{"id":90707,"date":"2025-05-10T18:30:08","date_gmt":"2025-05-10T18:30:08","guid":{"rendered":"https:\/\/www.europesays.com\/uk\/90707\/"},"modified":"2025-05-10T18:30:08","modified_gmt":"2025-05-10T18:30:08","slug":"delete-any-apps-on-your-phone-that-are-on-this-list","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/uk\/90707\/","title":{"rendered":"Delete Any Apps On Your Phone That Are On This List"},"content":{"rendered":"<p class=\"color-body light-text\" role=\"button\">You have been warned \u2014 get deleting.<\/p>\n<p>Getty<\/p>\n<p>Update: Republished on May 10 with new warnings into high-risk apps. <\/p>\n<p>A serious threat to Android users has been revealed today, with as many as 2.5 million dangerous apps being installed each and every month. The apps have a nasty trick that fools users into the initial download, and once on a phone, the damage is done. There\u2019s a new list of apps to delete, but there\u2019s also a simple warning that will help keep you safe.<\/p>\n<p>The new report comes courtesy of <a class=\"color-link\" href=\"https:\/\/go.integralads.com\/rs\/469-VBI-606\/images\/AMER_Threat_Lab_Kaleidoscope_Report_IAS.pdf\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/go.integralads.com\/rs\/469-VBI-606\/images\/AMER_Threat_Lab_Kaleidoscope_Report_IAS.pdf\" aria-label=\"Integral Ad Science,\">Integral Ad Science,<\/a> the same team that warned of the \u201c<a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/03\/05\/googles-play-store-deletion-do-not-keep-all-these-apps-on-your-phone\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/03\/05\/googles-play-store-deletion-do-not-keep-all-these-apps-on-your-phone\/\" target=\"_self\" aria-label=\"Vapor\" rel=\"noopener\">Vapor<\/a>\u201d attacks on Android phones in March. This new threat is dubbed \u201cKaleidoscope \u2014 due to its constant transformations as it tries to evade detection and analysis.&#8221; The name has changed but the threat is broadly the same.<\/p>\n<p>The cyber criminals behind this latest ad fraud machine plant benign apps on Google\u2019s Play Store that contain none of their malicious code. They then distribute malicious replicas of those apps through third-party app stores and direct installs. Users are directed to those duplicates via messaging and social media channels. To users, it seems that they\u2019re downloading a legitimate app through an ad or promotion. And to advertisers, it seems their ad impressions are coming from legitimate apps.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-4\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/05\/08\/google-starts-scanning-screenshots-for-location-data-you-must-now-decide\/\" target=\"_blank\" aria-label=\"Google\u2019s New Update Scans Your Screenshots For Locations\" rel=\"noopener noreferrer\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/05\/08\/google-starts-scanning-screenshots-for-location-data-you-must-now-decide\/\">ForbesGoogle\u2019s New Update Scans Your Screenshots For LocationsBy Zak Doffman<\/a><\/p>\n<p>The attackers\u2019 payday comes via those advertisers who have no idea their ads are being pushed out at an industrial scale to infected phones, where they disrupt the normal use of the phone to generate impressions which turn to cash. &#8220;The malicious app delivers intrusive out-of-context ads under the guise of the benign app ID in the form of full-screen interstitial images and videos, triggered even without user interaction.\u201d<\/p>\n<p>The SDK driving this malicious behavior has been updated and has now even been retrospectively added into apps that were previously caught doing the same. They now have a differently named SDK at their core. <a class=\"color-link\" href=\"https:\/\/go.integralads.com\/rs\/469-VBI-606\/images\/Kaleidoscope_IOCs_IAS.pdf\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/go.integralads.com\/rs\/469-VBI-606\/images\/Kaleidoscope_IOCs_IAS.pdf\" aria-label=\"The infected apps are on this list\">The infected apps are on this list<\/a>.<\/p>\n<p>This type of threat is well established. A year ago, I reported on the \u201c<a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2024\/07\/17\/samsung-galaxy-google-pixel-android-users-delete-these-evil-play-store-apps\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/zakdoffman\/2024\/07\/17\/samsung-galaxy-google-pixel-android-users-delete-these-evil-play-store-apps\/\" target=\"_self\" aria-label=\"evil twin\" rel=\"noopener\">evil twin<\/a>\u201d attacks flagged by Human Security, which warned that the \u201c<a class=\"color-link\" href=\"https:\/\/www.humansecurity.com\/newsroom\/human-discovers-konfety-ad-fraud-operation-wielding-novel-evil-twin-evasion-method\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.humansecurity.com\/newsroom\/human-discovers-konfety-ad-fraud-operation-wielding-novel-evil-twin-evasion-method\/\" aria-label=\"Konfety\">Konfety<\/a>\u201d ad fraud operation had deployed as many as 250 decoy apps on Play Store. Those legitimate and malicious apps shared a common \u201cCaramelSDK\u201d reference which aided detection and mitigation. Those references have been removed, albeit the original threat itself has not gone away.<\/p>\n<p>IAS says it \u201canalyzed both earlier and newer versions of benign and malicious variants associated with this scheme, examining previously known apps as well as newly discovered ones involved in this evolving threat.\u201d<\/p>\n<p>Google has removed flagged apps from Play Store and assures Play Protect will safeguard users from known versions of the threat. But this is a sideloading problem and an industry problem. \u201cThe entities behind Kaleidoscope have successfully identified a network of resellers who are not particularly diligent in vetting the quality of the inventory they deliver to advertisers, enabling them to effectively launder their traffic.\u201d<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-5\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/05\/08\/check-your-phone-before-apps-stop-working-this-month\/\" target=\"_blank\" aria-label=\"Check For Update On Your Phone\u2014Apps Stop Working This Month\" rel=\"noopener noreferrer\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/05\/08\/check-your-phone-before-apps-stop-working-this-month\/\">ForbesCheck For Update On Your Phone\u2014Apps Stop Working This MonthBy Zak Doffman<\/a><\/p>\n<p>Advice on staying safe is simple. If you\u2019re in the habit of sideloading, then scan the list of infected apps and delete any you recognize. Then take care on how many such third-party or direct installs you allow onto your phone.<\/p>\n<p>Sideloading has never been more under threat than now. It remains one of the key differentiators between Android and iPhone, notwithstanding Apple has again just been given 90 days to allow sideloading in Brazil. This follows the more significant EU ruling in Europe and the more material (financially at least) Epic Games ruling in the U.S.<\/p>\n<p>Google has clamped down on sideloading in Android 15, making it harder at least. And Samsung has gone further with One UI 7, its Android 15 wrap, expanding its default maximum restrictions to do all it can to deter users from installs outside main stores.<\/p>\n<p>\u201cI no longer seem to be bothered about the ability to sideload apps,\u201d <a class=\"color-link\" href=\"https:\/\/indianexpress.com\/article\/technology\/opinion-technology\/sideloading-android-apps-2025-benefits-risks-9990383\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/indianexpress.com\/article\/technology\/opinion-technology\/sideloading-android-apps-2025-benefits-risks-9990383\/\" aria-label=\"explained one newspaper columnist this weekend\">explained one newspaper columnist this weekend<\/a>. \u201cIt\u2019s just too risky in 2025, and I\u2019ve heard the same from quite a few Android loyalists who now stay away from sideloading for one specific reason \u2014 security.\u201d And this despite that same columnist \u201cpicking the OnePlus 13, my current daily driver, for multiple reasons; primarily for the fact that it\u2019s an Android-powered device that allows sideloading.\u201d<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-6\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/05\/08\/googles-gmail-warning-if-you-see-this-message-its-an-attack\/\" target=\"_blank\" aria-label=\"Google\u2019s Gmail Warning\u2014If You See This Message It\u2019s An Attack\" rel=\"noopener noreferrer\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/05\/08\/googles-gmail-warning-if-you-see-this-message-its-an-attack\/\">ForbesGoogle\u2019s Gmail Warning\u2014If You See This Message It\u2019s An AttackBy Zak Doffman<\/a><\/p>\n<p>Sideloading makes this type of ad fraud possible. It relies on users downloading the malicious replica apps from direct links or third-party stores, and whole there\u2019s a Play Store dimension to this, it\u2019s those replica installs that do all the damage.<\/p>\n<p>When Europe pushed Apple to open up to other app stores, the <a class=\"color-link\" href=\"https:\/\/developer.apple.com\/support\/dma-and-apps-in-the-eu\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/developer.apple.com\/support\/dma-and-apps-in-the-eu\/\" aria-label=\"iPhone-maker warned\">iPhone-maker warned<\/a> the change &#8220;brings greater risks to users and developers. This includes new avenues for malware, fraud and scams, illicit and harmful content, and other privacy and security threats. These changes also compromise Apple\u2019s ability to detect, prevent, and take action against malicious apps on iOS and iPadOS, and to support users impacted by issues with apps downloaded outside of the App Store.&#8221;<\/p>\n<p>This latest threat presents those risks, &#8220;a sophisticated evolution in ad fraud,&#8221; IAS says, \u201cwhere threat actors continually adapt to evade detection and extend the scheme\u2019s reach. By rebranding their SDKs, shifting command-and-control infrastructure, and embedding malicious capabilities into benign-appearing applications, these threat actors demonstrate a relentless focus on circumventing defenses.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"You have been warned \u2014 get deleting. Getty Update: Republished on May 10 with new warnings into high-risk&hellip;\n","protected":false},"author":2,"featured_media":90708,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3159],"tags":[26516,633,547,4692,43022,43021,4693,53,16,15],"class_list":{"0":"post-90707","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-mobile","8":"tag-android-warning","9":"tag-google-warning","10":"tag-mobile","11":"tag-pixel-warning","12":"tag-play-store-deletion","13":"tag-play-store-warning","14":"tag-samsung-warning","15":"tag-technology","16":"tag-uk","17":"tag-united-kingdom"},"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@uk\/114484964533145865","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts\/90707","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/comments?post=90707"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts\/90707\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/media\/90708"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/media?parent=90707"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/categories?post=90707"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/tags?post=90707"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}