---
title: New malware detected on Google Play, 100.000+ users affected
description: Joker is a malware that silently exfiltrates data and subscribes users to unwanted premium subscription. The malware was found in 24 apps on Google Play.
image: https://blog.pradeo.com/hubfs/joker_malware_pradeo.png
---

[![pradeo_logo_color](https://blog.pradeo.com/hs-fs/hubfs/pradeo_logo_color.png?width=220&height=33&name=pradeo_logo_color.png "pradeo_logo_color")](https://pradeo.com)

- Solutions 
    - [Mobile Threat Defense](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Secure Private Store](https://pradeo.com/en/solutions/mobile-device-security/secure-private-store/)
    - [Mobile Application Compliance Audit](https://pradeo.com/en/solutions/mobile-application-security/application-compliance-audit/)
    - [Runtime Application Self Protection](https://pradeo.com/en/solutions/mobile-application-security/rasp/)
    - [Shielding](https://pradeo.com/en/solutions/mobile-application-security/application-shielding/)
    - [Application Security Testing](https://pradeo.com/en/solutions/mobile-application-security/application-security-testing/)
- Use cases 
    - [Cybersecurity in MDM/ UEM](https://pradeo.com/en/use-cases/cybersecurity-in-mdm-uem/)
    - [Securing mobile devices](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Securing Mobile Applications](https://pradeo.com/en/solutions/mobile-application-security/application-security-testing/)
    - [Malware / leakware protection](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Phishing protection](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Ensuring compliance for applications](https://pradeo.com/en/compliance/)
    - [Ensuring compliance for mobile fleet](https://pradeo.com/en/compliance/)
    - [Securing BYOD](https://pradeo.com/en/solutions/mobile-device-security/secure-private-store/)
- [Become partner](https://pradeo.com/become-partner/)
- Resources 
    - [Solution briefs](https://pradeo.com/en/resources/?solution-briefs)
    - [Customer Cases](https://pradeo.com/en/resources/?customer-cases)
    - [Integration briefs](https://pradeo.com/en/resources/?integration-briefs)
    - [White Papers](https://pradeo.com/en/resources/?white-papers)
    - [Analyst reports & guides](https://pradeo.com/en/resources/?analyst-reports-guides)
    - [On demand webcast](https://pradeo.com/en/resources/?webcasts-on-demand)
    - [About us](https://pradeo.com/en/about/)
- [Blog](https://blog.pradeo.com/)
- [Contact](https://pradeo.com/contact/)
- en 
    - [**FR**](https://blog.pradeo.com/fr)
    - [**DE**](https://blog.pradeo.com/de)

### Topics

- Select a Topic

### Stay up to date

 SUBSCRIBE TO OUR BLOG

### Stay up to date

[Security Alert](https://blog.pradeo.com/topic/security-alert) [Mobile Application Security](https://blog.pradeo.com/topic/mobile-application-security)

# New malware detected on Google Play, 100.000+ users affected

![Picture of Roxane Suau](https://blog.pradeo.com/hubfs/roxane-suau.jpg)

 By [Roxane Suau](https://blog.pradeo.com/author/roxane-suau) on July, 5 2022

[mailto:?subject=Take%20a%20look%20at%20this%20article](mailto:?subject=Take%20a%20look%20at%20this%20article)

![pradeo_int_app_lock_joker_malware2](https://blog.pradeo.com/hubfs/joker_malware_pradeo.png)

*This article is regularly updated with the names of new mobile applications infected with Joker malware but yet available for download on Google Play. Our team *always alerts Google of its discoveries.**

---

Updated on Tuesday July 5th, 2022

Pradeo just identified 4 new malicious applications embedding the Joker malware and acting as droppers, available for download on Google Play. Jointly, they have been installed by 100.000+ users.

Joker is categorized as Fleeceware, as its main activity is to subscribe to unwanted paid services or send SMS / make calls to premium numbers, unbeknownst to users. By using as little code as possible and thoroughly hiding it, Joker generates a very discreet footprint that can be tricky to detect. In the last three years, the malware was found hiding in thousands of apps.

Users are advised to immediately delete these applications from their smartphones and tablets to avoid fraudulent activities:

| Version: 1.3.2 \| Installs: 50.000+[![smart-sms-messages](https://blog.pradeo.com/hs-fs/hubfs/smart-sms-messages.jpg?width=1905&name=smart-sms-messages.jpg)](https://play.google.com/store/apps/details?id=com.sms.mms.message.ffei.free) | Version: 1.3.238 \| Installs: 10.000+<https://play.google.com/store/apps/details?id=laughthofire.autrusmartcamera>[![blood-pressure](https://blog.pradeo.com/hs-fs/hubfs/blood-pressure.jpg?width=1905&name=blood-pressure.jpg)](https://play.google.com/store/apps/details?id=com.listening.bpmonitor) |
| --- | --- |
| Version: 2.0 \| Installs: 10.000+[![voice-lang-translator](https://blog.pradeo.com/hs-fs/hubfs/voice-lang-translator.jpg?width=1905&name=voice-lang-translator.jpg)](https://play.google.com/store/apps/details?id=com.piolang.transltor.voice) | Version: 2.0 \| Installs: 10.000+[![quick-txt-sms](https://blog.pradeo.com/hs-fs/hubfs/quick-txt-sms.jpg?width=1905&name=quick-txt-sms.jpg)](https://play.google.com/store/apps/details?id=com.sms.qiatext.messagesing) |

 

## How it works

Our analysis of the above-mentioned applications shows that they use various mechanism to commit fraud, through in-app purchase or SMS sending to premium numbers.

To bypass two-factor authentication protocols during in-app purchases, Smart SMS Messages and Blood Pressure monitor intercept one-time passwords. To do so, the first one simply reads SMS and takes silent screenshots, the second one intercepts notifications’ content. Victims only notice the fraud when receiving their mobile phone invoice, potentially weeks after it started.

All of these apps are programmed to install other applications on users’ devices, acting as dropper to potentially convey even more dangerous malware.

By diving into these applications, we noticed several elements that compose a pattern when it comes to malicious applications on Google Play, and that could help users anticipate their malicious nature. First, their developers’ account only feature one app each. Usually once they are banned from the store, they simply create another one. Secondly, their privacy policies are short, use a template, never disclose the full extent of the activities the apps can perform and are hosted on a Google Doc or Google Site page. Finally, those applications are never related to a company name or website.

 

## Previously infected applications

---

Beautiful Themed Keyboard  
Package: com.expression.kept.current.keyboardthemes  
Version: 3.6  
Installs: 5.000+

![](https://blog.pradeo.com/hs-fs/hubfs/image-png-Jun-30-2022-12-52-47-11-PM.png?width=223&name=image-png-Jun-30-2022-12-52-47-11-PM.png)

---

All Wallpaper Messenger  
Package: com.estarpro.liteSMS  
Version: 2.2.0  
Installs: 100.000+

![](https://blog.pradeo.com/hs-fs/hubfs/image-png-Jun-30-2022-12-53-07-02-PM.png?width=223&name=image-png-Jun-30-2022-12-53-07-02-PM.png)

---

Angina Reports  
Package: com.anbackward.reportsanginahealthy  
Version: 1.05.20  
Installs: 5.000+

![](https://blog.pradeo.com/hs-fs/hubfs/image-png-Jun-30-2022-12-53-20-66-PM.png?width=223&name=image-png-Jun-30-2022-12-53-20-66-PM.png)

---

Moon Horoscope  
Package: com.hearite.moonhoroscope  
Version: 51.5  
Installs: 10.000+

![](https://blog.pradeo.com/hs-fs/hubfs/image-png-Jun-30-2022-12-53-33-68-PM.png?width=223&name=image-png-Jun-30-2022-12-53-33-68-PM.png)

---

**Color Message**  
Package: com.guo.smscolor.amessage  
Version: 3.1  
Installs: 100.000+

[![](https://blog.pradeo.com/hs-fs/hubfs/image-png-May-24-2022-04-12-59-92-PM.png?width=223&name=image-png-May-24-2022-04-12-59-92-PM.png)](https://play.google.com/store/apps/details?id=applock.safety.protect.apps)

---

**Safety AppLock**  
Package: applock.safety.protect.apps  
Version: 6.5  
Installs: 10.000+

[![Capture d’écran 2020-08-31 à 10.00.14](https://blog.pradeo.com/hs-fs/hubfs/Capture%20d%E2%80%99e%CC%81cran%202020-08-31%20a%CC%80%2010.00.14.jpg?width=222&name=Capture%20d%E2%80%99e%CC%81cran%202020-08-31%20a%CC%80%2010.00.14.jpg)](https://play.google.com/store/apps/details?id=applock.safety.protect.apps)

---

**Convenient Scanner 2**  
Package: com.convenient.scanner.tb  
Version: 14.0.4  
Installs: 100.000+

[![Capture d’écran 2020-08-31 à 10.00.04](https://blog.pradeo.com/hs-fs/hubfs/Capture%20d%E2%80%99e%CC%81cran%202020-08-31%20a%CC%80%2010.00.04.jpg?width=222&name=Capture%20d%E2%80%99e%CC%81cran%202020-08-31%20a%CC%80%2010.00.04.jpg)](https://play.google.com/store/apps/details?id=com.convenient.scanner.tb)

---

**Push Message-Texting&SMS**  
Package: sms.pushmessage.messaging  
Version: 4.13  
Installs: 10.000+

[![Capture d’écran 2020-08-31 à 09.59.50](https://blog.pradeo.com/hs-fs/hubfs/Capture%20d%E2%80%99e%CC%81cran%202020-08-31%20a%CC%80%2009.59.50.jpg?width=221&name=Capture%20d%E2%80%99e%CC%81cran%202020-08-31%20a%CC%80%2009.59.50.jpg)](https://play.google.com/store/apps/details?id=sms.pushmessage.messaging)

---

**Emoji Wallpaper**  
Package: tw.hdwallpaperthemes.emoji.wallpaper  
Version: 14.3  
Installs: 10.000+

[![Capture d’écran 2020-08-31 à 09.59.40](https://blog.pradeo.com/hs-fs/hubfs/Capture%20d%E2%80%99e%CC%81cran%202020-08-31%20a%CC%80%2009.59.40.jpg?width=222&name=Capture%20d%E2%80%99e%CC%81cran%202020-08-31%20a%CC%80%2009.59.40.jpg)](https://play.google.com/store/apps/details?id=tw.hdwallpaperthemes.emoji.wallpaper)

---

**Separate Doc Scanner**  
Package: sk.pdf.separatedoc.scanner  
Version: 2.0.74  
Installs: 50.000+

[![Capture d’écran 2020-08-31 à 09.59.24](https://blog.pradeo.com/hs-fs/hubfs/Capture%20d%E2%80%99e%CC%81cran%202020-08-31%20a%CC%80%2009.59.24.jpg?width=221&name=Capture%20d%E2%80%99e%CC%81cran%202020-08-31%20a%CC%80%2009.59.24.jpg)](https://play.google.com/store/apps/details?id=sk.pdf.separatedoc.scanner)

---

**Fingertip GameBox**  
Package: com.theone.finger.games  
Version: 3.0.7  
Installs: 1000+

[![Capture d’écran 2020-08-31 à 09.59.09](https://blog.pradeo.com/hs-fs/hubfs/Capture%20d%E2%80%99e%CC%81cran%202020-08-31%20a%CC%80%2009.59.09.jpg?width=222&name=Capture%20d%E2%80%99e%CC%81cran%202020-08-31%20a%CC%80%2009.59.09.jpg)](https://play.google.com/store/apps/details?id=com.theone.finger.games)

---

 

For more information, write to [roxane.suau@pradeo.com.](mailto:roxane.suau@pradeo.com)

 

###### About The Author

[More from this author](https://blog.pradeo.com/author/roxane-suau)

![](https://blog.pradeo.com/hs-fs/hubfs/roxane-suau.jpg?height=100&name=roxane-suau.jpg)

###### Roxane Suau

#### Recommended articles

[![Android: The 4th zero-day vulnerability patched in six months](https://blog.pradeo.com/hubfs/Template%20article%20(34).png)](https://blog.pradeo.com/android-the-4th-zero-day-vulnerability-patched-in-six-months-1)

###### [Android: The 4th zero-day vulnerability patched in six months](https://blog.pradeo.com/android-the-4th-zero-day-vulnerability-patched-in-six-months-1)

 - June 30, 2026

[![2026 World Cup: Cyberattacks Target Fans' Mobile Devices](https://blog.pradeo.com/hubfs/Template%20article%20(31)-1.png)](https://blog.pradeo.com/2026-world-cup-cyberattacks-target-fans-mobile-devices)

###### [2026 World Cup: Cyberattacks Target Fans' Mobile Devices](https://blog.pradeo.com/2026-world-cup-cyberattacks-target-fans-mobile-devices)

 - June 11, 2026

[![Signal: a phishing campaign targets users' backups](https://blog.pradeo.com/hubfs/Template%20article%20(30)-1.png)](https://blog.pradeo.com/signal-a-phishing-campaign-targets-users-backups)

###### [Signal: a phishing campaign targets users' backups](https://blog.pradeo.com/signal-a-phishing-campaign-targets-users-backups)

 - June 4, 2026

#### Recommended articles

### Popular articles

### Stay up to date

### Recent articles

### Articles récents

[RedHook: the banking trojan that grants itself system-level access on Android](https://blog.pradeo.com/redhook-the-banking-trojan-that-grants-itself-system-level-access-on-android)

 - 5 July, 2022

[What Google's latest report reveals about mobile threats](https://blog.pradeo.com/what-googles-latest-report-reveals-about-mobile-threats)

 - 5 July, 2022

[Android: The 4th zero-day vulnerability patched in six months](https://blog.pradeo.com/android-the-4th-zero-day-vulnerability-patched-in-six-months-1)

 - 5 July, 2022

[Vibe Coding: when AI-generated code multiplies vulnerabilities](https://blog.pradeo.com/vibe-coding-when-ai-generated-code-multiplies-vulnerabilities)

 - 5 July, 2022

[2026 World Cup: Cyberattacks Target Fans' Mobile Devices](https://blog.pradeo.com/2026-world-cup-cyberattacks-target-fans-mobile-devices)

 - 5 July, 2022

### Topics

- [Mobile Security (56)](https://blog.pradeo.com/topic/mobile-security)
- [Mobile Application Security (46)](https://blog.pradeo.com/topic/mobile-application-security)
- [Expertise (31)](https://blog.pradeo.com/topic/expertise)
- [Security Alert (30)](https://blog.pradeo.com/topic/security-alert)
- [Cybersecurity (29)](https://blog.pradeo.com/topic/cybersecurity)
- [News (27)](https://blog.pradeo.com/topic/news)
- [Partners (24)](https://blog.pradeo.com/topic/partners)
- [Corporate (12)](https://blog.pradeo.com/topic/corporate)
- [Events (4)](https://blog.pradeo.com/topic/events)
- [Actualité (2)](https://blog.pradeo.com/topic/actualité)
- [predictions (2)](https://blog.pradeo.com/topic/predictions)
- [cyberattack (1)](https://blog.pradeo.com/topic/cyberattack)

see all

[![New Call-to-action](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/2378615/ad3111b0-9454-41ff-91f4-9eee95b1f08f.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/2378615/ad3111b0-9454-41ff-91f4-9eee95b1f08f)

### Get in touch with mobile security experts

[Contact us](https://www.pradeo.com/en-US/contact-us)

[![](https://blog.pradeo.com/hs-fs/hubfs/pradeo_logo_white_square.png?width=90&height=74&name=pradeo_logo_white_square.png)](https://pradeo.com)

European leader in mobile security, Pradeo protects business mobile devices and applications.

[Read More](https://www.pradeo.com/en-US/)

- [Resources](https://www.pradeo.com/en-US/pradeo-ressources#white_papers)
- [UEM security](https://www.pradeo.com/en-US/uem-mdm-security)
- [Use cases](https://www.pradeo.com/en-US/pradeo-ressources#use-case)
- [Data protection](https://www.pradeo.com/en-US/mobile-data-privacy-regulation)
- [Contact us](https://www.pradeo.com/en-US/contact-us)

- [Mobile Threat Defense](https://www.pradeo.com/en-US/mobile-threat-defense)
- [Mobile Application Security Testing](https://www.pradeo.com/en-US/application-security-testing)
- [In-App Protection](https://www.pradeo.com/en-US/in-app-protection)
- [Secure Private Store](https://www.pradeo.com/en-US/private-app-store)
- [Mobile Threat Intelligence](https://www.pradeo.com/en-US/mobile-threat-intelligence#perso-threat-intelligence)

![email.svg](https://cdn2.hubspot.net/hubfs/3067823/awwal/email.svg "email.svg")

[contact@pradeo.com](mailto:contact@pradeo.com)

Copyright @ 2022. All Right Reserved.

- <https://www.linkedin.com/company/pradeo-security-systems>
- <https://twitter.com/pradeo>
- <https://www.youtube.com/channel/UCD7hgYE8WuipxJtxsHDUdMA>

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Roxane Suau"
  },
  "dateModified" : "July 5, 2022, 9:43:29 AM",
  "datePublished" : "2022-07-05 08:46:01",
  "description" : "Joker is a malware that silently exfiltrates data and subscribes users to unwanted premium subscription. The malware was found in 24 apps on Google Play.",
  "headline" : "New malware detected on Google Play, 100.000+ users affected",
  "image" : {
    "@type" : "ImageObject",
    "url" : "https://f.hubspotusercontent10.net/hubfs/2378615/joker_malware_pradeo.png"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://2378615.fs1.hubspotusercontent-eu1.net/hubfs/2378615/Logo%20Pradeo%20D%C3%A9grad%C3%A9%20Long%20Couleurs.svg"
    },
    "name" : "Pradeo"
  }
}
```