• News/
  • https://www.bleepingcomputer.com/news/security/malicious-android-vapor-apps-on-google-play-installed-60-million-times/

Malicious Android 'Vapor' apps on Google Play installed 60 million times

BleepingComputer
·
Bill Toulas
·
Published Mar 18, 2025
·
Updated

Over 300 malicious Android applications downloaded 60 million items from Google Play acted as adware or attempted to steal credentials and credit card information. The operation was first uncovered by IAS Threat Lab, who categorized the malicious activity under the name "Vapor" and said it has been ongoing since early 2024. IAS identified 180 apps as part of the Vapor campaign, generating 200 million fraudulent advertising bid requests daily to engage in large-scale ad fraud. A newly published report by Bitdefender increased the number of malicious apps to 331, reporting many infections in Brazil, the United States, Mexico, Turkey, and South Korea. "The apps display out-of-context ads and even try to persuade victims to give away credentials and credit card information in phishing attacks," warns Bitdefender. Although all of these apps have since been removed from Google Play, there's a significant risk that Vapor will return through new apps as the threat actors have already demonstrated the ability to bypass Google's review process. The apps used in the Vapor campaign are utilities offering specialized functionality like health and fitness tracking, note-taking tools and diaries, battery optimizers, and QR code scanners. The apps pass Google's security reviews because they include the promoted functionality and do not contain malicious components at the time of submission. Instead, the malware functionality is downloaded post-installation via updates delivered from a comma...

Read full article

Affected Software

3 affected components
Google Google Play
Android Android apps
Google Android
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the discovery of over 300 malicious Android apps on Google Play that were downloaded 60 million times.

2

What type of threats do these malicious apps pose?

The malicious apps act as adware or attempt to steal users' credentials and credit card information.

3

Who uncovered this operation involving the malicious apps?

The operation was first uncovered by IAS Threat Lab.

4

Which platforms are affected by these malicious Android apps?

The affected platforms include Google Play and Android mobile devices.

5

How many times were these malicious apps downloaded?

These malicious Android apps were installed approximately 60 million times.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203