- Feb 4, 2016
- 2,520
...some quotes from the articlae above:
Experts say that during the past two years, millions of users appear to have downloaded and installed apps infected with one of these three AdDown adware versions. Trend Micro researcher Ecular Xu said AdDown was distributed to various app developers as an advertising SDK, which explains why it was found in so many apps. Xu published a list of apps previously infected, but which have now removed AdDown from their code:
Seventy-five apps available for download from the official Google Play Store had to remove a malicious advertising library that was secretly an adware called AdDown, which Trend Micro researchers have been tracking for the last two years.
This adware appeared in January 2015 and besides showing ads to infected users, it also came with the ability to collect personal data on its victims, and at one point could even secretly install apps without the user's knowledge.
Over time, Trend Micro says it detected the adware in over 800 apps that were uploaded on the Play Store, usually as small utility apps, such as wallpaper changers, photo editors, and flashlight apps.
The first stage of evolution featured the simplest version of the adware, but was also the one with the most intrusive features, coming equipped with a method of installing apps behind the user's back.
The third and last stage of AdDown was first detected starting with September 2016, and while it generally improved the second stage's features, it also added support for detecting and evading sandbox environments.