the affected apps has already been installed, users should uninstall it immediately and run a full scan with Google Play Protect or other security software.

The Vapor campaign once again shows that even the official Google Play Store offers no absolute protection against malware. Cybercriminals are increasingly using sophisticated methods to distribute malicious apps and circumvent protection mechanisms. A combination of technical safeguards and prudent user behavior remains the best way to protect against such threats.

Mastodon
Scroll to Top