In some cases you don’t even need to agree to download the apps. For example, PCWorld spotted one ad on an Android phone for a battery utility called Battery Upgrade. Tapping the ad–even by accident–launches the phone’s Web browser, which automatically initiates the download of the app’s installer file on the Android device.
The ads are similar to scareware marketing tactics that have appeared on PCs: Such ads pop up on desktops or laptops, warning that your computer is infected and advising you to download a program to fix the problem. In many cases those rogue system utilities and antivirus products are merely disguises for software that spies on users.
Why use battery ads as a ploy? They tap into a common anxiety, Brandt says. Phone users aren’t yet concerned about viruses on their phones, but they are worried about their battery being sucked dry.
Privacy-Busting Battery App
Worse, the ad links to step-by-step instructions on how to lower your phone’s security settings to install the battery utility, Brandt says. “There is no question in my mind that this technique could be used for something far more sinister than a worthless battery app.”
What do the makers of Battery Doctor/Battery Upgrade have to say about their apps? We couldn’t find them. No contact information for the publishers appears within the app itself. The domain that hosts the ad and download was registered through a service that shields the owners’ contact information.
Big Brands and Popular Games Enable Sleazy Ads
PCWorld stumbled across the Battery Doctor ad on Hasbro’s free, ad-sponsored version of Scrabble. EA Mobile, which developed and maintains the Scrabble app through a licensing arrangement with Hasbro, pulled the ad after PCWorld brought it to the company’s attention.
“After becoming aware of the issue, we immediately resolved it by pulling the ad,” says Ben Webley, head of global in-game advertising and sponsorships for EA. “Our user experience remains of the utmost importance to EA, and every ad network we work with signs up to a strict publisher-standards agreement.”
But PCWorld also found other top free Android OS games delivering similar misleading battery warnings via ads. Earlier this year the hit game Angry Birds was displaying bogus battery ads that linked to malicious apps, according to Lookout Mobile Security.
Earlier this year some unsuspecting Android users heeded battery-conservation ads and downloaded an Android Trojan horse program called Battery Saver (security experts know the malware by the name GGTracker).
Kevin Mahaffey, Lookout’s cofounder, says that battery ads on the game Angry Birds pointed to an app in Google’s Android Market that, when installed, tried to charge users $10 a month by surreptitiously sending out premium text messages via the customer’s phone.
Malicious hackers like to target phones because they provide a direct payoff, Mahaffey says. “As opposed to your PC, a phone has a unique connection to a payment system (through your wireless carrier). When hackers have taken over a phone, that’s the first thing they try to exploit,” he says. With control of your phone, hackers can make premium 900-service calls or send premium text messages that put money directly in their pockets.
Android Is a Target
Security firm McAfee says that malware targets the Android OS disproportionately because it’s the largest mobile platform in the world. In a 2011 report, McAfee says that malware targeting Android phones jumped 76 percent from the previous quarter (PDF).
Fortunately, the numbers of people who have been directly affected by mobile malware are still small: about 2 percent of U.S. Android users and 5 percent worldwide, according to Lookout’s numbers.
“There is no grey area when it comes to pushing a download onto a device without a user’s consent,” he says. “It’s wrong.”
Joe Laszlo, a spokesperson for the Interactive Advertising Bureau, says mobile advertising is still relatively new, and many companies that broker ads are still trying to figure out how to screen out the bad actors. “There are no lesser standards for mobile ads,” Laszlo notes. “Ads that are deceptive and fraudulent are no good, whether it’s on a desktop Web browser or mobile device.”
5 Safe-Phone Tips
1. Be suspicious of messages that pop up on your phone and claim you need to update the device’s software. When in doubt, call your wireless carrier and ask if you really need a patch or update.
2. Download mobile security protection. Lookout Mobile Security is a good free app; AVG Antivirus offers Anti-Virus Free and Norton has Norton Mobile Security. (See related: Protect Your Android Phone with Security Apps)
3. Pay close attention to the permissions that apps request. Google’s Android Market breaks down exactly what each app wants to access on your phone. If a tic-tac-toe game wants to read your phone’s contacts, for instance, be suspicious.
4. Read app reviews carefully, and consider the app’s star rating and how many people have downloaded it. Be suspicious of third-party app stores that offer paid apps for free.
5. Watch for signs that your phone may be infected. If you see that your phone has sent text messages or email, or placed calls that you didn’t initiate, your phone is probably compromised.