Antivirus software company Bitdefender has reported top 10 adware apps available on Google Play. The apps which include "what is my ip" still existing in Google Play, has been playing havoc in users' smartphone as well as PCs. These so called "Google Play adware" apps are integrated with sophisticated malware which makes users either subscribe to a premium-rated numbers with the help of scareware messages or get more apps installed with a even higher number of ads packed inside it. The apps are developed with such finesse that once they are downloaded by the user it gets stored in the system with different name. Once installed, they create a desktop shortcut named System Manager. With such apps requiring just 2 permissions namely - Network Communication & System Tools, it makes the user experience cumbersome as it force them to download device-clogging apps in addition to constant occurrence of adware.

The apps still available on Google Play has their origins to 2 developer accounts but the digital footprints suggests about the involvement of same person or group behind it.
Technical Details
According to the researchers at Bitdefender, this "Google Play Adware" made its way to Google's Vetting process due to the special method used by the attackers. The malicious .apk files are not being spread in the wild openly, they are wrapped up with a sophisticated attack vector i.e. a URL redirects browsers (Chrome, Firefox, Android native browser, Facebook or even TinyBrowser) to a specially crafted URL tosses the users around from one ad-showing website to another.

"For each browser search, clicked URL, or Facebook-opened link, users are redirected to a webpage (http://www.mobilsitelerim.com/anasayfa) that displays a variety of geolocation-specific ads intended to either scare viewers into subscribing to premium-rated numbers for an alleged security subscription or trick them into installing more adware disguised as system or performance updates", states the report.
Potential Damages
The report states no harm in leakage of personal information of users, but a potential aggressive behaviour of adware is detected as found on adware or certain Ransomware such as "Cryptolocker" on desktop PCs. The Ransomware messages (sometimes false scareware messages) or Pop-ups may lead to serious tension for a normal smartphone user. Also it adds upto risks of serious damages to the performance of Android devices.

Mitigation
At the time of publishing this article, certain apps still existed with adware content on Google Play. They are detected as Android.Trojan.HiddenApp.E by Bitdefender. It is strongly recommended that people facing adware and random pop-up links should install security solutions as well removing such random apps stored under suspicious names.