DEV Community

Cover image for App Hider Auto-installation - Solved
Lilo Jimmy
Lilo Jimmy

Posted on • Updated on

App Hider Auto-installation - Solved

Own an Android Smartphone? Hackers can install any malicious third-party app on your smartphone remotely even if you have clearly tapped a reject button of the app. Security researchers have uncovered a trojanized adware family that has the capability to automatically install any app on an Android device by abusing the operating system's accessibility features.

Michael Bentley, head of response at mobile security firm Lookout, warned in a blog post published Thursday that the team has found three adware families:Shedun (GhostPush)

Kemoge (ShiftyBug)

Shuanet

How app hider is installed automatically on your Android

Image description

It has been reported multiple times that the App Hider Android app has been installed automatically.

We will discuss in-depth to understand the reasons behind this drastic action and how to prevent this.

In App Hider app we can hide any applications as well as files from our device.

It's official app can be found on Play store

But once, you will install it from the Play store, it is safe to use as it will not contain any suspicious malware. App hider is totally safe to use as it will ask you for the permission of each access.

After installing it you will be required to set the 6 Digit pin in order to go to the further options like hiding apps and settings etc.

We can separate the auto-installed app into two categories.
**
Installed safe and authentic apps** just to earn some revenue. (These are basically done by genuine apps that will ask for auto-installed permissions. By doing this they will earn some revenue from it and your device will be used to install those applications) Generally, these apps are installed from Play Store itself.

Installed unsafe and third-party apps: These are done by some attackers who can use any third-party app to insert their malicious programs in that third-party app. Once a user will install it on their device, these apps will firstly ask for your permission for auto-installation. If you give the permission, the app will act normally so that no one can suspect any threat with this application.

By using this second type of attack their main object is to use your device to install the apps outside of Playstore in .apk format.
They can use their own apps to be installed while you connect to the high-speed internet. These things happen in the background and due to the internet speed most of the applications will be installed within a few seconds.

Most of us can see the data packets and internet speed on our notification bar so these suspicious apps are generally auto-downloaded while you are not using your phone.

How to detect if the auto-installed app is authentic or suspicious

First of all, search the name of the application on any App Store or Play Store, If the app is from the play store it will be on the top of the search result.

Just click on that and you can find two options.

  • Open or Launch

  • Install

If you see the Install option then for sure we can say that the app is not installed from the play store as if it was from the play store then the package name must be the same and you will be able to see Open option instead of install.

If you see the Open option then there might be two possibilities. The attacker may use the same package name as the official package name of play store. Or the app is really from the Play store and safe to use.

For example, when TikTok and PUBG were banned in India the third-party apps were using the same package name and they could use the app as they were from the Play Store.

In USA similar scenario was noticed.

Now moving to the most important thing.

In most cases the unauthorized third-party auto-installed apps run in the background to use your data and battery as well, so this will be a major issue of your device's health. It can drain your battery power as it will be running seamlessly in the background.

You can check your running application history on your android.

If you are using older versions of android then go to -- settings---> search for background

If you are using the newer android version then digital wellbeing might be useful

You can find your running apps sorted by time using this new feature.

How to get prevented from auto installation apps

Till now it is reported that apps installed outside of the Play store can install unauthorized applications.

Here is the list of applications that are reported for auto-installing the app hider application.

  • Dream 11 (This can't be found on the Play store)

  • Mod applications of any premium app like Vanced YouTube, Kinemaster Mod, Free earning Mod applications.

  • Telegram Mod

So stay away, from installing these third-party apps. Google's Android will not be responsible for any issue.

If you still want to use any of these. Then make sure that your internet data is turned off while installing these and before enabling internet data just remove all the permissions from these apps if possible.

  • How to differentiate Official App Hider and Unofficial One

In the official App Hider, you will be able to set the passwords and it won't be running in the background without your consent.

In the unofficial App hider, you will not be able to find the application even as the icon might be different from the original.

If you somehow manage to find the application you will not be able to open it as you will be able to find the numbers key of the calculator only. This application looks similar to App Hider but it will act like Trojan virus which will use your internet data and CPU uses to drain your battery power.

Though it has been reported and said that App Hider spends Millions of Dollars to promote their application through the auto-installation process.

Not only this app but there are also 100 other apps doing the same tactics to promote their applications.

If this article is useful for you this might be useful for others too. Share this article with other android users.

Top comments (1)

Collapse
 
fraidan profile image
fraidan

Same thing happend with my Phone too. Closed to Kicking my Ass.