Version 3.17.18 of the official APKPure Android app was found to contain malicious code that decrypted and launched a payload at startup, turning the third-party app store itself into a malware delivery channel. The payload collected device information, sent it to a command-and-control server, displayed intrusive advertising, opened browser pages with ads, and could fetch additional executable modules for further activity on infected devices.
Researchers observed the app downloading a Trojan resembling Triada, a malware family known for ad fraud, forced subscriptions to paid services, and secondary malware delivery. The exposure was especially serious on older Android versions, where the malware could install apps into the system partition and potentially create persistent, hard-to-remove infections similar to xHelper. APKPure was reportedly notified on April 8 and addressed the issue by releasing version 3.17.19.

Trace attribution and downstream blast radius.
3 events from the most recent confirmed update back to the earliest known activity.
APKPure remediated the incident by releasing version 3.17.19 of its Android app. Users were advised to remove version 3.17.18 and install the clean replacement.
APKPure confirmed that version 3.17.18 of its official Android app was infected with malicious code. The implanted code decrypted and launched a payload that collected device data, contacted a command-and-control server, showed ads, and could fetch additional malware.
The malicious code issue in the official APKPure Android app was reported to APKPure's developers on April 8. This disclosure preceded APKPure's confirmation and remediation of the infected release.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 11 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.