Exposed: 60 Million Downloads of Dangerous ‘Vapor’ Android Apps Stealing Credit Cards and Credentials


# Massive Android Malware Campaign Affects 60 Million Downloads from Google Play

A sophisticated malware operation dubbed “Vapor” has infected over 300 Android applications with a combined 60 million downloads from Google Play. These malicious apps primarily functioned as adware but some also attempted to steal user credentials and credit card information through phishing attacks.

## Campaign Details

First discovered by IAS Threat Lab in early 2024, the campaign initially identified 180 apps generating approximately 200 million fraudulent advertising bid requests daily. Bitdefender’s subsequent investigation expanded the count to 331 malicious applications, with significant infection rates in Brazil, the United States, Mexico, Turkey, and South Korea.

While Google has removed all identified apps from the Play Store, security researchers warn that the threat actors have demonstrated their ability to bypass Google’s review process, suggesting Vapor may return through new applications.

## How the Malware Works

The malicious apps masqueraded as legitimate utilities including:
– Health and fitness trackers
– Note-taking tools
– Battery optimizers
– QR code scanners

These apps successfully passed Google’s security reviews by including the advertised functionality without malicious components at submission time. The malware was delivered post-installation through updates from command and control servers.

Popular infected apps included:
– AquaTracker (1 million downloads)
– ClickSave Downloader (1 million downloads)
– Scan Hawk (1 million downloads)
– Water Time Tracker (1 million downloads)
– Be More (1 million downloads)

## Sophisticated Evasion Techniques

After installation, Vapor apps employ several techniques to hide their presence:
– Disabling their launcher activity to become invisible
– Renaming themselves to appear as legitimate system apps
– Launching without user interaction
– Using native code to enable hidden components
– Bypassing Android 13+ security protections
– Creating fullscreen overlays that display ads with no exit option
– Removing themselves from “Recent Tasks”

Some variants displayed fake login screens for popular platforms like Facebook and YouTube to steal credentials or prompted users to enter credit card information.

## Protection Recommendations

Users should:
– Avoid installing unnecessary apps from unknown publishers
– Scrutinize app permissions
– Compare the app drawer with the installed apps list in Settings
– Remove any identified malicious apps immediately
– Run a complete system scan with Google Play Protect

The complete list of all 331 malicious apps is available through Bitdefender’s report.

Share This Article