technology
SimBad adware found in 206 Google Play apps with nearly 150 million downloads
Check Point found SimBad in 206 now-removed simulator games on Google Play that show ads, open phishing URLs and can install apps remotely.
Apr 2nd 2026 ยท United States
Insights
- Check Point identified 206 Google Play apps infected by the SimBad adware.
- The infected apps have been downloaded almost 150 million times globally.
- Google removed all identified infected apps from the Play Store after being notified.
- SimBad can display ads, open phishing URLs in the device browser, and install apps remotely by contacting a command and control server.
- Researchers warn SimBad currently acts as adware but has the infrastructure to evolve into a more serious threat.
Sources
- WhatsApp says Italian surveillance company tricked around 200 users into downloading spyware www.thehindu.com
- WhatsApp has an alert on fake app that some iPhone users in Italy downloaded timesofindia.indiatimes.com
- WhatsApp Alerts 200 Users After Fake iOS App Installed Spyware; Italian Firm Faces Action thehackernews.com
- Microsoft Warns of WhatsApp-Delivered VBS Malware Hijacking Windows via UAC Bypass thehackernews.com
- Over 150 millions users have downloaded one of 200 SimBad adware infected Google Play Store apps 9to5google.com