---
title: "New malware on Google Play: How this app made it through Play Protect"
description: "We detected on Google Play a malware with 10K+ installs: Daily Food Diary. The cybercriminal who published it bypassed Play Protect by obfuscating its code"
image: https://blog.pradeo.com/hubfs/malware_google_play.jpg
---

[![pradeo\_logo\_color](https://blog.pradeo.com/hs-fs/hubfs/pradeo_logo_color.png?width=220&height=33&name=pradeo_logo_color.png "pradeo_logo_color")](https://pradeo.com)

- Solutions 
    - [Mobile Threat Defense](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Secure Private Store](https://pradeo.com/en/solutions/mobile-device-security/secure-private-store/)
    - [Mobile Application Compliance Audit](https://pradeo.com/en/solutions/mobile-application-security/application-compliance-audit/)
    - [Runtime Application Self Protection](https://pradeo.com/en/solutions/mobile-application-security/rasp/)
    - [Shielding](https://pradeo.com/en/solutions/mobile-application-security/application-shielding/)
    - [Application Security Testing](https://pradeo.com/en/solutions/mobile-application-security/application-security-testing/)
- Use cases 
    - [Cybersecurity in MDM/ UEM](https://pradeo.com/en/use-cases/cybersecurity-in-mdm-uem/)
    - [Securing mobile devices](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Securing Mobile Applications](https://pradeo.com/en/solutions/mobile-application-security/application-security-testing/)
    - [Malware / leakware protection](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Phishing protection](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Ensuring compliance for applications](https://pradeo.com/en/compliance/)
    - [Ensuring compliance for mobile fleet](https://pradeo.com/en/compliance/)
    - [Securing BYOD](https://pradeo.com/en/solutions/mobile-device-security/secure-private-store/)
- [Become partner](https://pradeo.com/become-partner/)
- Resources 
    - [Solution briefs](https://pradeo.com/en/resources/?solution-briefs)
    - [Customer Cases](https://pradeo.com/en/resources/?customer-cases)
    - [Integration briefs](https://pradeo.com/en/resources/?integration-briefs)
    - [White Papers](https://pradeo.com/en/resources/?white-papers)
    - [Analyst reports & guides](https://pradeo.com/en/resources/?analyst-reports-guides)
    - [On demand webcast](https://pradeo.com/en/resources/?webcasts-on-demand)
    - [About us](https://pradeo.com/en/about/)
- [Blog](https://blog.pradeo.com/)
- [Contact](https://pradeo.com/contact/)
- en 
    - [**FR**](https://blog.pradeo.com/fr)
    - [**DE**](https://blog.pradeo.com/de)

### Topics

- Select a Topic

### Stay up to date

 SUBSCRIBE TO OUR BLOG

### Stay up to date

[Security Alert](https://blog.pradeo.com/topic/security-alert)

# New malware on Google Play: How this app made it through Play Protect

![Picture of Roxane Suau](https://blog.pradeo.com/hubfs/roxane-suau.jpg)

 By [Roxane Suau](https://blog.pradeo.com/author/roxane-suau) on January, 22 2021

[mailto:?subject=Take%20a%20look%20at%20this%20article](mailto:?subject=Take%20a%20look%20at%20this%20article)

![](https://blog.pradeo.com/hubfs/malware_google_play.jpg)

We detected yesterday on Google Play a**malicious mobile application** with 10K+ installs called “Daily Food Diary”. The cybercriminal who published this app **bypassed** **Play Protect security** by deeply **obfuscating**its malicious code. After being reported, the malware was shortly deleted from the official store this morning. **Users are advised to promptly ****uninstall it from their devices. **

 

[Name: Daily Food Diary](https://play.google.com/store/apps/details?id=com.dailyapp.fooddiary) 

**Package:** com.dailyapp.fooddiary 

**Version:** 22

**Installs:** 10,000+ 

 

![](https://blog.pradeo.com/hs-fs/hubfs/Daily-png.png?width=363&name=Daily-png.png)![](https://blog.pradeo.com/hs-fs/hubfs/Daily2-png.png?width=305&name=Daily2-png.png)

 

Daily Food Diary is pretending to be a legitimate app in which you can take pictures of your meals and set mealtime alerts. It features a very minimal design and a few basic functionalities with no real purpose. In fact, the app true nature is malicious.  

When users launch it, they are immediately sent to the device settings to enable the app to automatically run at startup (foreground service permission). Besides, the app is set to always run in the background (wake lock permission). When users are on the app interface, attempts to exit are overridden to make it difficult to close it.

Daily Food Diary repeatedly asks for permissions to access the contact list, and when it gets it, it directly exfiltrates contacts' information to an unknown external storage. It also requests to manage phone calls, to potentially refuse incoming calls that would temporarily prevent the app from running in the background. Other lines of code seem to be related to the Joker malware. 

 

## A sophisticated mix of obfuscation and encryption 

To hide its true intentions, Daily Food Diary malicious code is hidden in an encrypted file called 0OO00l111l1l. Other files contain the native library that can decrypt the malicious code so it can execute (libshellx-super.2019.so), the encryption key (tosversion) and additional resources (o0oooOO0ooOo.dat).  

Besides, to stay undetected from dynamic analysis, the app does not perform its malicious behaviors when running in an emulator. 

![](https://blog.pradeo.com/hubfs/Capture-PNG.png)

TOSversion : 

![](https://blog.pradeo.com/hubfs/undefined-Jan-22-2021-02-28-23-81-PM.png)

Permissions : 

![](https://blog.pradeo.com/hubfs/undefined-Jan-22-2021-02-29-26-43-PM.png)

 

 

###### About The Author

[More from this author](https://blog.pradeo.com/author/roxane-suau)

![](https://blog.pradeo.com/hs-fs/hubfs/roxane-suau.jpg?height=100&name=roxane-suau.jpg)

###### Roxane Suau

#### Recommended articles

[![Android: The 4th zero-day vulnerability patched in six months](https://blog.pradeo.com/hubfs/Template%20article%20(34).png)](https://blog.pradeo.com/android-the-4th-zero-day-vulnerability-patched-in-six-months-1)

###### [Android: The 4th zero-day vulnerability patched in six months](https://blog.pradeo.com/android-the-4th-zero-day-vulnerability-patched-in-six-months-1)

 \- June 30, 2026

[![2026 World Cup: Cyberattacks Target Fans' Mobile Devices](https://blog.pradeo.com/hubfs/Template%20article%20(31)-1.png)](https://blog.pradeo.com/2026-world-cup-cyberattacks-target-fans-mobile-devices)

###### [2026 World Cup: Cyberattacks Target Fans' Mobile Devices](https://blog.pradeo.com/2026-world-cup-cyberattacks-target-fans-mobile-devices)

 \- June 11, 2026

[![Signal: a phishing campaign targets users' backups](https://blog.pradeo.com/hubfs/Template%20article%20(30)-1.png)](https://blog.pradeo.com/signal-a-phishing-campaign-targets-users-backups)

###### [Signal: a phishing campaign targets users' backups](https://blog.pradeo.com/signal-a-phishing-campaign-targets-users-backups)

 \- June 4, 2026

### Popular articles

### Stay up to date

### Recent articles

### Articles récents

[Fence integrates Pradeo's technology to secure its clients' mobile fleets](https://blog.pradeo.com/fence-integrates-pradeos-technology-to-secure-its-clients-mobile-fleets-1)

 \- 22 January, 2021

[RedHook: the banking trojan that grants itself system-level access on Android](https://blog.pradeo.com/redhook-the-banking-trojan-that-grants-itself-system-level-access-on-android)

 \- 22 January, 2021

[What Google's latest report reveals about mobile threats](https://blog.pradeo.com/what-googles-latest-report-reveals-about-mobile-threats)

 \- 22 January, 2021

[Android: The 4th zero-day vulnerability patched in six months](https://blog.pradeo.com/android-the-4th-zero-day-vulnerability-patched-in-six-months-1)

 \- 22 January, 2021

[Vibe Coding: when AI-generated code multiplies vulnerabilities](https://blog.pradeo.com/vibe-coding-when-ai-generated-code-multiplies-vulnerabilities)

 \- 22 January, 2021

### Topics

- [Mobile Security (56)](https://blog.pradeo.com/topic/mobile-security)
- [Mobile Application Security (46)](https://blog.pradeo.com/topic/mobile-application-security)
- [Expertise (31)](https://blog.pradeo.com/topic/expertise)
- [Security Alert (30)](https://blog.pradeo.com/topic/security-alert)
- [Cybersecurity (29)](https://blog.pradeo.com/topic/cybersecurity)
- [News (28)](https://blog.pradeo.com/topic/news)
- [Partners (25)](https://blog.pradeo.com/topic/partners)
- [Corporate (12)](https://blog.pradeo.com/topic/corporate)
- [Events (4)](https://blog.pradeo.com/topic/events)
- [Actualité (2)](https://blog.pradeo.com/topic/actualité)
- [predictions (2)](https://blog.pradeo.com/topic/predictions)
- [cyberattack (1)](https://blog.pradeo.com/topic/cyberattack)

see all

[![New Call-to-action](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/2378615/ad3111b0-9454-41ff-91f4-9eee95b1f08f.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/2378615/ad3111b0-9454-41ff-91f4-9eee95b1f08f)

### Get in touch with mobile security experts

[Contact us](https://www.pradeo.com/en-US/contact-us)

[![](https://blog.pradeo.com/hs-fs/hubfs/pradeo_logo_white_square.png?width=90&height=74&name=pradeo_logo_white_square.png)](https://pradeo.com)

European leader in mobile security, Pradeo protects business mobile devices and applications.

[Read More](https://www.pradeo.com/en-US/)

- [Resources](https://www.pradeo.com/en-US/pradeo-ressources#white_papers)
- [UEM security](https://www.pradeo.com/en-US/uem-mdm-security)
- [Use cases](https://www.pradeo.com/en-US/pradeo-ressources#use-case)
- [Data protection](https://www.pradeo.com/en-US/mobile-data-privacy-regulation)
- [Contact us](https://www.pradeo.com/en-US/contact-us)

- [Mobile Threat Defense](https://www.pradeo.com/en-US/mobile-threat-defense)
- [Mobile Application Security Testing](https://www.pradeo.com/en-US/application-security-testing)
- [In-App Protection](https://www.pradeo.com/en-US/in-app-protection)
- [Secure Private Store](https://www.pradeo.com/en-US/private-app-store)
- [Mobile Threat Intelligence](https://www.pradeo.com/en-US/mobile-threat-intelligence#perso-threat-intelligence)

![email.svg](https://cdn2.hubspot.net/hubfs/3067823/awwal/email.svg "email.svg")

[contact@pradeo.com](mailto:contact@pradeo.com)

Copyright @ 2022. All Right Reserved.

- <https://www.linkedin.com/company/pradeo-security-systems>
- <https://twitter.com/pradeo>
- <https://www.youtube.com/channel/UCD7hgYE8WuipxJtxsHDUdMA>

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Roxane Suau"
  },
  "dateModified" : "January 27, 2021, 3:28:04 PM",
  "datePublished" : "2021-01-22 15:04:03",
  "description" : "We detected on Google Play a malware with 10K+ installs: Daily Food Diary. The cybercriminal who published it bypassed Play Protect by obfuscating its code",
  "headline" : "New malware on Google Play: How this app made it through Play Protect",
  "image" : {
    "@type" : "ImageObject",
    "url" : "https://f.hubspotusercontent10.net/hubfs/2378615/malware_google_play.jpg"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://2378615.fs1.hubspotusercontent-eu1.net/hubfs/2378615/Logo%20Pradeo%20D%C3%A9grad%C3%A9%20Long%20Couleurs.svg"
    },
    "name" : "Pradeo"
  }
}
```