Google Play CallJam Malware Infects Half A Million Users

Android malware has been uncovered lurking on the Google Play app store that poses as a game while making calls to premium-rate numbers in the background.

The CallJam malware was spotted by computer security researchers Check Point and is the latest found to have infiltrated the Google Play online shop in spite of Google’s screening procedures.

Google Play infected

The game remained on Google Play until the company was notified by Check Point, in spite of users pointing out its deceptive activities in comments such as: “It dialled a wrong international number. Continuously. Wtf.”

The malware, which posed as a game called ‘Gems Chest for Clash Royale’, had been removed from Google Play’s listings as of Monday, but Check Point said it had already been downloaded between 100,000 to 500,000 times since it was placed there in May.

Aside from the dialling agent, the malware also sends victims to malicious websites that display revenue-generating advertisements.

CallJam does not make use of any complex hacks to make its calls, simply asking the targeted user for permission to do so, Check Point noted.

Permissions

“Most users grant permissions willingly, often without reading or fully understanding information about the permissions they are granting,” the firm said in an advisory.

The malware was able to gain a high user rating of four out of five by forcing users to rate it before they could begin playing.

“This is another reminder that attackers can develop high-reputation apps and distribute them on official app stores, putting devices and sensitive data at risk,” Check Point said.

Are you a security pro? Try our quiz!

Matthew Broersma

Matt Broersma is a long standing tech freelance, who has worked for Ziff-Davis, ZDnet and other leading publications

Recent Posts

Creating Deepfake Porn Without Consent To Become A Crime

People who create sexually explicit ‘deepfakes’ of adults will face prosecution under a new law…

12 hours ago

Google Fires 28 Staff Over Israel Protest, Undertakes More Layoffs

Protest at cloud contract with Israel results in staff firings, in addition to layoffs of…

13 hours ago

Russia Already Meddling In US Election, Microsoft Warns

Microsoft warns of Russian influence campaigns have begun targetting upcoming US election, albeit at a…

14 hours ago

EU To Drop Microsoft’s OpenAI Investment Probe – Report

Microsoft to avoid an EU investigation into its $13 billion investment in OpenAI, after EC…

18 hours ago

US Provides Assurances For Julian Assange Extradition

As President Biden 'considers' request to drop Julian Assange extradition, US provides assurances to prevent…

20 hours ago