Close Menu
MyAppsPlus

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Anthropic CEO calls for pacing AI frontier model development and warns ‘in 6–12 months such a swarm [of agents] could be capable of taking over the entire internet’

    September 12, 2026

    Android malware creates a hidden copy of your banking app

    September 12, 2026

    iPhone 18 Pro and iPhone 18 Pro Max Now Available to Pre-Order

    September 12, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    MyAppsPlusMyAppsPlus
    Saturday, September 12
    • Home
    • Breaking Tech
    • Apps & Software
    • AI & Automation
    • Android
    • iPhone & iOS
    • More
      • Reviews
      • How-To Guides
      • Deals & Discounts
      • Shop
    MyAppsPlus
    Home»Android»The 2026 list of malicious Android and iPhone apps
    Android

    The 2026 list of malicious Android and iPhone apps

    myappsplusBy myappsplusAugust 31, 2026008 Mins Read
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email Telegram WhatsApp
    Follow Us
    Google News Flipboard
    The 2026 list of malicious Android and iPhone apps
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    Last year, I gave you 224 apps to delete. This year’s list is shorter but nastier. Twenty-eight of these apps sold the same scam under one name. Five hid a bank-login thief inside a PDF reader. Fifty planted a rootkit that survives a factory reset.

    Every app on this page has been removed from Google Play or Apple’s App Store. But there’s a problem. Removal stops new downloads. It does not reach the copy already on your phone. If you installed any of these, it’s still there, still running.

    Here’s what to do. Scroll the list, delete anything you recognize, then run the five-minute check at the bottom. And bookmark this page. I’ll keep it current.

    Do this first (two minutes)

    Android: Open the Play Store, tap your profile picture, tap Play Protect, tap Scan. Google says Play Protect automatically removes the worst of these once they’re flagged. Let it finish.

    iPhone: There’s no equivalent scanner. Go to Settings > General > iPhone Storage, scroll the list and delete anything you don’t recognize or haven’t opened in months.

    Now the list.

    1. The “Call History” scam (28 apps, 7.3 million downloads)

    Found by ESET in May 2026. These apps promised to show you anyone’s call log, texts or WhatsApp history for $6 to $80. They took the money through Google Play billing, credit cards and UPI, then handed back random gibberish. They went by nearly identical names, so here’s the rule: If the app name starts with “Call History,” delete it.

    • Call history: any number deta (3 million+ downloads)
    • Call History of Any Number (1 million+)
    • Call Details of Any Number (1 million+)
    • Call History Any Number Detail (five separate versions, 100,000 to 500,000 downloads each)
    • Call History Of Any Number (several versions)
    • Call History of Any Numbers
    • Call History Any Number detail
    • Call History Any Number
    • Phone Call History Tracker
    • Call History Pro
    • Call History of Numbers
    • Call History For Any Number
    • Call History – Any Number Data
    • Call History- Any Number Deta (hiding inside a “PDF maker” package)

    If you paid one of these, dispute the charge with your card or through Google Play’s refund page. You were sold nothing.

    2. The bank account thieves (Anatsa droppers)

    Found by Zscaler and Kaspersky between December 2025 and August 2026. These look like plain document readers. Once installed, they quietly download Anatsa, a banking Trojan that lays a fake login screen over 831 banking and finance apps, logs what you type and reads your texts for the verification codes. The tell: a PDF reader that asks you to “install an update” from inside the app.

    • Document Reader – File Manager (50,000+ downloads)
    • StellarGrid (50,000+)
    • Fake “Document Reader” (10,000+; package name begins com.groundstation)
    • File Horizon (Document Reader) (100,000+)
    • Cleanova

    If you had one of these, change your banking passwords from a different device, turn on a passkey or authenticator app, check your statements for transfers you didn’t make andfreeze your credit at all four bureaus, so a stolen login can’t be used to open new accounts in your name. 

    3. The rootkit that survives a factory reset (Operation NoVoice, 50+ apps, 2.3 million installs)

    Found by McAfee in March 2026. These apps used old Android bugs to rewrite a core system file so every app on the phone runs the attacker’s code. It cloned WhatsApp sessions and stayed put through a factory reset. Google’s position: Phones with a security update from May 2021 or later were never vulnerable. If your phone can’t update anymore, this one is aimed at you.

    • Storage Cleaner
    • WiFi Finder
    • Universal Assistant
    • Dynamic Puzzle
    • Gallery App
    • Blend Photo
    • Life Toolbox
    • 2048 Game

    McAfee listed 47 more by package name only, including an “AirVPN,” a “BeautyCam,” a Ludo game and a pregnancy-exercise app. If your phone hasn’t had a security update in years and you have a no-name cleaner, VPN or game you don’t remember installing, that’s the one.

    4. The camera apps with a backdoor (Keenadu, 300,000+ installs)

    Found by Kaspersky in February 2026. Smart-home camera apps carrying a backdoor that can install other apps, grant itself permissions, read banking data and watch your incognito browsing. Kaspersky also found it baked into the firmware of cheap no-name tablets.

    • Eoolii
    • Ziicam
    • Eyeplus – Your home in your eyes

    5. The subscription signers (Joker and friends, 19 apps)

    Found by Doctor Web in quarterly sweeps from October 2025 through July 2026. These sign you up for premium services you never see until they show up on your phone bill. Fun fact: You never need a third-party “cleaner” app. Android and iPhone clean themselves.

    • ShowLounge – TV & Dramas
    • AIM: Crosshair Asist
    • True Cargo Drive
    • Battery 3D: Charge Effects
    • PixStudio – Photo Editor
    • Chat Messages
    • Easy Messages
    • Smart File Cleaner
    • Junk Clean Master
    • Fast Cleaner
    • Private Chat Message
    • Magic Camera
    • Stream Hive
    • Prime Link
    • Useful Cleaner
    • Reel Drama
    • Clean Boost
    • Convert Text to PDF
    • File Text Messages

    Check your carrier bill for charges you don’t recognize and call to have them removed. Ask for a “third-party billing block” while you’re on the phone. If a charge on your bill doesn’t trace back to an app you remember installing, you may be a victim of phone-bill cramming, and there’s a way to get that money back. 

    Also from Doctor Web’s sweeps. Games that redirect to offshore casinos, “rewards” apps that never pay out and camera apps that spray ads.

    • Chicken Road Fun
    • Zeus Jackpot Mania
    • Pino Bounce
    • TPAO
    • Coin News Promax
    • Time Shift Cam
    • Fusion Collage Editor

    7. iPhone: the crypto-wallet thieves

    Found by Kaspersky in April 2026, plus a July lawsuit. Apple’s store isn’t immune, it’s just targeted differently. These posed as real crypto wallets, then captured the recovery phrase that unlocks everything.

    • LeddgerNew (note the typo; one of 26 “FakeWallet” apps impersonating Ledger, MetaMask, Trust Wallet, Coinbase, TokenPocket, imToken and Bitpie)
    • SafeW – 云办公助理 and 悟空外卖 (SparkCat v2: ask for photo access, then read your screenshots for wallet phrases)
    • SafeX (the Android twin of SparkCat v2)
    • Sparrow Wallet (counterfeit; the real Sparrow is desktop-only. A lawsuit says this fake stole $1.8 million from three people)
    • Freecash (not malware, but pulled in April for selling user data)

    Rule: A wallet app with a misspelled name is a thief with a typo.

    The numbers you can’t see on this list

    Some of the biggest campaigns this year never published app names, only technical package IDs. You can’t look them up by name, but you should know the scale:

    • Trapdoor (HUMAN Security, May 2026): 455 apps, 24 million installs. PDF readers and cleaners that show a fake “update,” then run invisible browsers generating 659 million fraudulent ad requests a day. Three-quarters of the traffic came from U.S. phones.
    • SlopAds (HUMAN Security, September 2025): 224 apps, 38 million installs. The list from last year.
    • Zscaler’s 2025 mobile report: 239 malicious apps, 42 million installs. Adware was 69% of what they found.
    • AfterCall (DoubleVerify, July 2026): dozens of apps a month showing a full-screen ad after every phone call.
    • Free VPNs (academic study, July 2026): of 281 free Android VPNs tested, 29 leaked your traffic and 61 sent data unencrypted.
    • Google’s own count: 1.75 million app submissions rejected and 80,000 developer accounts banned in 2025.

    The five-minute check

    1. Scan. Android: Play Store > profile > Play Protect > Scan. iPhone: delete what you don’t recognize.
    2. See who can read your screen. Android: Settings > Accessibility > Downloaded apps. If anything is switched on that isn’t a screen reader or your password manager, turn it off and uninstall the app. Then Settings > Apps > Special app access > Display over other apps. Same rule. Google started restricting these permissions in March 2026 because this is how most of the bank thieves and ad-fraud apps operate.
    3. Never install an “update” an app asks for inside itself. Trapdoor, the Anatsa droppers and the fake PDF readers all used a fake update prompt to pull the real malware after passing store review. Real updates come from the Play Store or App Store app only.
    4. Patch or retire. NoVoice only worked on phones with no security update since May 2021. Check: Android Settings > Security > Security update; iPhone Settings > General > Software Update. If there’s nothing newer,your phone has an expiration date, and it’s the target. 
    5. Be suspicious of the boring categories. Cleaners, PDF readers, file managers, wallpaper and camera apps, “call history” finders and wallet look-alikes. A food-delivery app has no business reading your whole photo library. Check the developer name, compare the review count to the install count, and read the app name twice.

    🎯 Send this to someone who still has a “cleaner” or “battery saver” app they can’t remember installing. 

    2026 Android iPhone list malicious
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    myappsplus
    • Website

    Related Posts

    Android malware creates a hidden copy of your banking app

    September 12, 2026

    iPhone 18 Pro and iPhone 18 Pro Max Now Available to Pre-Order

    September 12, 2026

    Samsung Galaxy SmartTag 3 copies the worst part of Apple’s AirTag in leak

    September 12, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    The 6 AI-free Linux distros I recommend most

    August 19, 20263 Views

    AI, automation, robot dogs ensure on-site nuclear safety

    September 7, 20262 Views

    This tiny AI box could save me from upgrading my perfectly good laptop

    September 6, 20262 Views
    Latest Reviews

    Apple Wallet driver’s licenses are coming to North Carolina, but there’s a catch

    myappsplusAugust 18, 2026

    3 Japanese AI Stocks Turning Automation Spending Into Real Revenue

    myappsplusAugust 18, 2026

    Apple: DOJ’s latest challenge in antitrust case ‘fails at every level’

    myappsplusAugust 18, 2026
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Apple Wallet driver’s licenses are coming to North Carolina, but there’s a catch

    August 18, 20260 Views

    3 Japanese AI Stocks Turning Automation Spending Into Real Revenue

    August 18, 20260 Views

    Apple: DOJ’s latest challenge in antitrust case ‘fails at every level’

    August 18, 20260 Views
    Our Picks

    Anthropic CEO calls for pacing AI frontier model development and warns ‘in 6–12 months such a swarm [of agents] could be capable of taking over the entire internet’

    September 12, 2026

    Android malware creates a hidden copy of your banking app

    September 12, 2026

    iPhone 18 Pro and iPhone 18 Pro Max Now Available to Pre-Order

    September 12, 2026

    Subscribe to Updates

    Subscribe to our newsletter and get the latest tech news, app updates, AI trends, smartphone reviews, and exclusive deals delivered straight to your inbox.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Get In Touch
    • Disclaimer
    • Privacy Policy
    • Terms & Conditions
    © 2026 MyAppsPlus. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.