News

Tip From Child Uncovers Adware Scam Apps Totalling 2.4 Million Downloads

Giulio Saggin
Giulio Saggin
Tuesday 28 November 2023

A tip from a child has led to the discovery of seven adware scam apps available on the Apple App Store and Google Play Store.

The apps have been downloaded more than 2.4 million times and raked in at least half a million dollars for those behind the scam, which was uncovered when the child, a 12yo girl, became suspicious of an app promoted on a TikTok profile. She reported it to Avast’s "Be Safe Online" project, which educates children in the Czech Republic on how to stay safe online, which then discovered further scam apps.

"The apps are specifically targeted to young people ... (and) come in the form of either charging $2 to $10 for a service that doesn’t meet that price point, including causing the phone to vibrate, a wallpaper, or access to music," wrote Avast in a blog. "The apps ... violate both Google’s and Apple’s app policies by either making misleading claims around app functionalities, or serving ads outside of the app and hiding the original app icon soon after the app is installed."

At least three TikTok profiles, one of which has in excess of 300,000 followers, were found pushing the apps, while an Instagram account promoting one of the apps had more than 5,000 followers.

"It is particularly concerning that the apps are being promoted on social media platforms popular among younger kids, who may not recognize some of the red flags surrounding the apps and therefore may fall for them," said Avast.

Avast has reported the apps to Apple and Google and the accounts to TikTok and Instagram.

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203