#FleeceWare
フリースウェアアプリ発見。
1週間3836円課金するメモ帳アプリ。
#GooglePlay
#FleeceWare
September 23, 2026 at 9:23 AM
whatthetech.tv/free-apps-th...
Before you download that app with a free trial, it could be the most expensive thing on your phone if you forget to cancel. But there's a simple thing you can do. Link in the comments to see the full story. A $676 app?????
Free Apps That Can Cost You Hundreds: The “Fleeceware” Free Trial Trap
Some “free” apps use short trials and expensive subscriptions that can cost hundreds of dollars if you forget to cancel. Here’s how fleeceware apps work and how to stop them.
whatthetech.tv
March 12, 2026 at 2:20 PM
Fleeceware: Avast found 204 fleeceware apps with 1+ billion downloads and $400M+ in revenue on the App Store and Google Play Store. These apps lure users with free trials, then hit them with extreme subscription fees, some as high as $3,432/year.

12/19
June 23, 2025 at 7:34 AM
Both Apple and Google have struggled with fleeceware and phishing malware on their app stores for over a decade.

9/19
June 23, 2025 at 7:34 AM
とはいえ、「課金を止めしようとしても、受け付けず、延々と課金をむしり取る」というfleecewareなるカテゴリのマルウェア(悪意のあるソフトウェア)があるからね。アプリストア通しての課金は、やろうと思えばアプリストア側から制御できるけど(アンインストール時に課金停止するかも聞くとか)、独自ルートで課金されたらfleecewareならやりたい放題できるし。で、苦情はアプリストア側に来るので、そりゃ、警告の1つでも入れたくなるのは分かる。
May 19, 2025 at 4:37 AM
Claim: “Apple and Google continue to distribute VPN apps with undisclosed ties to Chinese companies, including the Chinese military, even…” Verdict: Missing co…
Cammack Cites Nudify Apps, Fleeceware, Chinese VPNs in Critique of Apple and Go…
Grade B · Factuality 78/100 · 35% Right-leaning
Cammack Cites Nudify Apps, Fleeceware, Chinese VPNs in Critique of Apple and Google
Grade B · Factuality 78/100 · 35% Right-leaning
cladfacts.com
August 12, 2026 at 10:25 AM
SCAM ALERT: 28 'CallPhantom' apps on Google Play tricked 7.3M users into paying for a fake call history service. The fleeceware apps have been removed, but the incident highlights the danger of fraudulent apps. 📱💸 #Android #Scam #Fleeceware
Fraudulent
ESET researchers uncovered the
cyber.netsecops.io
May 8, 2026 at 6:25 PM
How to Tell If You're Being Scammed By Fleeceware Apps

flip.it/XMD..i
How to Tell If You're Being Scammed By Fleeceware Apps
Fleeceware is one of the worst scams you can deal with on your device, because it has one, singular goal: extracting as much money from you as possibl
flip.it
January 5, 2025 at 1:54 PM
10 Dangerous Android Apps on Play Store You Must Delete Now (Joker Malware Alert!) Archyde Android users are urged to immediately remove six applications—including Safety AppLock and Emoji Wallpa...

#Technology #aplikasi #android #Play #Store

Origin | Interest | Match
10 Dangerous Android Apps on Play Store You Must Delete Now (Joker Malware Alert!)
Android users are urged to immediately remove six applications—including Safety AppLock and Emoji Wallpaper—following reports that these utilities secretly execute malicious background processes. These apps, previously hosted on the Google Play Store, engage in ad fraud and unauthorized subscription sign-ups, necessitating manual deletion to ensure complete removal from devices. ## The Anatomy of the Fleeceware Exploit The malicious activity identified in these applications aligns with a cybersecurity category known as “fleeceware.” Unlike traditional malware that aims to encrypt data for ransom or exfiltrate credentials, fleeceware exploits the trust users place in legitimate-looking utility apps to trigger unauthorized recurring billing cycles. By abusing the Android Accessibility Service or obfuscating their true function within the package manifest, these apps bypass standard user scrutiny. According to researchers at Phone Arena, the list of compromised applications includes: * Safety AppLock * Convenient Scanner 2 * Push Message – Texting & SMS * Emoji Wallpaper * Separate Doc Scanner * Fingertip GameBox These applications frequently leverage “ad fraud” modules, which silently load invisible web pages in the background to inflate advertising metrics. While this drains battery life and consumes cellular data, the more immediate financial risk is the unauthorized subscription to high-cost, low-value services. ## Technical Evasion and the Limits of Play Protect Google’s Play Protect system functions as a signature-based and heuristic scanner. However, malicious actors are increasingly using polymorphic code—software that changes its appearance or signature each time it is recompiled—to evade detection. When an app is removed from the Google Play Store, it does not trigger a remote wipe of the user’s local installation. The burden of remediation remains entirely on the end-user. “The challenge with modern mobile threats is that they reside in the gray area between legitimate software functionality and malicious intent,” says Marcus Hutchins, a noted cybersecurity researcher. “Users often grant permissions for ‘accessibility’ or ‘draw over other apps’ without realizing these are the exact API hooks required for a fleeceware app to automate UI interactions and approve its own subscriptions.” ## Hardening Your Android Environment Removing the offending applications is only the first step. To verify that no residual billing agreements exist, users must audit their Google Play subscription history. Navigate to the Google Play Store, tap your profile icon, and select “Payments & Subscriptions” to identify and cancel any unrecognized charges. Android Permissions and API's | Android Malware analysis 101 The shift toward AI-driven threat detection is intended to mitigate these risks. Google has begun integrating advanced behavioral analysis into Android’s security stack, which monitors for anomalous API calls—such as an Emoji Wallpaper app requesting permission to read SMS messages or initiate network-wide background transfers. ### Recommended Security Hygiene To maintain device integrity, prioritize the following configurations: * **Permission Auditing:** Regularly check “App Permissions” in settings. If a calculator or wallpaper app requests access to your contacts or SMS, treat it as a high-risk indicator of malicious intent. * **Play Protect Verification:** Ensure that “Scan apps with Play Protect” is toggled to the “On” position in the Play Store settings. * **Source Control:** Avoid sideloading APKs from third-party repositories. Even with Google’s scanning, the official Play Store remains the most audited environment for mobile code. ## The Ecosystem War on Obfuscated Code This incident highlights a growing tension between user privacy and the open nature of the Android ecosystem. Unlike the strictly curated environment of iOS, Android’s permission model allows for deep system-level integration. While this enables powerful customization, it also creates a larger attack surface for developers who abuse Android Manifest declarations. “We are seeing a trend where malware authors are essentially ‘gaming’ the review process by keeping the app’s manifest clean during the initial submission,” notes Dr. Sarah Miller, a senior analyst at the Cybersecurity Institute. “They then push a server-side update that enables the malicious functionality only after the app has gained a significant user base. This is a cat-and-mouse game that signature-based antivirus simply cannot win alone.” As of mid-June 2026, the primary defense against these threats remains user vigilance. If an application provides a utility that seems disconnected from its requested permissions, or if your device experiences unexplained battery drain, consider the app compromised. Delete the installation, clear the application cache, and audit your linked payment methods immediately. ### Share this: * Share on Facebook (Opens in new window) Facebook * Share on X (Opens in new window) X *
www.archyde.com
June 16, 2026 at 4:34 AM
Las apps llamadas fleeceware ofrecen “pruebas gratis” y funcionalidades útiles, pero ocultan suscripciones caras que empiezan a cobrarse automáticamente al terminar el periodo de prueba.
www.xatakandroid.com/seguridad/es...
November 11, 2025 at 11:35 PM
"#Avast uncovered three apps, Beetle #VPN, Buckler VPN, and Hat VPN Pro, as part of the #scam. [...] The three apps charge users $9.99 for a weekly subscription once a three day free trial expires." #Fleeceware #iOS
November 13, 2024 at 5:38 PM
“Security researchers from #Sophos say they've discovered a new set of '#fleeceware' apps that appear to have been downloaded and installed by more than 600 million #Android users.” #CyberSecurity
November 13, 2024 at 5:32 PM
Fleeceware’ apps overcharge users for basic app functionality
Unscrupulous publishers take advantage of Play Market policy loopholes to charge app users hundreds of dollars

wp.me/p3v0p-flH
‘Fleeceware’ apps overcharge users for basic app functionality
Unscrupulous publishers take advantage of Play Market policy loopholes to charge app users hundreds of dollars
wp.me
December 3, 2024 at 8:14 PM