• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechGoogle

Why Downloading Flashlight Apps From Google Play May Be a Bad Idea

By
Jonathan Vanian
Jonathan Vanian
Down Arrow Button Icon
By
Jonathan Vanian
Jonathan Vanian
Down Arrow Button Icon
January 5, 2018, 9:00 AM ET

Google booted a number of apps from its online store that fooled people into believing they were helpful services, like flashlights and call recording apps, while spreading malware.

Cybersecurity company Check Point Software revealed the findings on Friday after discovering the fraudulent apps in November and notifying Google (GOOG), which promptly removed the software from the Google Play store, said Check Point security researcher Daniel Padon. Although Check Point routinely notifies the search giant of malicious apps it discovers on the Google Play store in private, it will publicly reveal more egregious forms of malware that the company believes warrants more attention, he explained.

Padon estimates that the malware, called LightsOut because if affects several flashlight apps, has been downloaded between 1.5 million to 7.5 million times. He based those numbers on publicly available download estimates from Google Play on each of the 22 different affected apps.

To trick people into installing the shady software, hackers gave the apps legitimate sounding names like “Voice Recorder Pro,” “WiFi Password Pro,” “Super Flashlight Lite,” and “Brightest LED Flashlight-Pro.”

Once downloaded and opened by users, the apps display a “settings” screen in which people can choose for the software to display online advertising. But this choice is merely an illusion, since the apps can be controlled from outside servers to display unwanted ads, Padon said.

The deceiving apps then disappear from people’s home screens, making them hard to remove for those without technical skills.

“My mother was infected by a similar adware once,” Padon recalled of older phony phantom apps. “She didn’t understand how to remove it in the first place.”

Get Data Sheet, Fortune’s technology newsletter.

A number of actions can cause unwanted ads to display on screens, including ending a phone call, locking the screen, or even plugging in a phone charger.

Although the malware does not represent a “significant step forward” in technical complexity, it highlights “another step in the way adware manages to infiltrate Google Play,” said Padon.

LightsOut shows that hackers “are becoming more sophisticated in the way they are managing to bypass Google Plays’ detections and continue to serve fraudulent ads,” he said.

How the LightsOut malware works.
How the LightsOut malware works, from Check Point.

Padon praised Google’s (GOOG) overall security efforts in filtering shady apps from Google Play, especially so-called ransomware, in which the apps, once downloaded, can immediately block people from accessing their smartphone or scramble their documents unless they pay up.

What Google struggles in, however, is discovering apps that perform covert tasks over a period of time in order to remain undetected instead of immediately engaging in fraud or other nefarious activities. And hackers are increasingly distributing malicious apps in the Google Play store, Padon said.

Based on Check Point’s research, and not counting similar efforts by other security vendors, Padon estimates that from 2016 through 2017, the amount of malware downloads “at the very least doubled” on Google Play. In 2017, Check Point estimated between 35.5 and 106 million malicious app downloads from Google Play, compared to 15.5 to 20.5 million malicious app downloads in 2016.

“It’s important to note that these numbers refer only to malware first discovered by Check Point, and do not include all malware we’ve detected, or malware detected by other vendors, so the total numbers probably exceed this by far,” he later added in an email.

Padon recommends that Android phone users install some form of security software on their smartphones that can screen for bad apps. People should generally avoid installing flashlight apps too, because they appear to be a common way that hackers routinely spread malware.

“I can’t really think of a good reason to install a flashlight app, but people continue to do so,” said Padon. “It is the cliché that keeps on giving.”

About the Author
By Jonathan Vanian
LinkedIn iconTwitter icon

Jonathan Vanian is a former Fortune reporter. He covered business technology, cybersecurity, artificial intelligence, data privacy, and other topics.

See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

david
CommentaryScience
The one skill that separates people who get smarter with AI from everyone else
By David Rock and Chris WellerMarch 21, 2026
5 hours ago
Geoffrey Hinton standing in front of a white and grey background.
AITech
‘Godfather of AI’ says tech companies aren’t concerned with the AI endgame. They’re focused on short-term profits instead
By Sasha RogelbergMarch 21, 2026
6 hours ago
MagazineCoding
Cursor’s crossroads: The rapid rise, and very uncertain future, of a $30 billion AI startup
By Allie GarfinkleMarch 21, 2026
6 hours ago
war
CommentaryMiddle East
Companies are now on the front lines of war. They need to act like it
By Jeremy BashMarch 21, 2026
6 hours ago
A woman looks frustrated a computer
AIWomen
Women are avoiding the very technology that threatens them most, as expert warns of a ‘two-tiered AI economy’ approaching
By Jacqueline MunisMarch 21, 2026
9 hours ago
AIFinance
Why Block’s COO is tracking ‘gross profit per employee’—and how AI is on track to double it to $2 million
By Sheryl EstradaMarch 21, 2026
9 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.