Malicious Android 'Vapor' apps on Google Play installed 60 million times
Published on: 2025-06-11 17:52:53
Over 300 malicious Android applications downloaded 60 million items from Google Play acted as adware or attempted to steal credentials and credit card information.
The operation was first uncovered by IAS Threat Lab, who categorized the malicious activity under the name "Vapor" and said it has been ongoing since early 2024.
IAS identified 180 apps as part of the Vapor campaign, generating 200 million fraudulent advertising bid requests daily to engage in large-scale ad fraud.
A newly published report by Bitdefender increased the number of malicious apps to 331, reporting many infections in Brazil, the United States, Mexico, Turkey, and South Korea.
"The apps display out-of-context ads and even try to persuade victims to give away credentials and credit card information in phishing attacks," warns Bitdefender.
Although all of these apps have since been removed from Google Play, there's a significant risk that Vapor will return through new apps as the threat actors have already demo
... Read full article.