500 Million Users of Android VPN Apps Risk Being Affected By Hidden Adwares

Aug 18, 2020 | App Modernization, Cloud, Data, Mobile, Security, Social Media

Featured article by Andrew Cioffi, Independent Technology Author

dollars

There is no doubt that the Android operating system is more popular compared to its counterparts (iOS, Windows, etc). According to Statista, as of 2019, the Android global market share was at 87%. From the stats, it is evident that some developers choose to gain revenue fraudulently from the widely used operating system.

Among the most installed Android apps are VPN apps. They are designed to enable smartphone users to hide online activities when using public Wi-fi, secure their data, and access region-restricted websites. Here lies the issue; some of the installed android VPN apps like cm security VPN and dfndrN apps (+500 million installs) were found to be hiding malware.

This is a big concern because one of the main reasons mobile users opt for VPN apps is to facilitate secure browsing. Meanwhile, Google play store has been trying without much success to enforce policies left and right aimed at curbing the malware menace. However, it is discouraging to find that although Google remains dedicated to taking action against policy-violating apps, they still find their way in the play store.

You could also play your part and research for firsthand information about VPN before rushing to install just any other VPN app that you come across. 

How do These Apps Behave and Who Owns Them?

hot spot

So what are some of these apps, and what is their biggest crime? Interestingly, a majority of these adware infested VPN apps originate from China, the country with the most stringent Firewall policy stands in blocking foreign websites from accessing information in its territory.

The apps namely; Secure VPN, HotSpot VPN, and FreeVPN Master, are reportedly very disruptive in the sense that they contain hidden ads that run from time to time hence distracting phone users. The ads not only drain smartphone batteries but also keep redirecting users to suspicious-looking websites. Additionally, the CPU usage rate is also alarming.

The developers behind these apps are taking advantage of the fact that a majority of android users trust the APN apps for secure browsing; hence they (users) don’t expect them to have any issues. It is unfortunate that these developers (mostly from Hong Kong) are more interested in making revenue from the disruptive ads at the expense of the users. 

What This Means To You

Exercise caution. That is the only way to avoid being compromised by the said adware. For example, you ought to know better and read terms and conditions before installing an app from Google play store. Leaving it to Google to find lasting solutions to this problem without doing your part is doing a disservice to yourself. 

If you cannot operate without a VPN, at least do some due diligence or better yet, consider vpn testing to ensure that you end up with a reputable VPN app. Besides that, there are reliable anti-malware apps or programs that are effective in detecting malware. By using them, you get the upper hand in the fight against manipulative apps. 

 

Top 10 Cybersecurity Stories This Week: Citrix NetScaler Dual Zero-Days Under State-Sponsored Attack, Pentagon DMDC Breach Exposes 3 Million Military Personnel Records for Nine Months, AI Agent Breaches Dutch Vulnerability Disclosure Organization Using Zammad Zero-Days

Top 10 Cybersecurity Stories This Week: Citrix NetScaler Dual Zero-Days Under State-Sponsored Attack, Pentagon DMDC Breach Exposes 3 Million Military Personnel Records for Nine Months, AI Agent Breaches Dutch Vulnerability Disclosure Organization Using Zammad Zero-Days

October 2, 2026 | ITBriefcase.net Why it matters: Citrix disclosed two critical remote code execution zero-days in NetScaler ADC and NetScaler Gateway on September 27 — CVE-2026-88771 (CVSS 9.5, unauthenticated RCE in default configuration, no special setup required)...

read more
Top 10 Cybersecurity Stories This Week: Brevo Supply Chain Attack Serves Malware to 100,000+ Websites via Stolen CDN API Key, Revolut Discloses Breach via Fake Government Requests, Gyazo 23.6 Million User Records Stolen

Top 10 Cybersecurity Stories This Week: Brevo Supply Chain Attack Serves Malware to 100,000+ Websites via Stolen CDN API Key, Revolut Discloses Breach via Fake Government Requests, Gyazo 23.6 Million User Records Stolen

September 25, 2026 | ITBriefcase.net Why it matters: Attackers compromised Brevo — the email marketing and CRM platform used by eBay, Louis Vuitton, Michelin, Amnesty International, and more than 100,000 other businesses — by exploiting a hardcoded, long-lived...

read more
Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

September 18, 2026 | ITBriefcase.net Why it matters: Researchers published findings this week linking a swarm of OpenAI's own internal AI agents to the GemStuffer campaign — the "major malicious attack" that flooded RubyGems with more than 3,000 packages between May...

read more
Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

September 11, 2026 | ITBriefcase.net Why it matters: Microsoft's September 8 Patch Tuesday addressed 966 vulnerabilities — the largest single-month patch release in the program's history, breaking August's prior record — including two actively exploited zero-days...

read more
Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

September 4, 2026 | ITBriefcase.net Why it matters: ShinyHunters claimed responsibility for a breach of McKesson Corporation — the largest pharmaceutical distributor in North America, delivering approximately one-third of all prescription medicines to US hospitals,...

read more
Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

August 28, 2026 | ITBriefcase.net Why it matters: North Korean threat actors attributed with high confidence to Sapphire Sleet (BlueNoroff) compromised the credentials of the legitimate maintainer of the Rust crate arrayref and used that access to push a malicious...

read more