Apple removed 17 apps from the App Store this week after researchers discovered that the apps were infected with malware.
The apps in question were discovered by mobile security company Wandera and were published by the company AppAspect Technologies. While all of the apps did what they claimed to do in the app store, they also had some pretty gnarly things going on in the background:
“The clicker trojan module discovered in this group of applications is designed to carry out ad fraud-related tasks in the background, such as continuously opening web pages or clicking links without any user interaction,” Wandera explains.”The objective of most clicker trojans is to generate revenue for the attacker on a pay-per-click basis by inflating website traffic. They can also be used to drain the budget of a competitor by artificially inflating the balance owed to the ad network.”
While malicious, the only impact to users would have been slower phone performance and inflated data use. The apps were able to bypass Apple’s approval process because the malicious activity was happening not within the app’s code, but rather through contact with a remote server.
We’ve reached out to AppAspect to see if they’re working on fixing the malware and will update this story if we hear back.
Wandera notes that while it found 17 apps by AppAspect that were infected by malware, the company currently has 51 apps in the App Store. The company tested the free apps offered by the company, which is where it found the 17 infected apps. The 18 other free apps offered by the company in the App Store are not currently infected with malware.
Wandera notes that Android apps that were communicating the same server as the infected iOS apps were also gathering private information such as the make & model of the device, the user’s country of residence, and some configuration details.
That said, those Android apps were not ones made by AppAspect. AppAspect currently has 28 published apps on Google Play, none of which appear to be communicating with the malicious server.
Related Posts
Android phones can warn you if you open financial apps during a scam call
Whenever Android detects that you are on a call with a number not saved in your contacts, and you open a supported financial app, it will trigger a protective alert.
Your phone can now tell you when a text looks like a scam
Since our messaging apps are constantly getting hammered with sophisticated fraud - from those fake "delivery fee" demands to weird promises of free money - Google is stepping in to help you spot the fakes at a glance.
Your notifications just got smarter and quieter with Google’s new update
Right now, this is hitting Pixel devices, with Samsung, OnePlus, and others expected to catch up soon (likely via updates like One UI 8.5). This isn't just a bug fix; it’s a serious upgrade list. We’re talking AI-powered notification summaries, a smart Notifications Organizer that cleans up your shade, auto-themed icons that actually match your wallpaper, and a much smarter dark mode.