Check Point researchers identified an Android malware campaign, dubbed AdultSwine, embedded in roughly 60 game applications on Google Play, many of them designed for children. The infected apps were downloaded an estimated 3 million to 7 million times and used a command-and-control infrastructure to upload device information, receive configuration updates, hide app icons, and trigger advertising behavior after device boot or screen unlock. The malware displayed intrusive ads outside the host app, including pornographic content, while deliberately avoiding overlays on browsers and social networking apps to reduce user suspicion.
The campaign monetized infections through multiple fraud schemes, including fake virus alerts that pushed users toward dubious “security” apps and bogus prize offers such as an iPhone giveaway that harvested phone numbers for premium-service subscription fraud. Researchers warned that the same remotely controlled delivery mechanism could be adapted for broader social-engineering attacks or credential theft, highlighting the risk posed by malicious apps that bypass platform trust and reach large numbers of mobile users through official app stores.

Trace attribution and downstream blast radius.
1 event from the most recent confirmed update back to the earliest known activity.
On its publication date, Check Point researchers disclosed a malicious Android campaign they dubbed AdultSwine, embedded in about 60 Google Play game applications, several aimed at children. The report said the apps had been downloaded an estimated 3 million to 7 million times and monetized infections through pornographic ads, scareware, and fraudulent premium-service subscriptions.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 33 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.