Android malware ‘Goldoson’ infects 60 legitimate apps on Google Play

April 17, 2023

A new Android spyware, nicknamed “Goldoson,” has infiltrated Google Play via 60 legal apps, which have been downloaded over 100 million times. The dangerous malware component is a component of a third-party library that developers unintentionally included in their applications.

L.POINT with L.PAY, Swipe Brick Breaker, Money Manager Expense & Budget, and GOM Player are among the impacted applications, with millions of downloads. Compass 9: Smart Compass, GOM Audio – Music, Sync lyrics, LOTTE WORLD Magicpass, and Korea Subway are among the other afflicted applications with hundreds of millions of downloads.

According to McAfee’s research team, which discovered Goldoson, the malware can collect data on installed apps, Wi-Fi and Bluetooth-connected devices, and the user’s GPS location. It can also perform ad fraud by clicking on ads in the background without the user’s consent.

When a user launches an app containing Goldoson, the library registers the device and receives its configuration from a remote server whose domain is obfuscated. The configuration contains parameters that set which data-stealing and ad-clicking functions Goldoson should run on the infected device and how often.

The data collection function sends a list of installed apps, geographical location history, MAC address of devices connected over Bluetooth and Wi-Fi, and more to the C2 server. The level of data collection depends on the permissions granted to the infected app during its installation and the Android version. Even in recent versions of the OS, Goldoson had enough permissions to gather sensitive data in 10% of the apps.

The ad-clicking function takes place by loading HTML code and injecting it into a customized, hidden WebView, and then using that to perform multiple URL visits, generating ad revenue. The victim does not see any indication of this activity on their device.

Google confirmed the action, stating that the apps violated Google Play policies. “The safety of users and developers is at the core of Google Play. When we find apps that violate our policies, we take appropriate action,” Google said in a statement.

The sources for this piece include an article in BleepingComputer.

Top Stories

Related Articles

December 29, 2025 Google parent Alphabet said Monday it will acquire data-centre and energy developer Intersect Power in a deal more...

December 23, 2025 Thank you. None of what follows happens without your support. Hashtag Trending has now passed three million more...

December 23, 2025 Editor's Notes: This is the first of two articles reflecting on the year but Yogi Schulz. Schulz' more...

December 23, 2025 Spotify says it has identified the user account behind what it describes as “unlawful” scraping of its more...

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn