{"id":51910,"date":"2016-08-10T00:23:28","date_gmt":"2016-08-10T07:23:28","guid":{"rendered":"https:\/\/blogs.mcafee.com\/?p=51910"},"modified":"2025-06-03T20:46:46","modified_gmt":"2025-06-04T03:46:46","slug":"obfuscated-malware-discovered-google-play","status":"publish","type":"post","link":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/obfuscated-malware-discovered-google-play\/","title":{"rendered":"Obfuscated Malware Discovered on Google Play"},"content":{"rendered":"<p>The McAfee Labs Mobile Malware Research team found early this week on Google Play a set of malware published by the developer account ValerySoftware:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-51921 size-full\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/20160809-Google-Play-malware-1.png\" alt=\"20160809 Google Play malware 1\" width=\"1207\" height=\"786\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/20160809-Google-Play-malware-1.png 1207w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/20160809-Google-Play-malware-1-300x195.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/20160809-Google-Play-malware-1-768x500.png 768w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/20160809-Google-Play-malware-1-1024x667.png 1024w\" sizes=\"auto, (max-width: 1207px) 100vw, 1207px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-51920 size-full\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/20160809-Google-Play-malware-2.png\" alt=\"20160809 Google Play malware 2\" width=\"1194\" height=\"1047\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/20160809-Google-Play-malware-2.png 1194w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/20160809-Google-Play-malware-2-300x263.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/20160809-Google-Play-malware-2-768x673.png 768w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/20160809-Google-Play-malware-2-1024x898.png 1024w\" sizes=\"auto, (max-width: 1194px) 100vw, 1194px\" \/><\/p>\n<p>Each one of these apps have been downloaded and installed up to 500 times, which means up to 3,000 devices could be infected by this threat.<\/p>\n<h2>Some characteristics of this malware:<\/h2>\n<ul>\n<li>Encrypted and obfuscated at many levels<\/li>\n<li>Downloads APK files from external sources<\/li>\n<li>Tries to install apps from Google Play without user interaction<\/li>\n<li>Displays or silently accesses ads from multiple vendors of advertisement development kits<\/li>\n<li>Leaks sensitive information<\/li>\n<li>Receives commands to open and close applications<\/li>\n<li>Receives commands to install and uninstall applications<\/li>\n<\/ul>\n<p>Negative user reviews on the market are likely caused by the fact that these malicious apps provide no features at all. This Trojan pretends to be a game patch but is only a WebView function that locally loads a couple of HTML resources after requesting device admin privileges\u2014probably to avoid uninstallation after its disappointing execution:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-51919 size-medium\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/20160809-Google-Play-malware-3a-187x300.png\" alt=\"20160809 Google Play malware 3a\" width=\"187\" height=\"300\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/20160809-Google-Play-malware-3a-187x300.png 187w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/20160809-Google-Play-malware-3a.png 449w\" sizes=\"auto, (max-width: 187px) 100vw, 187px\" \/> <img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-51918 size-medium\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/20160809-Google-Play-malware-3b-187x300.png\" alt=\"20160809 Google Play malware 3b\" width=\"187\" height=\"300\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/20160809-Google-Play-malware-3b-187x300.png 187w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/20160809-Google-Play-malware-3b.png 466w\" sizes=\"auto, (max-width: 187px) 100vw, 187px\" \/> <img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-51917 size-medium\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/20160809-Google-Play-malware-3c-186x300.png\" alt=\"20160809 Google Play malware 3c\" width=\"186\" height=\"300\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/20160809-Google-Play-malware-3c-186x300.png 186w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/20160809-Google-Play-malware-3c.png 466w\" sizes=\"auto, (max-width: 186px) 100vw, 186px\" \/><\/p>\n<p>In the background, however, the malware loads and decrypts multiple .dex files to start malicious activities that go unnoticed.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-51916 size-full\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/20160809-Google-Play-malware-4.jpg\" alt=\"20160809 Google Play malware 4\" width=\"625\" height=\"343\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/20160809-Google-Play-malware-4.jpg 625w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/20160809-Google-Play-malware-4-300x165.jpg 300w\" sizes=\"auto, (max-width: 625px) 100vw, 625px\" \/><\/p>\n<p>The payload is obfuscated at many levels with a packer, an executable and linkable format (ELF) binary crafted to decrypt the malicious code from a file stored in the asset directory of the APK. The name of the assets.dat files, binary ELF, and classes related to the malware functionality are random to avoid detection. The strings are obfuscated inside the ELF binary and the encrypted malicious .dex files.<\/p>\n<p>For example, a JSON file that contains URLs of control servers is obfuscated in the decrypted .dex file that is dynamically loaded by the original .dex:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-51915 size-full\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/20160809-Google-Play-malware-5.png\" alt=\"20160809 Google Play malware 5\" width=\"840\" height=\"222\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/20160809-Google-Play-malware-5.png 840w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/20160809-Google-Play-malware-5-300x79.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/20160809-Google-Play-malware-5-768x203.png 768w\" sizes=\"auto, (max-width: 840px) 100vw, 840px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-51914 size-full\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/20160809-Google-Play-malware-6.png\" alt=\"20160809 Google Play malware 6\" width=\"1013\" height=\"296\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/20160809-Google-Play-malware-6.png 1013w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/20160809-Google-Play-malware-6-300x88.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/20160809-Google-Play-malware-6-768x224.png 768w\" sizes=\"auto, (max-width: 1013px) 100vw, 1013px\" \/><\/p>\n<p>Based in the domain owner\u2019s information in this malware, we can tie the authors to a group of known cybercriminals in Europe who host and distribute malware.<\/p>\n<p>To pass unnoticed, the malware authors incorporated antiemulation techniques in the malicious code so the behavior could not be detected by automated dynamic test environments.<\/p>\n<p>Some web resources such as png images, JavaScript, and HTML code are inside the .dex files though coded in Base64. These resources are related to banners and ads that the malware can selectively display. These resources are not possible to observe in the main APK without decrypting the third .dex file, classes3.dex.<\/p>\n<p>The authors have Trojanized apps created with the Android Robo Templates framework to gain revenue from multiple ad libraries that are injected in the payload .dex, denoted in the following configuration class:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-51913 size-full\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/20160809-Google-Play-malware-7.png\" alt=\"20160809 Google Play malware 7\" width=\"935\" height=\"426\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/20160809-Google-Play-malware-7.png 935w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/20160809-Google-Play-malware-7-300x137.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/20160809-Google-Play-malware-7-768x350.png 768w\" sizes=\"auto, (max-width: 935px) 100vw, 935px\" \/><\/p>\n<p>From the main .dex file we can observe a downloader listener class that is ready to download APKs from a given URL. In the red boxes we see other injected classes from the malware:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-51912 size-full\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/20160809-Google-Play-malware-8.png\" alt=\"20160809 Google Play malware 8\" width=\"1553\" height=\"489\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/20160809-Google-Play-malware-8.png 1553w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/20160809-Google-Play-malware-8-300x94.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/20160809-Google-Play-malware-8-768x242.png 768w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/20160809-Google-Play-malware-8-1024x322.png 1024w\" sizes=\"auto, (max-width: 1553px) 100vw, 1553px\" \/><\/p>\n<p>Although Google has been successful in improving the policing of malicious apps, this threat is a reminder that malware can still be present even in official stores. Your first check before installing an app should be reviews by other users. Also check that permissions the app requests are related to its functionality, and review the developer profile to look for other apps. McAfee reminds you that if an app looks suspicious, you should not install it.<\/p>\n<p>McAfee Mobile Security detects this Android threat as Android\/Agent.FL and alerts mobile users if the malware is present. <a href=\"https:\/\/www.mcafeemobilesecurity.com\/\">Follow this link<\/a> for more information about <a href=\"https:\/\/www.mcafeemobilesecurity.com\/\">McAfee Mobile Security.<\/a><\/p>\n<p>To keep up with the latest security threats, follow <a href=\"https:\/\/twitter.com\/McAfee_Home\">@McAfee_Home<\/a> on Twitter and like us on <a href=\"https:\/\/www.facebook.com\/McAfee\">Facebook<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The McAfee Labs Mobile Malware Research team found early this week on Google Play a set of malware published by&#8230;<\/p>\n","protected":false},"author":833,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[442],"tags":[37,1814,76,180,214],"coauthors":[2035],"class_list":["post-51910","post","type-post","status-publish","format-standard","hentry","category-mcafee-labs","tag-android","tag-computer-security","tag-cybercrime","tag-malware","tag-mobile-security1"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Obfuscated Malware Discovered on Google Play | McAfee Blog<\/title>\n<meta name=\"description\" content=\"The McAfee Labs Mobile Malware Research team found early this week on Google Play a set of malware published by the developer account ValerySoftware: Each\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Obfuscated Malware Discovered on Google Play | McAfee Blog\" \/>\n<meta property=\"og:description\" content=\"The McAfee Labs Mobile Malware Research team found early this week on Google Play a set of malware published by the developer account ValerySoftware: Each\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/obfuscated-malware-discovered-google-play\/\" \/>\n<meta property=\"og:site_name\" content=\"McAfee Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/McAfee\/\" \/>\n<meta property=\"article:published_time\" content=\"2016-08-10T07:23:28+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-06-04T03:46:46+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/20160809-Google-Play-malware-1.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1207\" \/>\n\t<meta property=\"og:image:height\" content=\"786\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Fernando Ruiz\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@McAfee\" \/>\n<meta name=\"twitter:site\" content=\"@McAfee\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Fernando Ruiz\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/obfuscated-malware-discovered-google-play\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/obfuscated-malware-discovered-google-play\/\"},\"author\":{\"name\":\"Fernando Ruiz\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/0ed97a1d0ce0c90c2a9ef2fbab555922\"},\"headline\":\"Obfuscated Malware Discovered on Google Play\",\"datePublished\":\"2016-08-10T07:23:28+00:00\",\"dateModified\":\"2025-06-04T03:46:46+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/obfuscated-malware-discovered-google-play\/\"},\"wordCount\":576,\"publisher\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/obfuscated-malware-discovered-google-play\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/20160809-Google-Play-malware-1.png\",\"keywords\":[\"android\",\"computer security\",\"cybercrime\",\"malware\",\"mobile security\"],\"articleSection\":[\"McAfee Labs\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/obfuscated-malware-discovered-google-play\/\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/obfuscated-malware-discovered-google-play\/\",\"name\":\"Obfuscated Malware Discovered on Google Play | McAfee Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/obfuscated-malware-discovered-google-play\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/obfuscated-malware-discovered-google-play\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/20160809-Google-Play-malware-1.png\",\"datePublished\":\"2016-08-10T07:23:28+00:00\",\"dateModified\":\"2025-06-04T03:46:46+00:00\",\"description\":\"The McAfee Labs Mobile Malware Research team found early this week on Google Play a set of malware published by the developer account ValerySoftware: Each\",\"breadcrumb\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/obfuscated-malware-discovered-google-play\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/obfuscated-malware-discovered-google-play\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/obfuscated-malware-discovered-google-play\/#primaryimage\",\"url\":\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/20160809-Google-Play-malware-1.png\",\"contentUrl\":\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/20160809-Google-Play-malware-1.png\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/obfuscated-malware-discovered-google-play\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Blog\",\"item\":\"https:\/\/www.mcafee.com\/blogs\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Other Blogs\",\"item\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"McAfee Labs\",\"item\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"Obfuscated Malware Discovered on Google Play\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#website\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/\",\"name\":\"McAfee Blog\",\"description\":\"Internet Security News\",\"publisher\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.mcafee.com\/blogs\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#organization\",\"name\":\"McAfee\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png\",\"contentUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png\",\"width\":1286,\"height\":336,\"caption\":\"McAfee\"},\"image\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/McAfee\/\",\"https:\/\/x.com\/McAfee\",\"https:\/\/www.linkedin.com\/company\/mcafee\/\",\"https:\/\/www.youtube.com\/McAfee\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/0ed97a1d0ce0c90c2a9ef2fbab555922\",\"name\":\"Fernando Ruiz\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/image\/5b6dec450e97e87f9a57fae15bae5d34\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/7fa953f9b978dc1f77d7abb273aa5ec1?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/7fa953f9b978dc1f77d7abb273aa5ec1?s=96&d=mm&r=g\",\"caption\":\"Fernando Ruiz\"},\"description\":\"Fernando Ruiz is a Security Researcher in McAfee Labs. He specializes in mobile threats and Android malware. Ruiz performs deep analysis and reverse engineering of malicious code, packers, and vulnerabilities; and creates detection technologies to proactively protect people against a wide spectrum of malware and potentially unwanted programs.\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/author\/fernando-ruiz\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Obfuscated Malware Discovered on Google Play | McAfee Blog","description":"The McAfee Labs Mobile Malware Research team found early this week on Google Play a set of malware published by the developer account ValerySoftware: Each","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_US","og_type":"article","og_title":"Obfuscated Malware Discovered on Google Play | McAfee Blog","og_description":"The McAfee Labs Mobile Malware Research team found early this week on Google Play a set of malware published by the developer account ValerySoftware: Each","og_url":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/obfuscated-malware-discovered-google-play\/","og_site_name":"McAfee Blog","article_publisher":"https:\/\/www.facebook.com\/McAfee\/","article_published_time":"2016-08-10T07:23:28+00:00","article_modified_time":"2025-06-04T03:46:46+00:00","og_image":[{"width":1207,"height":786,"url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/20160809-Google-Play-malware-1.png","type":"image\/png"}],"author":"Fernando Ruiz","twitter_card":"summary_large_image","twitter_creator":"@McAfee","twitter_site":"@McAfee","twitter_misc":{"Written by":"Fernando Ruiz","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/obfuscated-malware-discovered-google-play\/#article","isPartOf":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/obfuscated-malware-discovered-google-play\/"},"author":{"name":"Fernando Ruiz","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/0ed97a1d0ce0c90c2a9ef2fbab555922"},"headline":"Obfuscated Malware Discovered on Google Play","datePublished":"2016-08-10T07:23:28+00:00","dateModified":"2025-06-04T03:46:46+00:00","mainEntityOfPage":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/obfuscated-malware-discovered-google-play\/"},"wordCount":576,"publisher":{"@id":"https:\/\/www.mcafee.com\/blogs\/#organization"},"image":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/obfuscated-malware-discovered-google-play\/#primaryimage"},"thumbnailUrl":"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/20160809-Google-Play-malware-1.png","keywords":["android","computer security","cybercrime","malware","mobile security"],"articleSection":["McAfee Labs"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/obfuscated-malware-discovered-google-play\/","url":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/obfuscated-malware-discovered-google-play\/","name":"Obfuscated Malware Discovered on Google Play | McAfee Blog","isPartOf":{"@id":"https:\/\/www.mcafee.com\/blogs\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/obfuscated-malware-discovered-google-play\/#primaryimage"},"image":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/obfuscated-malware-discovered-google-play\/#primaryimage"},"thumbnailUrl":"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/20160809-Google-Play-malware-1.png","datePublished":"2016-08-10T07:23:28+00:00","dateModified":"2025-06-04T03:46:46+00:00","description":"The McAfee Labs Mobile Malware Research team found early this week on Google Play a set of malware published by the developer account ValerySoftware: Each","breadcrumb":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/obfuscated-malware-discovered-google-play\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/obfuscated-malware-discovered-google-play\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/obfuscated-malware-discovered-google-play\/#primaryimage","url":"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/20160809-Google-Play-malware-1.png","contentUrl":"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/20160809-Google-Play-malware-1.png"},{"@type":"BreadcrumbList","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/obfuscated-malware-discovered-google-play\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https:\/\/www.mcafee.com\/blogs\/"},{"@type":"ListItem","position":2,"name":"Other Blogs","item":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/"},{"@type":"ListItem","position":3,"name":"McAfee Labs","item":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/"},{"@type":"ListItem","position":4,"name":"Obfuscated Malware Discovered on Google Play"}]},{"@type":"WebSite","@id":"https:\/\/www.mcafee.com\/blogs\/#website","url":"https:\/\/www.mcafee.com\/blogs\/","name":"McAfee Blog","description":"Internet Security News","publisher":{"@id":"https:\/\/www.mcafee.com\/blogs\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.mcafee.com\/blogs\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.mcafee.com\/blogs\/#organization","name":"McAfee","url":"https:\/\/www.mcafee.com\/blogs\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/","url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png","contentUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png","width":1286,"height":336,"caption":"McAfee"},"image":{"@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/McAfee\/","https:\/\/x.com\/McAfee","https:\/\/www.linkedin.com\/company\/mcafee\/","https:\/\/www.youtube.com\/McAfee"]},{"@type":"Person","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/0ed97a1d0ce0c90c2a9ef2fbab555922","name":"Fernando Ruiz","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/image\/5b6dec450e97e87f9a57fae15bae5d34","url":"https:\/\/secure.gravatar.com\/avatar\/7fa953f9b978dc1f77d7abb273aa5ec1?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/7fa953f9b978dc1f77d7abb273aa5ec1?s=96&d=mm&r=g","caption":"Fernando Ruiz"},"description":"Fernando Ruiz is a Security Researcher in McAfee Labs. He specializes in mobile threats and Android malware. Ruiz performs deep analysis and reverse engineering of malicious code, packers, and vulnerabilities; and creates detection technologies to proactively protect people against a wide spectrum of malware and potentially unwanted programs.","url":"https:\/\/www.mcafee.com\/blogs\/author\/fernando-ruiz\/"}]}},"_links":{"self":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts\/51910","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/users\/833"}],"replies":[{"embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/comments?post=51910"}],"version-history":[{"count":2,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts\/51910\/revisions"}],"predecessor-version":[{"id":215025,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts\/51910\/revisions\/215025"}],"wp:attachment":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/media?parent=51910"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/categories?post=51910"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/tags?post=51910"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/coauthors?post=51910"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}