GhostClicker adware threat

Trend Micro’s Threat Response Team has uncovered an auto-clicking GhostClicker adware in up to 340 apps in Google Play, to include one mobile app “Aladdin’s Adventure’s World” that was downloaded five million times.

As of August 7, there were still 101 affected apps that could be downloaded.

Trend Micro describes the adware in recent report

“Trend Micro detects these adware as GhostClicker (ANDROIDOS_GHOSTCLICKER.AXM) given its auto-click routine and the way it hides itself in Google Mobile Services (GMS), the set of Google’s most popular applications and application program interfaces (APIs). GhostClicker also hides in Facebook Ad’s software development kit (SDK). It embeds itself into these two services disguised as a package named “logs”, possibly to avoid rousing suspicion by pretending to be a legitimate app component.”

Leave a Reply