Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - 35M Downloads Of Android Minecraft Clones Spreads Adware
News & Analysis Application Security Attacks Malware Mobile Security Security Threats and Vulnerabilities

35M Downloads Of Android Minecraft Clones Spreads Adware

Olivia WilliamBy Olivia WilliamApril 27, 2023Updated:August 13, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
35M Downloads Android Minecraft Clones Spread Adware
35M Downloads Android Minecraft Clones Spread Adware
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

A group of 38 Minecraft-like games on Google Play attacked devices with the Android adware “HiddenAds,” which loaded ads in the background without the user’s knowledge. This made money for the games’ creators.

Minecraft is a successful sandbox game with over 140 million active players monthly. Many game companies have tried to make similar games. About 35 million Android users around the world, mostly from the US, Canada, South Korea, and Brazil got Minecraft-like games that were hiding adware.

Android Minecraft clones with 35M downloads infect users with adware – @billtoulashttps://t.co/u48lXRoWTX

— BleepingComputer (@BleepinComputer) April 27, 2023

Users didn’t notice the bad software activity going on in the background because they could play the games as promised. Also, a lot of ads could cause your device to get too hot, use more network data, or use up more battery power, which could be seen as being caused by the game.

The adware set was found by McAfee’s Mobile Research Team, which is part of the App Defense Alliance, which was made to protect Google Play from all kinds of dangers.

After reporting, all of the apps were reported and then taken off the store. Here are the most popular apps from this group of bad ones:

  • Block Box Master Diamond has been downloaded 10 million times.
  • Five million people have downloaded Craft Sword Mini Fun.
  • Block Box Skyland Sword has been downloaded 5 million times.
  • Craft Monster Crazy Sword has been downloaded 5 million times.
  • Block Pro Forrest Diamond has been downloaded 1 million times.
  • Block game Skyland Forrest has been downloaded 1 million times.
  • Block Rainbow Sword Dragon has been downloaded a million times.
  • Craft Rainbow Mini Builder has been downloaded 1 million times.
  • Block Forest Tree Crazy has been downloaded 1 million times.

McAfee says that the most popular games with malware are:

As soon as the user starts the game, the ads load in the background, but nothing shows up on the game screen. A study of network traffic, however, shows that several suspicious packets are sent and received. These packets are made by ad libraries from Google, AppLovin, Unity, and Supersonic, among others.

In the background, suspicious network packets were sent and received.

McAfee says that suspicious network messages were being traded in the background. McAfee says that the first network packets for a few of the apps have the same format, using “3.txt” as the path and looking like “https://(random).netlify.app/3.txt,” even though the domains are different for each app.

This, along with the fact that the games have similar names, points to a possible link between them, making it likely that the same person made both apps. But McAfee doesn’t say anything directly about any clear links.

Adware apps aren’t usually thought to be very dangerous for users, but they can slow down a mobile device, raise privacy concerns, and even create security holes that could let in even worse infections.

Android users should review McAfee’s report for a list of impacted apps and delete them if they haven’t already.

Conclusion

About 38 Google Play Minecraft knockoff apps infected devices with the Android adware “HiddenAds” to secretly load adverts to make cash. Numerous game publishers have tried to imitate Minecraft, a sandbox game with 140 million monthly active users. 35 million Android users in the US, Canada, South Korea, and Brazil downloaded Minecraft-like games with adware.

As promised, the consumers played the games without noticing the dangerous adware activities. Loading many adverts may cause overheating, higher network traffic, and battery consumption, which may be blamed on the game. The App Defense Alliance’s McAfee Mobile Research Team found the adware set. After reporting and removing all apps from the store, the most downloaded harmful apps are given below:

Olivia William
  • Olivia William
    Ciso Playbook: Cyber Resilience Strategy
  • Olivia William
    Apple Responds Swiftly to Active Security Threats with iOS 16.5.1 Update
  • Olivia William
    Zacks Investment Research Faces Larger Data Breach Affecting 8.8 Million Users
  • Olivia William
    British Airways and Boots Battling Data Breaches, Millions of Customers Affected

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Roundcube RCE Vulnerability Disclosed Early Amid Active Exploitation

June 10, 20255 Mins Read

Roblox Under Fire: Lawsuit Alleges Secret Data Tracking of Kids

May 13, 20254 Mins Read

Fake Indian Government Portal Used to Spread Cross-Platform Malware in Suspected APT36 Campaign

May 13, 20253 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}