• Home
  • News
  • Fortune 500
  • Tech
  • Finance
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechGoogle

Why Downloading Flashlight Apps From Google Play May Be a Bad Idea

By
Jonathan Vanian
Jonathan Vanian
Down Arrow Button Icon
By
Jonathan Vanian
Jonathan Vanian
Down Arrow Button Icon
January 5, 2018, 9:00 AM ET

Google booted a number of apps from its online store that fooled people into believing they were helpful services, like flashlights and call recording apps, while spreading malware.

Cybersecurity company Check Point Software revealed the findings on Friday after discovering the fraudulent apps in November and notifying Google (GOOG), which promptly removed the software from the Google Play store, said Check Point security researcher Daniel Padon. Although Check Point routinely notifies the search giant of malicious apps it discovers on the Google Play store in private, it will publicly reveal more egregious forms of malware that the company believes warrants more attention, he explained.

Padon estimates that the malware, called LightsOut because if affects several flashlight apps, has been downloaded between 1.5 million to 7.5 million times. He based those numbers on publicly available download estimates from Google Play on each of the 22 different affected apps.

To trick people into installing the shady software, hackers gave the apps legitimate sounding names like “Voice Recorder Pro,” “WiFi Password Pro,” “Super Flashlight Lite,” and “Brightest LED Flashlight-Pro.”

Once downloaded and opened by users, the apps display a “settings” screen in which people can choose for the software to display online advertising. But this choice is merely an illusion, since the apps can be controlled from outside servers to display unwanted ads, Padon said.

The deceiving apps then disappear from people’s home screens, making them hard to remove for those without technical skills.

“My mother was infected by a similar adware once,” Padon recalled of older phony phantom apps. “She didn’t understand how to remove it in the first place.”

Get Data Sheet, Fortune’s technology newsletter.

A number of actions can cause unwanted ads to display on screens, including ending a phone call, locking the screen, or even plugging in a phone charger.

Although the malware does not represent a “significant step forward” in technical complexity, it highlights “another step in the way adware manages to infiltrate Google Play,” said Padon.

LightsOut shows that hackers “are becoming more sophisticated in the way they are managing to bypass Google Plays’ detections and continue to serve fraudulent ads,” he said.

How the LightsOut malware works.
How the LightsOut malware works, from Check Point.

Padon praised Google’s (GOOG) overall security efforts in filtering shady apps from Google Play, especially so-called ransomware, in which the apps, once downloaded, can immediately block people from accessing their smartphone or scramble their documents unless they pay up.

What Google struggles in, however, is discovering apps that perform covert tasks over a period of time in order to remain undetected instead of immediately engaging in fraud or other nefarious activities. And hackers are increasingly distributing malicious apps in the Google Play store, Padon said.

Based on Check Point’s research, and not counting similar efforts by other security vendors, Padon estimates that from 2016 through 2017, the amount of malware downloads “at the very least doubled” on Google Play. In 2017, Check Point estimated between 35.5 and 106 million malicious app downloads from Google Play, compared to 15.5 to 20.5 million malicious app downloads in 2016.

“It’s important to note that these numbers refer only to malware first discovered by Check Point, and do not include all malware we’ve detected, or malware detected by other vendors, so the total numbers probably exceed this by far,” he later added in an email.

Padon recommends that Android phone users install some form of security software on their smartphones that can screen for bad apps. People should generally avoid installing flashlight apps too, because they appear to be a common way that hackers routinely spread malware.

“I can’t really think of a good reason to install a flashlight app, but people continue to do so,” said Padon. “It is the cliché that keeps on giving.”

About the Author
By Jonathan Vanian
LinkedIn iconTwitter icon

Jonathan Vanian is a former Fortune reporter. He covered business technology, cybersecurity, artificial intelligence, data privacy, and other topics.

See full bioRight Arrow Button Icon

Latest in Tech

Big TechSpotify
Spotify users lamented Wrapped in 2024. This year, the company brought back an old favorite and made it less about AI
By Dave Lozo and Morning BrewDecember 4, 2025
9 hours ago
InnovationVenture Capital
This Khosla Ventures–backed startup is using AI to personalize cancer care
By Allie GarfinkleDecember 4, 2025
14 hours ago
AIEye on AI
Companies are increasingly falling victim to AI impersonation scams. This startup just raised $28M to stop deepfakes in real time
By Sharon GoldmanDecember 4, 2025
14 hours ago
Jensen Huang
SuccessBillionaires
Nvidia CEO Jensen Huang admits he works 7 days a week, including holidays, in a constant ‘state of anxiety’ out of fear of going bankrupt
By Jessica CoacciDecember 4, 2025
14 hours ago
Ted Pick
BankingData centers
Morgan Stanley considers offloading some of its data-center exposure
By Esteban Duarte, Paula Seligson, Davide Scigliuzzo and BloombergDecember 4, 2025
14 hours ago
Zuckerberg
EnergyMeta
Meta’s Zuckerberg plans deep cuts for metaverse efforts
By Kurt Wagner and BloombergDecember 4, 2025
14 hours ago

Most Popular

placeholder alt text
Economy
Two months into the new fiscal year and the U.S. government is already spending more than $10 billion a week servicing national debt
By Eleanor PringleDecember 4, 2025
19 hours ago
placeholder alt text
Success
‘Godfather of AI’ says Bill Gates and Elon Musk are right about the future of work—but he predicts mass unemployment is on its way
By Preston ForeDecember 4, 2025
15 hours ago
placeholder alt text
North America
Jeff Bezos and Lauren Sánchez Bezos commit $102.5 million to organizations combating homelessness across the U.S.: ‘This is just the beginning’
By Sydney LakeDecember 2, 2025
3 days ago
placeholder alt text
Success
Nearly 4 million new manufacturing jobs are coming to America as boomers retire—but it's the one trade job Gen Z doesn't want
By Emma BurleighDecember 4, 2025
15 hours ago
placeholder alt text
Success
Nvidia CEO Jensen Huang admits he works 7 days a week, including holidays, in a constant 'state of anxiety' out of fear of going bankrupt
By Jessica CoacciDecember 4, 2025
14 hours ago
placeholder alt text
Health
Bill Gates decries ‘significant reversal in child deaths’ as nearly 5 million kids will die before they turn 5 this year
By Nick LichtenbergDecember 4, 2025
1 day ago
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.