​FalseGuide malware victim count jumps to 2 million

android malware

An estimated 2 million Android users have now fallen victim to malware mistakenly downloaded from Google Play, which was initially reported to have affected approximately 600,000 users.

The malware, dubbed FalseGuide, was hidden in more than 40 guide apps for games, the oldest of which was uploaded to Google Play as early as November last year, security researchers from Check Point said.

ADVERTISEMENT

“Since April 24, when the article below was first published, Check Point researchers learned that the FalseGuide attack is far more extensive than originally understood,” Check Point said.

“The apps were uploaded to the app store as early as November 2016, meaning they hid successfully for five months, accumulating an astounding number of downloads.”

The security firm said it found five additional apps containing the malware on Google Play, developed by “Анатолий Хмеленко” — translated as Anatoly Khmelenko — since it made its findings public.

The malware was hidden in fake companion guide applications for popular games including Pokémon Go and FIFA Mobile, and Check Point initially reported that several of these fake guides had been downloaded more than 50,000 times. It creates a silent botnet out of the infected devices for adware purposes.

Once downloaded onto a device, FalseGuide requests device admin permission, which the malware uses to ensure the app cannot be deleted by the user — an activity that usually suggests the app is likely to be malicious.

The malware then registers itself to a Firebase Cloud Messaging topic — a cross-platform service that allows developers to send notifications and messages — which has the same name as the app. Once subscribed to the topic, Check Point said FalseGuide can receive messages containing links to additional modules and download them to the infected device.

“Depending on the attackers’ objectives, these modules can contain highly malicious code intended to root the device, conduct a DDoS attack, or even penetrate private networks,” the security firm wrote earlier this week.

Check Point believes the malicious apps are of Russian origin as the first batch were submitted under the Russian names of two fake developers, Sergei Vernik and Nikolai Zalupkin.

(via PCMag)



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


ADVERTISEMENT
Social Media Auto Publish Powered By : XYZScripts.com
Just in:
Cisco flaw hit before public warning // ClawHub breach exposes agent marketplace risk // Bracell Welcomes Fernando Branco’s Appointment to Lead ABAF and Reinforces Commitment to Sustainable Forestry Development in Bahia // Abu Dhabi starts new Saadiyat arts landmark // 5 Law Firms Making a Difference in Cincinnati // Construction Management Awards 2026 – Now open for nomination Introduction of the Inaugural “Excellent Construction Safety Culture Award” Guides the Construction Industry Toward a New Milestone in Safety // Altcoins resist as Bitcoin absorbs June shock // BOCHK expo spotlights Hong Kong wealth shift // Canvas breach sharpens UK campus cyber warning // Ras Tanura crash kills Aramco personnel // PlayStation sales hit May low // Hormuz attack strains fragile US-Iran truce // XRG and Eni deepen Argentina LNG push // Most UAE expats under-insured, reveals survey // Cheap RAT spreads through Telegram channels // Bank of China (Hong Kong) x Television Broadcasts Limited (“TVB”) “Wealth Management Expo 2026” was Successfully Held // Cloud bucket flaw exposes silent data theft risk // TCL Supports “2026 Olympic Day cum Aichi-Nagoya Asian Games Fun Run”, Celebrating the Olympic Spirit with Athletes and the Public, and Offering Lucky Draw Prizes Worth Approximately HK$180,000 // Afogreen Build Highlights Growing Adoption of Building Performance Modelling in Australia’s Sustainability-Driven Construction Sector // Anthropic reopens Mythos 5 for cyber defenders //