The 'Tekya' malware, as researchers call it, is designed to imitate the user's actions to click advertisements.

Dark Reading Staff, Dark Reading

March 25, 2020

1 Min Read

A new malware family has been discovered operating in 56 Google Play applications, which have collectively been downloaded nearly one million times around the world. Dubbed "Tekya," the malware aims to commit mobile ad fraud by imitating user actions to click advertisements.

Check Point researchers say 24 of these infected apps are designed for children; for example, puzzles or racing games. The rest are utility apps: calculators, translators, and cooking apps, for example. Tekya obfuscates native code to evade Google Play Protect detection, and it uses the MotionEvent mechanism built into Android to imitate the user's actions and generate clicks for ads from agencies like Google's AdMob, AppLovin', Facebook, and Unity, researchers report.

The Tekya campaign built its audience by cloning legitimate popular applications, especially children's apps, which were most popular for this particular malware. All of the infected apps have been removed from Google Play. If you think you may have one of these malicious apps on your device, researchers recommend uninstalling the affected app and updating the device's operating system and applications. 

Read more details here.

Edgepromohorizontal.jpgCheck out The Edge, Dark Reading's new section for features, threat data, and in-depth perspectives. Today's featured story: "Three Ways Your BEC Defense Is Failing & How to Do Better."

About the Author(s)

Dark Reading Staff

Dark Reading

Dark Reading is a leading cybersecurity media site.

Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like


More Insights