{"id":12473,"date":"2018-06-04T08:10:05","date_gmt":"2018-06-04T16:10:05","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2018\/06\/04\/news-6242\/"},"modified":"2018-06-04T08:10:05","modified_gmt":"2018-06-04T16:10:05","slug":"news-6242","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2018\/06\/04\/news-6242\/","title":{"rendered":"Mobile Menace Monday: A race to hidden ads"},"content":{"rendered":"<p><strong>Credit to Author: Nathan Collier| Date: Mon, 04 Jun 2018 15:00:00 +0000<\/strong><\/p>\n<p>Who doesn\u2019t love a good motorcycle racing game, right? How about one easily available on Google Play, a \u201csafe\u201d place for all your Android app desires? How about a bike racing game that sticks with you so much, you can\u2019t easily uninstall it? And it displays hidden ads?<\/p>\n<p>Wait, what!? That\u2019s right! In the slideshow below, a game titled <em>Motorcycle Race\u2014Bike Race <\/em>(package name: com.bikeme.racersm) has <em>rave<\/em>\u00a0reviews by users who demand to know how to uninstall the game.<\/p>\n<p> <a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/06\/mobile-menace-monday-bike-race-hidden-ads-now-play\/#gallery-24028-1-slideshow\">Click to view slideshow.<\/a> <\/p>\n<h3>Rev your engines for heightened privileges<\/h3>\n<p>So how does one get into such a predicament? That all starts with the install process. Upon installing <em>Motorcycle Race\u2014Bike Race, <\/em>the first screen asks to <em>Activate device administrator.<\/em><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"24032\" data-permalink=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/06\/mobile-menace-monday-bike-race-hidden-ads-now-play\/attachment\/install1-4\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Install1.png\" data-orig-size=\"720,1280\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Install1\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Install1-169x300.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Install1-338x600.png\" class=\"aligncenter size-medium wp-image-24032\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Install1-169x300.png\" alt=\"\" width=\"169\" height=\"300\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Install1-169x300.png 169w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Install1-338x600.png 338w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Install1.png 720w\" sizes=\"auto, (max-width: 169px) 100vw, 169px\" \/><\/p>\n<p>Okay, so obviously a bike racing game requesting device administrator rights with permission to <em>Lock the screen<\/em> is a big red flag. However, if you didn\u2019t catch that, there\u2019s another clue that something is amiss. Look at the app name asking for permission: <em>Media Player. <\/em>That\u2019s going to make finding the app in the device\u2019s app list rather difficult (hint, hint).<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"24033\" data-permalink=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/06\/mobile-menace-monday-bike-race-hidden-ads-now-play\/attachment\/install2-4\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Install2.png\" data-orig-size=\"718,158\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Install2\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Install2-300x66.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Install2-600x132.png\" class=\"aligncenter size-medium wp-image-24033\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Install2-300x66.png\" alt=\"\" width=\"300\" height=\"66\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Install2-300x66.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Install2-600x132.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Install2.png 718w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/p>\n<p>After the initial weirdness of asking for heightened privileges, the app does open and run as advertised.<\/p>\n<p> <a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/06\/mobile-menace-monday-bike-race-hidden-ads-now-play\/#gallery-24028-2-slideshow\">Click to view slideshow.<\/a> <\/p>\n<p>Don\u2019t expect the game to perform well, though. It runs so slow and choppy, it makes for an unpleasant experience. This is because it\u2019s doing something much more malicious in the background.<\/p>\n<h3>Over the handlebars into full screen ads<\/h3>\n<p>After the first time the device\u2019s screen is locked\/unlocked, it becomes clear why <em>Lock the screen<\/em> permission is requested. Behold: annoying lock screen ads that take up the whole screen!<\/p>\n<p> <a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/06\/mobile-menace-monday-bike-race-hidden-ads-now-play\/#gallery-24028-3-slideshow\">Click to view slideshow.<\/a> <\/p>\n<h3>Time to chuck this bike: how to uninstall<\/h3>\n<p>At this point, any user would be ready to ditch this two-wheeled game. However, if the game was given device administrator rights, this isn\u2019t as straightforward as simply dragging the icon to <em>uninstall.<\/em>\u00a0The easiest method would be to let <a href=\"https:\/\/play.google.com\/store\/apps\/details?id=org.malwarebytes.antimalware\" target=\"_blank\" rel=\"noopener\">Malwarebytes for Android<\/a>, which detects this as <a href=\"https:\/\/blog.malwarebytes.com\/detections\/android-trojan-hiddenads-bira\/\" target=\"_blank\" rel=\"noopener\">Android\/Trojan.HiddenAds.BiRa<\/a>, remove the app.<\/p>\n<p>However, you can also uninstall the app manually. Let\u2019s start with dragging the icon to <em>uninstall.\u00a0<\/em>That&#8217;ll bring up this warning pop-up:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"24039\" data-permalink=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/06\/mobile-menace-monday-bike-race-hidden-ads-now-play\/attachment\/uninstall1\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Uninstall1.png\" data-orig-size=\"720,1280\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Uninstall1\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Uninstall1-169x300.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Uninstall1-338x600.png\" class=\"aligncenter size-medium wp-image-24039\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Uninstall1-169x300.png\" alt=\"\" width=\"169\" height=\"300\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Uninstall1-169x300.png 169w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Uninstall1-338x600.png 338w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Uninstall1.png 720w\" sizes=\"auto, (max-width: 169px) 100vw, 169px\" \/><\/p>\n<p>Make sure to note the &#8220;<em>Bike Racer is part of the following app: Media Player&#8221;<\/em>\u00a0text, as you\u2019ll need this information later. Click <em>OK<\/em> to land here.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"24040\" data-permalink=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/06\/mobile-menace-monday-bike-race-hidden-ads-now-play\/attachment\/uninstall2\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Uninstall2.png\" data-orig-size=\"720,1280\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Uninstall2\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Uninstall2-169x300.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Uninstall2-338x600.png\" class=\"aligncenter size-medium wp-image-24040\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Uninstall2-169x300.png\" alt=\"\" width=\"169\" height=\"300\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Uninstall2-169x300.png 169w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Uninstall2-338x600.png 338w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Uninstall2.png 720w\" sizes=\"auto, (max-width: 169px) 100vw, 169px\" \/><\/p>\n<p>Next, select\u00a0<em>Manage device administrators.<\/em><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"24041\" data-permalink=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/06\/mobile-menace-monday-bike-race-hidden-ads-now-play\/attachment\/uninstall3\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Uninstall3.png\" data-orig-size=\"720,1280\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Uninstall3\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Uninstall3-169x300.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Uninstall3-338x600.png\" class=\"aligncenter size-medium wp-image-24041\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Uninstall3-169x300.png\" alt=\"\" width=\"169\" height=\"300\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Uninstall3-169x300.png 169w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Uninstall3-338x600.png 338w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Uninstall3.png 720w\" sizes=\"auto, (max-width: 169px) 100vw, 169px\" \/><\/p>\n<p>Click the <em>check mark\u00a0<\/em>to uncheck <em>Media Player <\/em>(which is the true name of the bike racing app). Depending on the Android OS version, this could also be an on\/off toggle switch.<\/p>\n<p>Here&#8217;s an extra reminder, as this is the tricky part: Anytime you need to uninstall an app manually, you\u2019re looking for the app name listed after the colon from first warning pop-up:\u00a0<em>part of the following app:&lt;app name&gt;.\u00a0<\/em>It\u2019s easy to assume that it\u2019s listed under the app icon name (in this case <em>Bike Racer).\u00a0<\/em>This method is a clever way to obfuscate removal.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"24042\" data-permalink=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/06\/mobile-menace-monday-bike-race-hidden-ads-now-play\/attachment\/uninstall4\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Uninstall4.png\" data-orig-size=\"720,1280\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Uninstall4\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Uninstall4-169x300.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Uninstall4-338x600.png\" class=\"aligncenter size-medium wp-image-24042\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Uninstall4-169x300.png\" alt=\"\" width=\"169\" height=\"300\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Uninstall4-169x300.png 169w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Uninstall4-338x600.png 338w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Uninstall4.png 720w\" sizes=\"auto, (max-width: 169px) 100vw, 169px\" \/><\/p>\n<p>Back to uninstalling the app. After you select the check mark, you&#8217;ll get to this screen. Click &#8220;<em>Deactivate&#8221;\u00a0<\/em>at the bottom of the screen.<\/p>\n<p>After device administrator rights are revoked, once again drag the icon to <em>uninstall. <\/em>This time, you&#8217;ll be able to\u00a0successfully remove the app.<\/p>\n<h3>You have the right to not give rights<\/h3>\n<p>Even when installing apps from reputable sources like Google Play, be careful when you grant device administrator rights. Although there are times when it\u2019s appropriate to grant such rights to an app, make sure the rights line up with the functionality of the app. Giving device administrator rights to a respectable security app in order to remediate ransomware makes sense. A bike racing game needn&#8217;t be given the same rights. Why would they need to lock your screen?<\/p>\n<p>With a little scrutiny and a lot of paying attention to the fine print, you can protect yourself from malicious apps that slip by Google Play&#8217;s security parameters. Stay safe out there!<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/06\/mobile-menace-monday-bike-race-hidden-ads-now-play\/\">Mobile Menace Monday: A race to hidden ads<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/06\/mobile-menace-monday-bike-race-hidden-ads-now-play\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Nathan Collier| Date: Mon, 04 Jun 2018 15:00:00 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/06\/mobile-menace-monday-bike-race-hidden-ads-now-play\/' title='Mobile Menace Monday: A race to hidden ads'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/06\/Featured_A-bike-race-to-hidden-ads-\u2014-now-on-PLAY.jpg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>A bike racing game on Google Play locks users&#8217; screens, displays full-screen ads, and is notoriously difficult to uninstall. It&#8217;s no wonder Android game reviewers demand to know how to get rid of it. We show you how. <\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/\" rel=\"category tag\">Cybercrime<\/a><\/li>\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/mobile\/\" rel=\"category tag\">Mobile<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/android\/\" rel=\"tag\">Android<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/device-administrator\/\" rel=\"tag\">Device Administrator<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/hidden-ads\/\" rel=\"tag\">Hidden Ads<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/mobile-menace-monday\/\" rel=\"tag\">mobile menace monday<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/triple-m\/\" rel=\"tag\">triple m<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/uninstall\/\" rel=\"tag\">uninstall<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/06\/mobile-menace-monday-bike-race-hidden-ads-now-play\/' title='Mobile Menace Monday: A race to hidden ads'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/06\/mobile-menace-monday-bike-race-hidden-ads-now-play\/\">Mobile Menace Monday: A race to hidden ads<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[10462,4503,18626,18627,10554,10555,10556,12217],"class_list":["post-12473","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-android","tag-cybercrime","tag-device-administrator","tag-hidden-ads","tag-mobile","tag-mobile-menace-monday","tag-triple-m","tag-uninstall"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/12473","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=12473"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/12473\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=12473"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=12473"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=12473"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}