Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In June 2012, two applications on Google Play posed as Super Mario Bros. and GTA3 Moscow City. Symantec found that they used a remote-payload design: the installed app could look relatively harmless while additional malicious functionality was retrieved or activated later. SecurityWeek reported 50,000–100,000 downloads per application before Google removed them—download counts, not confirmed infections.

The apps Symantec found

The strongest match for this incident is a July 2012 Symantec investigation attributed to researcher Irfan Asrar. Both games reportedly appeared on Google Play on June 24, 2012. SecurityWeek described the findings on July 11, following Symantec’s publication on July 10.

App listing Reported timing Reported reach and outcome
Super Mario Bros. Appeared June 24, 2012 50,000–100,000 reported downloads; removed by Google after notification
GTA3 Moscow City Appeared June 24, 2012 50,000–100,000 reported downloads; removed by Google after notification

SecurityWeek’s report does not establish that every download became an infected device, so the figures should not be presented as confirmed victims or as a current outbreak.

What “disguising malware” meant in this case

This was more than copying a game title or icon. The important technique was staging:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. A user installed an application presented as a game.
  2. The first-stage package concealed, deferred, or kept its most suspicious behavior inactive.
  3. Additional code or instructions could be downloaded or enabled remotely.
  4. The operator could change what happened after installation without replacing the visible store listing.

A conventional static scan examines the package it receives. A staged app can therefore separate its benign-looking front end from later behavior. The 2012 report establishes the remote-payload approach; it does not, by itself, prove that these two samples stole banking credentials, sent premium SMS messages, or carried out every behavior seen in later Android threats.

Why attackers use remote payloads

  • Less obvious first-stage code: the initial APK may be smaller or contain fewer recognizable malicious components.
  • Screening friction: a scanner may not observe a later download, delayed trigger, or server-directed action.
  • Changeability: operators can modify payloads or configuration without publishing an obviously different app.
  • Selective activation: a command server can decide when, where, or for whom functionality is enabled.

These are general security advantages of staged malware, not a claim that every mechanism was demonstrated in both named games. In a later Symantec-documented campaign, fake charger and cleaner apps received app lists, delay values, and advertising-server instructions from command-and-control infrastructure, illustrating how remote configuration supports testing and monetisation. See the Broadcom/Symantec technical document.

Why popular games were effective cover

Recognisable names create search traffic and an expectation that the app should be installed quickly, particularly when users are looking for unofficial versions of paid or famous games. A copied brand can make a developer profile, icon, and description seem familiar even when the publisher is unrelated. The listing’s apparent purpose also distracts from questions about package identity, permissions, and network activity.

What a concealed payload can do

The 2012 coverage confirms malicious applications and remote delivery, but not a complete payload inventory. Depending on what an operator delivers, disguised Android malware can:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • download another malicious component;
  • collect contacts, SMS messages, account data, or device identifiers;
  • display fraudulent overlays or capture input;
  • send premium-rate messages or perform advertising fraud;
  • abuse accessibility, notification, overlay, or device-administrator privileges;
  • hide its launcher icon or maintain persistence.

Those behaviors are documented in later Android investigations, not automatically in the two 2012 game samples. For example, Broadcom describes a fake Google Play Store application associated with Hydra (report), Vultur posing as an antivirus app and using overlays (report), and BTMOB using fake interfaces, overlays, and accessibility permissions (report).

Other evasion tricks seen in Android malware

Remote delivery is one layer in a broader disguise strategy. Symantec documentation has described:

  • obfuscation and packing that alter or conceal code;
  • unusual values in AndroidManifest.xml and compiled resources to frustrate scanners;
  • different names in the launcher and Android’s application settings;
  • process names that look ordinary or system-related;
  • removal of the launcher icon while the app remains installed.

Obfuscation alone is not proof of malware—legitimate developers also protect intellectual property—but an unexpected combination of identity mismatches, excessive permissions, delayed behavior, and unexplained network traffic is a stronger warning. See Symantec’s overview of Android malware evasion techniques and its documentation of apps that hide under alternate identities or disappear from the launcher (technical example).

How to assess a suspicious Android app

  • Publisher: compare the developer with the genuine publisher’s official site.
  • Package identity: check whether the package name, listing, icon, and installed name agree.
  • Permissions: be wary when a game requests SMS, accessibility, notification access, overlay, or device-administrator privileges without a clear need.
  • Reviews and updates: repetitive reviews, a newly renamed listing, or an implausible update history are warning signs.
  • Distribution: Google Play reduces risk but cannot guarantee safety; APKs from advertisements, messages, forums, and unofficial stores carry greater risk.
  • After installation: unexpected ads, redirects, battery drain, data use, overlays, or a disappearing icon deserve investigation.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to do if one is installed

  1. Go to Settings → Apps, select the suspicious app, and uninstall it.
  2. If uninstall is blocked, reboot into Safe Mode, remove any device-administrator privilege under the device-security settings, then uninstall from Settings.
  3. Run Google Play Protect or another reputable mobile-security scan. Google describes Play Protect at its official support page.
  4. Review accessibility services, notification access, overlay permissions, installation privileges, and device-administrator apps for unfamiliar entries.
  5. If credential or financial theft is plausible, use a clean device to change important passwords, review Google, email, social, and banking activity, and contact financial institutions about suspicious transactions.
  6. Install Android and Google Play system updates.
  7. If symptoms continue, back up only essential data and consider a factory reset. Do not restore suspicious APKs or automatically reinstall every old application.

Uninstalling may remove ordinary adware, but it does not prove that credentials were not copied or accounts were not compromised. A factory reset removes local software; it cannot reverse stolen data or fraudulent transactions.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The lesson for Android users

The 2012 incident is historical, and Google removed the two listings. Its lasting lesson is current: an app’s title, icon, store presence, and apparent function are not sufficient proof of safety. Impersonation combined with delayed or remotely delivered behavior can separate what users see from what the installed software eventually does. Check identity and permissions before installation, keep Android updated, and treat unexpected behavior as a security event rather than merely a nuisance.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.