{"id":21882,"date":"2018-04-04T06:00:16","date_gmt":"2018-04-04T10:00:16","guid":{"rendered":"https:\/\/www.kaspersky.com\/blog\/?p=21882"},"modified":"2022-10-18T08:05:13","modified_gmt":"2022-10-18T12:05:13","slug":"google-play-hidden-miners","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com\/blog\/google-play-hidden-miners\/21882\/","title":{"rendered":"Hidden miners on Google Play"},"content":{"rendered":"<p>When a computer shows signs of slowing down, many tend to blame viruses. But in the case of smartphones, sluggishness, overheating, or short battery life are usually put down to age. Time to buy a new one, people say. In fact, there is a chance that the problem may lie elsewhere \u2014 hidden <a target=\"_blank\" href=\"https:\/\/encyclopedia.kaspersky.com\/glossary\/mining-cryptocurrency\/?utm_source=kdaily&amp;utm_medium=blog&amp;utm_campaign=termin-explanation\" rel=\"noopener noreferrer\">mining<\/a>, to be precise.<\/p>\n<p>When it comes to mining, computing power matters. Of course, in terms of performance, mobile devices cannot hope to compete with <a target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/blog\/mining-easy-explanation\/17768\/\" rel=\"noopener noreferrer nofollow\">desktop computers armed with the latest graphics cards<\/a>, but in the eyes of cybercriminals, the sheer number of devices makes up for their lack of power. For those accustomed to feeding off other people\u2019s processing power, the millions of devices out there present an opportunity too juicy to ignore.<\/p>\n<p>It\u2019s actually alarmingly simple to infect a smartphone or tablet with a hidden miner. There\u2019s no need for the device owner to knowingly install a miner or download an app from a dubious source. Hidden miners can be picked up by downloading and running seemingly innocuous apps available on the official Google Play store.<\/p>\n<p><strong><\/strong><\/p>\n<h2>Miners on Google Play<\/h2>\n<p><\/p>\n<p>Typical miners pretending to be handy tools or games don\u2019t perform as described \u2014 instead, they show ads and covertly mine for cryptocurrency. But Google Play and other official stores keep out such fakes or, if they do manage to sneak in, quickly find and remove them. Therefore, malicious apps of this sort are distributed mainly through forums and nonofficial stores. The problem for cybercriminals is that too few people download anything from such resources.<\/p>\n<p>But they found a way around that particular problem: If an app actually does what is promised in its description, and the malware is neatly disguised, it may slip through. That\u2019s <a target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/blog\/dresscode-android-trojan\/13219\/\" rel=\"noopener noreferrer nofollow\">already happened<\/a>\u00a0\u2014 an attempt to create a smartphone-based botnet bypassed the safeguards on Google Play and a number of other app stores. Kaspersky Lab experts recently found several other specimens as well, this time with built-in miners.<\/p>\n<p>The most popular apps we found of this type were soccer-related: a family of apps with names including PlacarTV (<em>placar<\/em> means <em>score<\/em> in Portuguese), one of which had been downloaded more than 100,000 times. It contained the Coinhive miner, which mined Monero coins while users streamed games. It\u2019s a clever ruse, and not that easy to spot: Your mind is on the match, and watching videos heats up the phone and drains the battery anyway, just like the miner does, so you\u2019ll have no reason to be suspicious.<\/p>\n<p>Our experts also found a miner in a free VPN app called Vilny.net. This malware\u2019s trick was to keep tabs on the phone\u2019s temperature and battery. It then suspended mining as needed to avoid overheating or draining the device and attracting the owner\u2019s attention. A more <a target=\"_blank\" href=\"https:\/\/securelist.com\/pocket-cryptofarms\/85137\/\" rel=\"noopener noreferrer\">detailed and technical post on this miner is available on Securelist<\/a>.<\/p><div id=\"attachment_21883\" style=\"width: 508px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2018\/04\/04050045\/google-play-hidden-miners-detect.png\"><img decoding=\"async\" width=\"498\" height=\"1024\" aria-describedby=\"caption-attachment-21883\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2018\/04\/04050045\/google-play-hidden-miners-detect-498x1024.png\" alt=\"\" style=\"max-height:60vh\" class=\"size-large wp-image-21883\"><\/a><p id=\"caption-attachment-21883\" class=\"wp-caption-text\">Here\u2019s what detect of a hidden miner look like. Technically, it\u2019s <a target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/blog\/not-a-virus\/18015\/\" rel=\"noopener noreferrer nofollow\"><strong>Not-a-virus<\/strong><\/a>, nasty nevertheless<\/p><\/div>\n<p>We alerted Google about these apps, and the soccer-related ones have been removed from the Google Play store \u2014 Vilny.net is still available in the store, though. What\u2019s more, there is no guarantee that some other apps with hidden miners won\u2019t sneak in there in the future. So staying safe from them is up to you.<\/p>\n<p><strong><\/strong><\/p>\n<h3>How to guard against hidden miners on Android<\/h3>\n<p><\/p>\n<ul>\n<li>If your smartphone is behaving oddly, don\u2019t ignore it. If it heats up quickly and loses power for no apparent reason, it might be infected. You can find out if an app has suddenly started eating too much battery with a special app such as <a target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/blog\/kaspersky-battery-life\/17849\/\" rel=\"noopener noreferrer nofollow\">Kaspersky Battery Life<\/a>.<\/li>\n<li>When looking for new apps, take the developers of those apps into account. Software from reputable developers is far less likely to contain infections.<\/li>\n<li>Install  on your device. It will help detect all miners, including ones that don\u2019t noticeably overheat or discharge your device. Even a miner designed to back off periodically will eventually wear out your phone \u2014 and a crude one could <a target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/blog\/loapi-trojan\/20510\/\" rel=\"noopener noreferrer nofollow\">toast it<\/a><\/li>\n<\/ul>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kisa-generic\">\n","protected":false},"excerpt":{"rendered":"<p>Hidden miners detected in soccer and VPN apps on Google Play \u2014 steer clear!<\/p>\n","protected":false},"author":2484,"featured_media":21884,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2683],"tags":[105,109,877,2897,183,352,2756,2639,192,97,45,422,131],"class_list":{"0":"post-21882","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-threats","8":"tag-android","9":"tag-apps","10":"tag-battery-life","11":"tag-cryptojacking","12":"tag-google-play","13":"tag-kaspersky-lab","14":"tag-miners","15":"tag-mining","16":"tag-protection","17":"tag-security-2","18":"tag-smartphones","19":"tag-threats","20":"tag-tips"},"hreflang":[{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/google-play-hidden-miners\/21882\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/google-play-hidden-miners\/12988\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/google-play-hidden-miners\/10850\/"},{"hreflang":"ar","url":"https:\/\/me.kaspersky.com\/blog\/google-play-hidden-miners\/5678\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/google-play-hidden-miners\/15101\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/google-play-hidden-miners\/13384\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/google-play-hidden-miners\/12715\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/google-play-hidden-miners\/15772\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/google-play-hidden-miners\/15258\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/google-play-hidden-miners\/20111\/"},{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/google-play-hidden-miners\/4832\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/google-play-hidden-miners\/10203\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/google-play-hidden-miners\/10205\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/google-play-hidden-miners\/9119\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/google-play-hidden-miners\/16380\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/google-play-hidden-miners\/20043\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/google-play-hidden-miners\/19986\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/google-play-hidden-miners\/20010\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com\/blog\/tag\/miners\/","name":"miners"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/21882","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/2484"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=21882"}],"version-history":[{"count":9,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/21882\/revisions"}],"predecessor-version":[{"id":45867,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/21882\/revisions\/45867"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/21884"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=21882"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=21882"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=21882"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}