Malicious PDF Reader App Evades Android Security Protocols
An author at Android Police encountered a suspicious app disguised as a PDF reader that evaded Google Play Protect and Samsung's built-in app protection. The app, which was installed on his mom's phone, displayed persistent notifications that turned out to be adware.
The author ran two scans using the Google Play Store and Samsung's app protection, but both came back negative for malware. However, upon closer inspection, he discovered that the app was attempting to prompt users to tap a link to install an extra add-on or update to protect their device.
This raised red flags, as it didn't make sense for an app to require additional software to safeguard user data. The author suspected that tapping the link could lead to a phishing scam or malware installation.
Fortunately, his mom had received cybersecurity training and refused to interact with the suspicious notifications. The author was able to remove the app without issues, but warns users to remain vigilant when installing apps, even from official stores.