Google Play blocks millions of malicious apps every year. And still — year after year — major malware campaigns reach hundreds of millions of phones. That's not a knock on Google specifically; it's what happens when you run the review process for an app store with billions of users. The incentive to beat it is enormous, and the attackers only need to win once.

This is Part 2 of a three-part series on Android app safety:

  1. Criteria for deciding whether to install an Android app (Part 1)
  2. The history of malware that slipped past Play Store security, and Google's mass removals (this post)
  3. Auditing your existing and preinstalled apps after a factory reset (Part 3)

The scale of the fight

Before we get into the timeline, it's worth sitting with how much Google is actually catching — because the misses are more impressive in context.

Year Blocked from publishing Developer accounts banned Play Protect scale
2024 2.36 million apps 158,000 200B scans/day; 13M malicious apps caught outside Play
2025 1.75 million apps 80,000 350B scans/day; 27M malicious apps caught outside Play; 266M risky installs blocked

Google also says Play runs 10,000+ safety checks per published app and blocked 160 million spam ratings and reviews in 2025. That's a genuinely massive operation.

And it still isn't enough. Here's what got through anyway.

Timeline of notable breaches and mass removals

2017–ongoing: Joker (fleeceware / subscription fraud)

Joker has been around since 2017 and, at this point, is basically the Play Store's resident cockroach — it just will not go away. The trick is simple but effective: it intercepts SMS verification codes to silently subscribe victims to premium services, and it hides inside a tiny code footprint so it slips past review inside otherwise-functional apps (wallpaper apps, camera apps, that kind of thing).

A few highlights from its run:

The lesson here isn't "Google missed one app." It's that removing Joker from the Play Store doesn't remove it from your phone. Installed copies keep running after the takedown — Lookout has been explicit about that.

Feb 2020: 600+ disruptive-ad apps

Google removed over 600 apps and banned them from AdMob for a different kind of abuse: serving out-of-context ads, including full-screen ads that popped up when the app wasn't even open. Less "steal your data," more "ruin your phone," but still a policy violation at serious scale.

2018: Preinstalled firmware flaws

This one isn't a Play Store story, but it set up everything that came after. Researchers found vulnerabilities in the firmware of 25 Android models that let preinstalled apps wipe user data via factory reset with zero user interaction, lock people out of their phones entirely (this happened on the LG G6), or brick TV boxes outright. None of this required the user to download anything — it was already on the device when they bought it. This is the exact problem Part 3 of this series digs into.

2019–2020: Preinstalled app research gets serious

Academic and industry research started quantifying just how bad the preinstalled-app problem was:

  • FIRMSCOPE (USENIX Security 2020) scanned 331,342 preinstalled apps across 2,017 firmware images from 100+ vendors and found 850 unique privilege-escalation vulnerabilities, affecting 77% of the ROMs analyzed. The flaws allowed command injection, SMS interception, arbitrary app installation, and device wiping — all from apps users never chose to install and often can't remove.
  • Google's own 2018 Android Security Year in Review flagged that attackers were shifting effort toward preinstalled apps for a simple reason: fool one supply-chain participant (a vendor or carrier) instead of millions of individual users (analysis).

Sept 2021 (disclosed May 2022): Microsoft / mce Systems

Microsoft's 365 Defender Research Team found four high-severity vulnerabilities (CVE-2021-42598 through CVE-2021-42601) in a framework from mce Systems, used by several carriers to build preinstalled system apps (AT&T, TELUS, Rogers, Bell Canada, and Freedom Mobile were among those affected). The bugs allowed command injection and privilege escalation, exploitable via a remotely-invokable BROWSABLE activity — and the affected apps couldn't be uninstalled without root. Worse: these apps were listed on the Play Store too, and Play Protect's checks at the time weren't scanning for this class of issue. Microsoft reported the flaws to the vendor in September 2021; the public writeup didn't land until May 2022.

2024–2025: The "benign then weaponized" wave

This is one of the more unsettling patterns on this list. Bitdefender and IAS Threat Lab uncovered a campaign — later nicknamed "Vapor" — involving 331 apps and 60 million downloads. The apps launched as genuinely legitimate utilities (QR scanners, health trackers, wallpaper apps), passed review honestly, and then received updates starting in Q3 2024 that quietly added malicious code: out-of-context fullscreen ads, phishing overlays mimicking login pages for services like Facebook and YouTube, and hidden launcher icons. Fifteen of the apps were still live on the Play Store when the research wrapped up in March 2025.

This pattern — clean app, dirty update — is a genuinely hard problem for any review process, because the thing that got reviewed isn't the thing doing the damage.

Jun 2025: 20 crypto phishing apps

20 apps on Play were found impersonating legitimate crypto wallets specifically to drain user funds. Straightforward phishing, just wearing a Play Store badge.

Sep 2025: SlopAds — the steganography campaign

This is, genuinely, one of the more technically interesting campaigns on this list. HUMAN's Satori Threat Intelligence team, working with Google, uncovered an operation dubbed SlopAds:

  • 224 AI-themed apps, 38 million downloads, across 228 countries
  • 2.3 billion fraudulent ad bid requests per day at peak (top traffic sources: US 30%, India 10%, Brazil 7%)
  • A genuinely layered evasion stack: apps behaved completely normally when installed organically through the Play Store. Fraud only activated when the install came through the attackers' own ad campaigns — meaning weaponized marketing-attribution SDKs were used to fingerprint the install source. Once triggered, the app fetched encrypted config via Firebase Remote Config, then downloaded four PNG images that used steganography to hide pieces of a malicious APK, reassembled on-device into what researchers called "FatModule." From there, hidden WebViews clicked ads invisibly in the background.
  • Infrastructure behind it included command-and-control servers plus 300+ promotional domains, which suggests the operators were scaling up, not winding down.

(BleepingComputer coverage, HUMAN's press release)

Hiding malicious code inside image files isn't new as a technique, but seeing it at this scale, combined with conditional activation based on install source, is a good snapshot of where mobile malware is heading.

May 2026: CallPhantom

ESET found 28 apps with 7.3 million downloads, mostly targeting users in India. The pitch: pay for access to someone's call history, SMS logs, or WhatsApp activity. The delivery: fabricated data, hardcoded directly into the app, with nothing real behind it. Subscriptions ran $6–80. Google removed the apps, but refunds were only guaranteed for payments that went through Play's own billing system — some of the apps routed payments through third-party channels specifically to make that harder to reverse.

Jun 2026: A forgotten-app warning, in testing

Google is reportedly preparing a Play Store alert for apps that were pulled from the store, telling users the app "has been removed from Google Play and will no longer receive updates." It's a small feature, but it's a quiet admission of something important: removing an app from the store doesn't remove it from the phone, and users have had no way of knowing that an app they still rely on has effectively been orphaned — or worse, flagged as harmful.

Why malware keeps slipping through

Pulling the pattern out of all of the above, a few recurring techniques show up again and again:

  1. Delayed payload delivery. The app that gets reviewed ships clean. The malicious code arrives later, fetched from Firebase remote config, an encrypted module, or — as with SlopAds — hidden inside ordinary-looking images. Static, pre-publication review has nothing to catch.
  2. Conditional activation. Malware only arms itself for specific install sources, regions, or non-sandboxed real devices. Reviewers and emulators see the harmless path every time.
  3. Benign-to-malicious updates. A trusted, already-approved app flips the switch via a routine update. The signature stays valid. The permissions stay granted. Nothing about the installed app looks different.
  4. Obfuscation and polymorphism. Tiny code footprints (Joker's whole approach), encrypted configs, APKs split and hidden inside image files.
  5. Speed and volume. Factory-style app production — SlopAds researchers literally called their own campaign "AI slop" — can outpace the depth of review that's humanly (or even algorithmically) possible at scale.
  6. Post-removal persistence. Once an app is pulled from the store, copies already installed keep running, and users generally aren't notified unless they're paying close attention.

What this means for you

The single biggest takeaway here: removal from the Play Store does not mean removal from your phone. If an app you installed gets pulled for one of the reasons above, nothing happens to your device automatically. You have to go check.

This post is really meant to be read alongside the other two in this series — the download criteria in Part 1 help you avoid installing the next Joker or SlopAds in the first place, and the device audit in Part 3 walks through how to find anything that's already slipped through, including the preinstalled stuff you never chose to put there at all.


Sources

Google official

Malware campaigns & removals

Preinstalled / firmware


Part 1: 10 Criteria Before You Tap Install · Part 3: Auditing Preinstalled Apps That Survive a Factory Reset

Last updated: October 2026. Figures cited from Google's 2024/2025 ecosystem reports and security-vendor research as linked.