The Joker Android malware repeatedly infiltrated Google Play through seemingly legitimate apps, where it used multistage payload delivery, dynamic code loading, and heavy obfuscation to evade review while stealing SMS messages, contacts, device data, and notification content. Researchers tied campaigns across dozens of apps and hundreds of thousands of installs, including trojanized utility, wallpaper, camera, and medical-themed applications. Multiple reports showed Joker hiding malicious logic in ad frameworks, splash-screen code, packed APKs, Apache Cordova components, and runtime-loaded .dex or .jar files, with some samples using DexClassLoader, JavaScript-to-Java bridges, and notification-listener abuse to capture one-time PINs and SMS content without directly requesting sensitive permissions.
The malware’s primary objective was premium-service fraud: it identified victims by SIM or mobile country code, selectively targeted users in specific countries, intercepted verification messages, and silently enrolled devices in premium WAP or premium SMS subscriptions. Analysts observed infrastructure hosted on domains and cloud storage including Aliyun OSS, as well as payload concealment through GitHub-hosted resources, while newer variants unpacked themselves at runtime with commercial packers and fetched additional stages from remote servers before activating classes absent from the original APK. Google removed identified malicious apps from the Play Store, but the reporting showed Joker remained active for years and continuously adapted its delivery and evasion techniques to sustain mobile fraud operations.

Pull IOCs and campaign context straight into your stack.
14 events from the most recent confirmed update back to the earliest known activity.
On June 19, 2022, ReBensk reported an Android/Joker sample that used encrypted Aliyun OSS URLs and a multistage chain to download and load successive JAR and DEX payloads, including components named seek and Yang. Cryptax's follow-on analysis showed the sample decrypted strings with PBEWithMD5AndDES, loaded code via getClassLoader and DexClassLoader, and reused a com.xjuys payload previously seen in other Joker samples.
Check Point reported a new Joker variant on Google Play that concealed its malicious DEX payload as Base64-encoded data inside the app, then decoded and dynamically loaded it to evade detection. The campaign used a Notification Listener service and C2-controlled activation to silently subscribe victims to premium services, and the researchers published multiple infected package names and hashes.
DNS metadata cited by CSIS TechBlog suggested that the Joker family's recent campaigns began in early June 2019.
K7 Labs states that the Joker malware family had been targeting Android users since it was discovered in 2017.
A Medium analysis examined the Android app Health Index Monitor, identifying it as a Joker-family sample that used Apache Cordova plus multiple dynamically loaded stages including a payload DEX, a remote JAR, and a fourth-stage DEX. The malware stole SMS content via notification-listener access, registered SMS receivers, exfiltrated data, and could retrieve accounts and send SMS messages.
K7 Labs stated that multiple recently discovered Joker-infected Google Play apps, including com.camera.phototimezonecamera and related packages, had been removed from the store.
K7 Labs analyzed a Joker sample in com.camera.phototimezonecamera that dynamically downloaded a first-stage JAR from grouplearn[.]shop and a second-stage JAR from implemente[.]life. The second payload supplied the missing okhttp3.service class and enabled SMS interception and premium-service subscription fraud.
Quick Heal reported that Google Play Store applications were again found carrying Joker malware, indicating continued recurrence of malicious Android apps in the Play ecosystem.
K7 Labs listed multiple Google Play packages tied to the Joker campaign, including com.upinklook.kunicam, kindledev.nap.ksms, com.camerasideas.collagemaker, and others, along with hashes, payload URLs, and final C2 IP addresses.
K7 Labs reported a new Google Play Joker campaign in which samples such as kindledev.nap.ksms used Tencent Legu or ijiami packers, unpacked at runtime, and downloaded malicious DEX payloads. The campaign continued Joker's SMS theft, contact theft, and premium-service fraud activity.
Trend Micro found two additional Joker-associated samples tied to surasuke7.github.io, though neither sample was available on Google Play.
Trend Micro analyzed a Joker sample embedded in a working wallpaper app that used a JavaScript bridge and GitHub-hosted infrastructure at surasuke7.github.io to help hide payload elements. The sample appeared to target a mobile operator in Thailand and subscribed users to a WAP service without their knowledge.
CSIS TechBlog said Google was removing the malicious Joker apps from Google Play during the researchers' investigation.
CSIS TechBlog reported Joker distributed through 24 Google Play apps with more than 472,000 installs. The malware used second-stage payloads to steal SMS messages, contacts, and device data while committing premium-subscription fraud.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 123 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
9 references tracked. Mallory keeps watching after this page renders.
cryptax.medium.com
Open sourcecryptax.medium.com
Open sourcelabs.k7computing.com
Open sourceblogs.quickheal.com
Open sourcelabs.k7computing.com
Open sourceblogs.quickheal.com
Open sourcetrendmicro.com
Open sourceresearch.checkpoint.com
Open sourcemedium.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.