These 16 malicious Android apps have over 20 million downloads — delete them now

Green skull on smartphone screen.
(Image credit: Shutterstock)

Despite Google’s best efforts, 16 malicious apps which contain the Clicker malware have managed to slip past the search giant’s defenses and end up on the Google Play Store.

According to a new blog post from McAfee, these bad apps, which masquerade as utilities like flashlights and calculators, have been downloaded over 20 million times from the Play Store. 

Fortunately, the cybersecurity firm’s researchers reached out to Google and all of the apps in question have since been removed from the Play Store. Still though, if you have any of them installed on your Android smartphone or tablet, you will need to delete them manually.

These malicious apps and the malware they contain aren’t capable of stealing your identity or your data but they do commit ad fraud in the background. The danger here is that when these apps visit sites to earn ad revenue, they’re draining your battery and this can also slow down your phone.

Delete these apps now

Here is the full list of all 16 malicious apps discovered by McAfee courtesy of The Hacker News. You may notice that there are multiple instances of Flashlight+ but these are actually distinct apps from different developers. You should manually remove them from your Android devices as soon as possible to avoid extra wear and tear on their batteries.

  • High-Speed Camera - 10,000,000+ downloads
  • Smart Task Manager - 5,000,000+ downloads
  • Flashlight+ - 1,000,000+ downloads
  • 달력메모장 (Calendar Notepad) - 1,000,000+ downloads
  • K-Dictionary - 1,000,000+ downloads
  • BusanBus - 1,000,000+ downloads
  • Flashlight+ - 500,000+ downloads
  • Quick Note - 500,000+ downloads
  • Currency Converter - 500,000+ downloads
  • Joycode - 100,000+ downloads
  • EzDica - 100,000+ downloads
  • Instagram Profile Downloader - 100,000+ downloads
  • Ez Notes  - 100,000+ downloads
  • 손전등 (Flashlight) - 1,000+ downloads
  • 계산기 (Calculator) - 100+ downloads
  • Flashlight+ - 100+ downloads

Hiding their malicious behavior

While these 16 malicious apps do what their listings on the Play Store describe, they also download a remote configuration by executing an HTTP request after you open them. However, they even register a Firebase Cloud Messaging (FCM) listener to receive push messages to commit ad fraud on your devices.

The cybercriminals behind this campaign use FCM messages to let the Clicker malware within the apps know which sites to visit for ad clicks. Not only does this eat up your data plan and drain your battery but it also earns revenue for the cybercriminals.

Since these apps are visiting sites in the background, you won’t actually be able to tell they’re doing this. Other malicious apps are far more dangerous but these ones put extra strain on the best Android phones when installed.

How to stay safe from malicious apps and mobile malware

A hand holding a phone securely logging in

(Image credit: Google)

When it comes to protecting yourself from malicious apps, you should avoid downloading apps that don’t come from official app stores like the Play Store, the Amazon App Store or the Samsung Galaxy Store. In this case, doing so wouldn’t have helped but in general, you want to avoid sideloading apps on Android even though doing so can be tempting.

If you do happen to download and install a malicious app, the best Android antivirus apps can help keep you protected. Likewise, you should ensure that Google Play Protect is enabled on your Android smartphone as it frequently scans all of your apps for malware.

Finally, if an app seems too good to be true, it probably is, which is why you should think carefully before installing any new apps on your devices.

Ad fraud is quite the profitable business for cybercriminals and for this reason, we will likely continue to see malicious apps that visit sites for clicks while draining your battery and slowing down your smartphone going forward. 

Next: See our Google Pixel 7 Pro vs iPhone 14 Pro Max face-off to see which flagship phone wins. 

Anthony Spadafora
Managing Editor Security and Home Office

Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches to password managers and the best way to cover your whole home or business with Wi-Fi. He also reviews standing desks, office chairs and other home office accessories with a penchant for building desk setups. Before joining the team, Anthony wrote for ITProPortal while living in Korea and later for TechRadar Pro after moving back to the US. Based in Houston, Texas, when he’s not writing Anthony can be found tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
An image of a Google Android robot
Google blocked over 2.5 million suspicious Android apps from the Play Store last year
A smartphone screen displaying the Android name and logo next to a sign reading 'MALWARE'.
Fake Google Play Store pages are spreading Trojan malware that can steal your financial data
Google Play logo on an android smartphone with corner hole punch camera
At least 5 North Korean spy apps have been found on Google Play — what you need to know
One phone with skull and crossbones on screen among several other clean-looking phones.
Malicious iPhone apps are spreading screenshot-reading malware on the Apple App Store — how to stay safe
A laptop displaying the Chrome logo
Don't click this — malicious ads impersonating Google Chrome spreading dangerous malware
Latest in Online Security
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
A man filing his taxes electronically on a laptop
AI-powered tax scams are here - how to stay safe from deepfakes, phishing and more this tax season
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
Latest in News
iPhone 16 Pro vs iPhone 16 Pro Max in hand showing displays
Forget iPhone 17 — iPhone 18 could get this huge upgrade
The new Husqvarna iQ series robot lawn mower.
Husqvarna’s new robot mowers offer GPS for less
Rendered images of rumored foldable iPhone.
Foldable iPhone report just revealed key details — here's what we know
NYTimes Connections
NYT Connections today hints and answers — Sunday, March 23 (#651)
NYT Strands on a cellphone
NYT Strands today — hints, spangram and answers for game #385 (Sunday, March 23 2025)
Nintendo Switch 2
Nintendo Switch 2 rumored specs — here’s what we know so far