{"id":67731,"date":"2017-01-13T11:23:46","date_gmt":"2017-01-13T19:23:46","guid":{"rendered":"https:\/\/securingtomorrow.mcafee.com\/?p=67731"},"modified":"2025-06-06T02:22:54","modified_gmt":"2025-06-06T09:22:54","slug":"trojanized-photo-app-on-google-play-signs-up-users-for-premium-services","status":"publish","type":"post","link":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/trojanized-photo-app-on-google-play-signs-up-users-for-premium-services\/","title":{"rendered":"Trojanized Photo App on Google Play Signs Up Users for Premium Services"},"content":{"rendered":"<p style=\"text-align: justify;\">Mobile apps usually have names that give some indication of their function. In one recent case, however, we found a misnamed app that turned out to be malicious.<\/p>\n<p style=\"text-align: justify;\">Every Android app has an ID value, commonly known as the package name, to uniquely identify it on a device and in Google Play. Most package names on Google Play have some relation to the type of app (for example, photography apps usually have <em>photo<\/em>\u00a0in package name). When we saw the package name com.star.trek on Google Play, we expected an app related to the popular science fiction series. However, it\u00a0appears to be a photo app based on its application name and description:<\/p>\n<p style=\"text-align: justify;\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-67734 size-full\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/TrojanSMS_GoogleSearchApp.png\" alt=\"trojansms_googlesearchapp\" width=\"592\" height=\"103\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/TrojanSMS_GoogleSearchApp.png 592w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/TrojanSMS_GoogleSearchApp-300x52.png 300w\" sizes=\"auto, (max-width: 592px) 100vw, 592px\" \/><br \/>\nThe app seems popular on Google Play, with more than one million downloads yet an unusual low rating (3.5 out of 5):<\/p>\n<p style=\"text-align: justify;\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-67735 \" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/TrojanSMS_I_Love_Filter.png\" alt=\"trojansms_i_love_filter\" width=\"312\" height=\"429\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/TrojanSMS_I_Love_Filter.png 716w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/TrojanSMS_I_Love_Filter-218x300.png 218w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/TrojanSMS_I_Love_Filter-363x500.png 363w\" sizes=\"auto, (max-width: 312px) 100vw, 312px\" \/><br \/>\nAnother warning flag raised by this app is that the application name \u201cI Love Filter\u201d does not correspond to the application name in the banner \u201cWonderful Cam.\u201d Looking at user reviews, we found some hints as to its low ratings from so many people:<\/p>\n<p style=\"text-align: justify;\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-67739\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/TrojanSMS_RatingAndReviews-248x300.png\" alt=\"trojansms_ratingandreviews\" width=\"422\" height=\"510\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/TrojanSMS_RatingAndReviews-248x300.png 248w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/TrojanSMS_RatingAndReviews-413x500.png 413w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/TrojanSMS_RatingAndReviews.png 579w\" sizes=\"auto, (max-width: 422px) 100vw, 422px\" \/><br \/>\nOne review says the app makes money from your messages, suggesting the app is in fact an SMS Trojan, one of the oldest and most profitable threats to mobile devices. This type of malware sends SMS (text) messages to premium-rate numbers and charges the user for a specific service. In some cases, instead of charging for each SMS sent, the user is subscribed to a service that continuously charges until a message is submitted to cancel the subscription. After we downloaded and installed this suspect app, we confirmed that app demands permission to send SMS. There is also a typo in the application name (Fliter), which makes it even more suspicious:<\/p>\n<p style=\"text-align: justify;\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-67732 \" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/TrojanSMS_AppInfo.png\" alt=\"trojansms_appinfo\" width=\"272\" height=\"332\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/TrojanSMS_AppInfo.png 684w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/TrojanSMS_AppInfo-246x300.png 246w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/TrojanSMS_AppInfo-410x500.png 410w\" sizes=\"auto, (max-width: 272px) 100vw, 272px\" \/><br \/>\nOnce the app is executed, our suspicions are confirmed:<\/p>\n<p style=\"text-align: justify;\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-67737\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/TrojanSMS_PremiumService-169x300.png\" alt=\"trojansms_premiumservice\" width=\"278\" height=\"494\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/TrojanSMS_PremiumService-169x300.png 169w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/TrojanSMS_PremiumService-578x1024.png 578w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/TrojanSMS_PremiumService-282x500.png 282w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/TrojanSMS_PremiumService.png 686w\" sizes=\"auto, (max-width: 278px) 100vw, 278px\" \/><br \/>\nAs soon as the app is opened, it loads a website to subscribe the user to a premium service once the user clicks on the \u201cContinue\u201d button. The &#8220;good&#8221; news is that rather than subscribing the user automatically in the background, the app explains the cost of each SMS and, more important, how the user can stop the service. The bad news is that if the user does not pay, the application cannot be used.<\/p>\n<p style=\"text-align: justify;\">Does this behavior mean that the developer is offering the app as free but then tries to charge the user to use the app? Not really. Looking at the decompiled source code of \u201cI Love Filter,\u201d we see that com.star.trek is in fact the free legitimate app Retro Live infected with Trojan code to charge the user via SMS messages:<\/p>\n<p style=\"text-align: justify;\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-67740\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/TrojanSMS_RetroLive-300x247.png\" alt=\"trojansms_retrolive\" width=\"414\" height=\"341\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/TrojanSMS_RetroLive-300x247.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/TrojanSMS_RetroLive-608x500.png 608w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/TrojanSMS_RetroLive.png 687w\" sizes=\"auto, (max-width: 414px) 100vw, 414px\" \/><br \/>\nRetro Live is currently not available on Google Play, although this is not the first time that it is being used to make a profit on Google Play. At least three other Trojanized Retro Live apps have been identified, and are currently available only on third-party sites:<\/p>\n<p style=\"text-align: justify;\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-67736\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/TrojanSMS_OtherApps-185x300.png\" alt=\"trojansms_otherapps\" width=\"251\" height=\"407\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/TrojanSMS_OtherApps-185x300.png 185w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/TrojanSMS_OtherApps-630x1024.png 630w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/TrojanSMS_OtherApps-308x500.png 308w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/TrojanSMS_OtherApps.png 690w\" sizes=\"auto, (max-width: 251px) 100vw, 251px\" \/><br \/>\nIn the case of Beautiful Photo, and unlike I Love Filter, the terms and conditions are not so clear and are not even in English, which could lead some to click \u201cSetup\u201d without paying attention to the other text and thus subscribe the user to an unwanted premium-rate service:<\/p>\n<p style=\"text-align: justify;\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-67738\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/TrojanSMS_PremiumService2-169x300.png\" alt=\"trojansms_premiumservice2\" width=\"234\" height=\"415\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/TrojanSMS_PremiumService2-169x300.png 169w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/TrojanSMS_PremiumService2-576x1024.png 576w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/TrojanSMS_PremiumService2-281x500.png 281w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/TrojanSMS_PremiumService2.png 720w\" sizes=\"auto, (max-width: 234px) 100vw, 234px\" \/><br \/>\nIn addition to the SMS subscription function, the injected code also leaks device and user information, including the phone number, GPS location, installed apps, and IP address:<\/p>\n<p style=\"text-align: justify;\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-67742 size-full\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/TrojanSMS_UserInfoUpload.png\" alt=\"trojansms_userinfoupload\" width=\"881\" height=\"447\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/TrojanSMS_UserInfoUpload.png 881w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/TrojanSMS_UserInfoUpload-300x152.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/TrojanSMS_UserInfoUpload-768x390.png 768w\" sizes=\"auto, (max-width: 881px) 100vw, 881px\" \/><br \/>\nThe malware can also download and install applications:<\/p>\n<p style=\"text-align: justify;\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-67733 size-full\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/TrojanSMS_DownloadAndInstall.png\" alt=\"trojansms_downloadandinstall\" width=\"813\" height=\"480\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/TrojanSMS_DownloadAndInstall.png 813w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/TrojanSMS_DownloadAndInstall-300x177.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/TrojanSMS_DownloadAndInstall-768x453.png 768w\" sizes=\"auto, (max-width: 813px) 100vw, 813px\" \/><br \/>\nIn previous years Android has introduced security measures to protect users against SMS Trojans. Since Android 4.2 (Jelly Bean), the operating system has displayed a pop-up message to inform users that an app is trying to send an SMS message to a premium short number and ask for confirmation. In Android 4.4 (KitKat) Google introduced the concept of a default SMS app that limits the ability of malware to silently intercept incoming SMS messages. Nevertheless, malware authors have found ways to overcome some restrictions: In the following case the malware mutes the incoming SMS alert notification to avoid alerting the user that a confirmation message has arrived:<\/p>\n<p style=\"text-align: justify;\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-67741 size-full\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/TrojanSMS_silentMode.png\" alt=\"trojansms_silentmode\" width=\"482\" height=\"56\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/TrojanSMS_silentMode.png 482w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/TrojanSMS_silentMode-300x35.png 300w\" sizes=\"auto, (max-width: 482px) 100vw, 482px\" \/><br \/>\nAlthough SMS Trojans are not as popular as earlier in Android&#8217;s career, Trojanized apps with injected code to subscribe users to premium services remain an easy way for malware authors to profit in a restricted environment like Google Play. Users may think they are paying for a legitimate app while in fact subscribing to a service that needs a specific SMS to make it stop. Another risk lies in children downloading, installing, and executing apps, while clicking on confirmation messages that could result in charges.<\/p>\n<p style=\"text-align: justify;\">We have reported the \u201cI Love Filter\u201d app to Google and it should be removed soon. To protect yourselves from this threat, employ security software on your mobile devices, check user reviews for apps on Google Play, and do not accept or trust apps that ask for payment functionality via SMS messages as soon as the app is opened.<\/p>\n<h2>McAfee Mobile Security<\/h2>\n<p style=\"text-align: justify;\">McAfee Mobile Security detects this threat as Android\/SmsPay and alerts mobile users if it is present, while protecting them from any data loss. For more information about McAfee Mobile Security, visit <a href=\"http:\/\/www.mcafeemobilesecurity.com\">http:\/\/www.mcafeemobilesecurity.com<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Mobile apps usually have names that give some indication of their function. In one recent case, however, we found a&#8230;<\/p>\n","protected":false},"author":462,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[442],"tags":[76,4452,180,214],"coauthors":[1104],"class_list":["post-67731","post","type-post","status-publish","format-standard","hentry","category-mcafee-labs","tag-cybercrime","tag-cybersecurity","tag-malware","tag-mobile-security1"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Trojanized Photo App on Google Play Signs Up Users for Premium Services | McAfee Blog<\/title>\n<meta name=\"description\" content=\"Mobile apps usually have names that give some indication of their function. In one recent case, however, we found a misnamed app that turned out to be\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Trojanized Photo App on Google Play Signs Up Users for Premium Services | McAfee Blog\" \/>\n<meta property=\"og:description\" content=\"Mobile apps usually have names that give some indication of their function. In one recent case, however, we found a misnamed app that turned out to be\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/trojanized-photo-app-on-google-play-signs-up-users-for-premium-services\/\" \/>\n<meta property=\"og:site_name\" content=\"McAfee Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/McAfee\/\" \/>\n<meta property=\"article:published_time\" content=\"2017-01-13T19:23:46+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-06-06T09:22:54+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/TrojanSMS_GoogleSearchApp.png\" \/>\n\t<meta property=\"og:image:width\" content=\"592\" \/>\n\t<meta property=\"og:image:height\" content=\"103\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Carlos Castillo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@carlosacastillo\" \/>\n<meta name=\"twitter:site\" content=\"@McAfee\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Carlos Castillo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/trojanized-photo-app-on-google-play-signs-up-users-for-premium-services\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/trojanized-photo-app-on-google-play-signs-up-users-for-premium-services\/\"},\"author\":{\"name\":\"Carlos Castillo\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/894ee4a790607d505a13c24955d2edbe\"},\"headline\":\"Trojanized Photo App on Google Play Signs Up Users for Premium Services\",\"datePublished\":\"2017-01-13T19:23:46+00:00\",\"dateModified\":\"2025-06-06T09:22:54+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/trojanized-photo-app-on-google-play-signs-up-users-for-premium-services\/\"},\"wordCount\":867,\"publisher\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/trojanized-photo-app-on-google-play-signs-up-users-for-premium-services\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/TrojanSMS_GoogleSearchApp.png\",\"keywords\":[\"cybercrime\",\"cybersecurity\",\"malware\",\"mobile security\"],\"articleSection\":[\"McAfee Labs\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/trojanized-photo-app-on-google-play-signs-up-users-for-premium-services\/\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/trojanized-photo-app-on-google-play-signs-up-users-for-premium-services\/\",\"name\":\"Trojanized Photo App on Google Play Signs Up Users for Premium Services | McAfee Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/trojanized-photo-app-on-google-play-signs-up-users-for-premium-services\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/trojanized-photo-app-on-google-play-signs-up-users-for-premium-services\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/TrojanSMS_GoogleSearchApp.png\",\"datePublished\":\"2017-01-13T19:23:46+00:00\",\"dateModified\":\"2025-06-06T09:22:54+00:00\",\"description\":\"Mobile apps usually have names that give some indication of their function. In one recent case, however, we found a misnamed app that turned out to be\",\"breadcrumb\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/trojanized-photo-app-on-google-play-signs-up-users-for-premium-services\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/trojanized-photo-app-on-google-play-signs-up-users-for-premium-services\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/trojanized-photo-app-on-google-play-signs-up-users-for-premium-services\/#primaryimage\",\"url\":\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/TrojanSMS_GoogleSearchApp.png\",\"contentUrl\":\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/TrojanSMS_GoogleSearchApp.png\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/trojanized-photo-app-on-google-play-signs-up-users-for-premium-services\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Blog\",\"item\":\"https:\/\/www.mcafee.com\/blogs\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Other Blogs\",\"item\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"McAfee Labs\",\"item\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"Trojanized Photo App on Google Play Signs Up Users for Premium Services\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#website\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/\",\"name\":\"McAfee Blog\",\"description\":\"Internet Security News\",\"publisher\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.mcafee.com\/blogs\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#organization\",\"name\":\"McAfee\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png\",\"contentUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png\",\"width\":1286,\"height\":336,\"caption\":\"McAfee\"},\"image\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/McAfee\/\",\"https:\/\/x.com\/McAfee\",\"https:\/\/www.linkedin.com\/company\/mcafee\/\",\"https:\/\/www.youtube.com\/McAfee\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/894ee4a790607d505a13c24955d2edbe\",\"name\":\"Carlos Castillo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/image\/729f5b9d2761341175762c5f10652607\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/Carlos-Castillo-96x96.jpg\",\"contentUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/Carlos-Castillo-96x96.jpg\",\"caption\":\"Carlos Castillo\"},\"description\":\"Carlos Castillo specializes in the analysis of mobile threats and Android malware. Castillo performs static and dynamic analysis of suspicious applications to support McAfee\u2019s Mobile Security for Android product. He is the author of the McAfee-published white paper, \\\"Android Malware Past, Present, and Future,\u201d and wrote the \u201cHacking Android\\\" section of the book, \\\"Hacking Exposed 7: Network Security Secrets &amp; Solutions.\u201d As a recognized mobile malware researcher, Castillo has presented at several security industry events, including 8.8 Computer Security Conference and Segurinfo, a leading information security conference in South America. Prior to his position at McAfee, Castillo performed security compliance audits for the Superintendencia Financiera of Colombia, and worked at security startup Easy Solutions Inc., where he conducted penetration tests on web applications, helped shut down phishing and malicious websites, supported security and network appliances, performed functional software testing, and assisted in research and development related to anti-electronic fraud. Castillo joined the world of malware research when he won ESET Latin America\u2019s Best Antivirus Research contest with a paper titled, \u201cSexy View: The Beginning of Mobile Botnets.\u201d Castillo holds a degree in systems engineering from the Universidad Javeriana in Bogot\u00e1, Colombia.\",\"sameAs\":[\"https:\/\/www.linkedin.com\/in\/carlosacastillo\/\",\"https:\/\/x.com\/carlosacastillo\"],\"url\":\"https:\/\/www.mcafee.com\/blogs\/author\/carlos-castillo\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Trojanized Photo App on Google Play Signs Up Users for Premium Services | McAfee Blog","description":"Mobile apps usually have names that give some indication of their function. In one recent case, however, we found a misnamed app that turned out to be","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_US","og_type":"article","og_title":"Trojanized Photo App on Google Play Signs Up Users for Premium Services | McAfee Blog","og_description":"Mobile apps usually have names that give some indication of their function. In one recent case, however, we found a misnamed app that turned out to be","og_url":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/trojanized-photo-app-on-google-play-signs-up-users-for-premium-services\/","og_site_name":"McAfee Blog","article_publisher":"https:\/\/www.facebook.com\/McAfee\/","article_published_time":"2017-01-13T19:23:46+00:00","article_modified_time":"2025-06-06T09:22:54+00:00","og_image":[{"width":592,"height":103,"url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/TrojanSMS_GoogleSearchApp.png","type":"image\/png"}],"author":"Carlos Castillo","twitter_card":"summary_large_image","twitter_creator":"@carlosacastillo","twitter_site":"@McAfee","twitter_misc":{"Written by":"Carlos Castillo","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/trojanized-photo-app-on-google-play-signs-up-users-for-premium-services\/#article","isPartOf":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/trojanized-photo-app-on-google-play-signs-up-users-for-premium-services\/"},"author":{"name":"Carlos Castillo","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/894ee4a790607d505a13c24955d2edbe"},"headline":"Trojanized Photo App on Google Play Signs Up Users for Premium Services","datePublished":"2017-01-13T19:23:46+00:00","dateModified":"2025-06-06T09:22:54+00:00","mainEntityOfPage":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/trojanized-photo-app-on-google-play-signs-up-users-for-premium-services\/"},"wordCount":867,"publisher":{"@id":"https:\/\/www.mcafee.com\/blogs\/#organization"},"image":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/trojanized-photo-app-on-google-play-signs-up-users-for-premium-services\/#primaryimage"},"thumbnailUrl":"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/TrojanSMS_GoogleSearchApp.png","keywords":["cybercrime","cybersecurity","malware","mobile security"],"articleSection":["McAfee Labs"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/trojanized-photo-app-on-google-play-signs-up-users-for-premium-services\/","url":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/trojanized-photo-app-on-google-play-signs-up-users-for-premium-services\/","name":"Trojanized Photo App on Google Play Signs Up Users for Premium Services | McAfee Blog","isPartOf":{"@id":"https:\/\/www.mcafee.com\/blogs\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/trojanized-photo-app-on-google-play-signs-up-users-for-premium-services\/#primaryimage"},"image":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/trojanized-photo-app-on-google-play-signs-up-users-for-premium-services\/#primaryimage"},"thumbnailUrl":"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/TrojanSMS_GoogleSearchApp.png","datePublished":"2017-01-13T19:23:46+00:00","dateModified":"2025-06-06T09:22:54+00:00","description":"Mobile apps usually have names that give some indication of their function. In one recent case, however, we found a misnamed app that turned out to be","breadcrumb":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/trojanized-photo-app-on-google-play-signs-up-users-for-premium-services\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/trojanized-photo-app-on-google-play-signs-up-users-for-premium-services\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/trojanized-photo-app-on-google-play-signs-up-users-for-premium-services\/#primaryimage","url":"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/TrojanSMS_GoogleSearchApp.png","contentUrl":"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/TrojanSMS_GoogleSearchApp.png"},{"@type":"BreadcrumbList","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/trojanized-photo-app-on-google-play-signs-up-users-for-premium-services\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https:\/\/www.mcafee.com\/blogs\/"},{"@type":"ListItem","position":2,"name":"Other Blogs","item":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/"},{"@type":"ListItem","position":3,"name":"McAfee Labs","item":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/"},{"@type":"ListItem","position":4,"name":"Trojanized Photo App on Google Play Signs Up Users for Premium Services"}]},{"@type":"WebSite","@id":"https:\/\/www.mcafee.com\/blogs\/#website","url":"https:\/\/www.mcafee.com\/blogs\/","name":"McAfee Blog","description":"Internet Security News","publisher":{"@id":"https:\/\/www.mcafee.com\/blogs\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.mcafee.com\/blogs\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.mcafee.com\/blogs\/#organization","name":"McAfee","url":"https:\/\/www.mcafee.com\/blogs\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/","url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png","contentUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png","width":1286,"height":336,"caption":"McAfee"},"image":{"@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/McAfee\/","https:\/\/x.com\/McAfee","https:\/\/www.linkedin.com\/company\/mcafee\/","https:\/\/www.youtube.com\/McAfee"]},{"@type":"Person","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/894ee4a790607d505a13c24955d2edbe","name":"Carlos Castillo","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/image\/729f5b9d2761341175762c5f10652607","url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/Carlos-Castillo-96x96.jpg","contentUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/Carlos-Castillo-96x96.jpg","caption":"Carlos Castillo"},"description":"Carlos Castillo specializes in the analysis of mobile threats and Android malware. Castillo performs static and dynamic analysis of suspicious applications to support McAfee\u2019s Mobile Security for Android product. He is the author of the McAfee-published white paper, \"Android Malware Past, Present, and Future,\u201d and wrote the \u201cHacking Android\" section of the book, \"Hacking Exposed 7: Network Security Secrets &amp; Solutions.\u201d As a recognized mobile malware researcher, Castillo has presented at several security industry events, including 8.8 Computer Security Conference and Segurinfo, a leading information security conference in South America. Prior to his position at McAfee, Castillo performed security compliance audits for the Superintendencia Financiera of Colombia, and worked at security startup Easy Solutions Inc., where he conducted penetration tests on web applications, helped shut down phishing and malicious websites, supported security and network appliances, performed functional software testing, and assisted in research and development related to anti-electronic fraud. Castillo joined the world of malware research when he won ESET Latin America\u2019s Best Antivirus Research contest with a paper titled, \u201cSexy View: The Beginning of Mobile Botnets.\u201d Castillo holds a degree in systems engineering from the Universidad Javeriana in Bogot\u00e1, Colombia.","sameAs":["https:\/\/www.linkedin.com\/in\/carlosacastillo\/","https:\/\/x.com\/carlosacastillo"],"url":"https:\/\/www.mcafee.com\/blogs\/author\/carlos-castillo\/"}]}},"_links":{"self":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts\/67731","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/users\/462"}],"replies":[{"embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/comments?post=67731"}],"version-history":[{"count":2,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts\/67731\/revisions"}],"predecessor-version":[{"id":215203,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts\/67731\/revisions\/215203"}],"wp:attachment":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/media?parent=67731"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/categories?post=67731"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/tags?post=67731"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/coauthors?post=67731"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}