• 中文版
  • BM
  • News
  • Deals
  • Reviews
    • First Impressions
    • Hands-on
    • Comparisons
  • Tech
    • Mobile
    • Computers
    • Cameras
    • Wearables
    • Audio
    • Drones
  • Telco
    • Celcom
    • Digi
    • Maxis
    • Time
    • Tune Talk
    • U Mobile
    • Unifi
    • Yes
  • Cars
  • Contribute
  • Jobs
Menu
  • 中文版
  • BM
  • News
  • Deals
  • Reviews
    • First Impressions
    • Hands-on
    • Comparisons
  • Tech
    • Mobile
    • Computers
    • Cameras
    • Wearables
    • Audio
    • Drones
  • Telco
    • Celcom
    • Digi
    • Maxis
    • Time
    • Tune Talk
    • U Mobile
    • Unifi
    • Yes
  • Cars
  • Contribute
  • Jobs
Search
  • Tech
    • News
    • Mobile
    • Computers
    • Cameras
    • Wearables
    • Audio
    • Drones
  • Telco
    • Celcom
    • Digi
    • Maxis
    • Time
    • U Mobile
    • Unifi
    • Yes
  • Reviews
    • First Impressions
    • Hands-on
    • Comparisons
  • Buyer’s Guide
  • Opinions
  • Digital Life
  • Video
  • Deals
  • How-To
  • Cars
  • Bahasa Melayu
  • EV
  • Contribute
  • Advertise
Menu
  • Tech
    • News
    • Mobile
    • Computers
    • Cameras
    • Wearables
    • Audio
    • Drones
  • Telco
    • Celcom
    • Digi
    • Maxis
    • Time
    • U Mobile
    • Unifi
    • Yes
  • Reviews
    • First Impressions
    • Hands-on
    • Comparisons
  • Buyer’s Guide
  • Opinions
  • Digital Life
  • Video
  • Deals
  • How-To
  • Cars
  • Bahasa Melayu
  • EV
  • Contribute
  • Advertise
Search
Close
Home Digital Life

This QR code scanner was infected by malware after an update, over 10 million Android devices are affected

  • BY Jinn Xiung
  • 10 February 2021
  • 12:48 pm
  • Comment
Share on FacebookShare on Twitter

A popular QR code scanner on Google Play was transformed into a nasty bit of malware that has infected 10 million Android users. In a blog post, cybersecurity researchers at Malwarebytes reported that Android users who installed Lavabird Ltd’s Barcode Scanner app experienced adverts appearing unexpectedly on their Android devices. 

The malware is said to open the default web browser by itself, without user interaction. Users are then directed to a dubious website that initiates a pop-up, compelling them to install an app called ‘Rocket Cleaner – System Optimizer’ that supposedly would improve the performance of their device.

It turns out that the QR code reader and barcode generator app has been on Goggle’s official app store for years. There is a good chance that users of the app downloaded it a long time ago and forgot about it. 

Most new Android smartphone, including those by Samsung, have built-in QR code scanners with their camera app. All you need to do is launch your camera app, and it will scan a QR code.

According to Malwarebytes, a software update issued roughly on 4 December 2020, changed functions of the app to push advertising without warning. Researchers also said the malicious code was heavily concealed to avoid detection. In fact, the update was even signed with the same security certificate used in the past, clean versions of the Android app.

The report goes to say that the majority of free apps on Google Play include some form of in-app advertising. This is done by including an ad SDK to the code of the app. This is usually done at the end of an app’s development. In contrast, paid-for versions do not have this SDK.

In most cases, unwanted programs, ads and malvertising (an attack where perpetrators inject malicious code into legitimate online advertising networks) are connected with new app installations. But in this case, users reported that they did not install any new apps recently. 

Malwarebytes explains:

Ad SDKs can come from various third-party companies and provide a source of revenue for the app developer. It’s a win-win situation for everyone

Users get a free app, while the app developers and the ad SDK developers get paid. But every once in a while, an ad SDK company can change something on their end and ads can start getting a bit aggressive.

Malwarebytes has reported its findings to Google and the search giant has removed the app from Google Play. But that doesn’t mean the app will disappear from infected devices. Users will need to manually uninstall the malicious app to be rid of it.

If you really need to install a QR code scanner app, here are some suggestions:

  • Google Lens
  • Kaspersky’s QR Scanner
  • QR Droid
  • QR Reader for Android

If you want to learn more about the infected app and how avoid it, go to Malwarebytes’ blog. You can also see a video that shows the malware in action.

[SOURCE, 2]

Related reading

New malware spreads itself by auto replying to all of your WhatsApp messages
PSA: These Ad blockers are affected by malware, uninstall them now
Tags: AndroidAppGoogle PlayPlay StoreQR Code scanner
Jinn Xiung

Jinn Xiung

POPULAR

This QR code scanner was infected by malware after an update, over 10 million Android devices are affected

February 10, 2021

A Look Inside the All-New Maxis Centre at 1 Utama: What’s Different?

February 12, 2026

MacBook Neo: Apple’s “Rahmah” laptop with up to 16-hour battery life, priced from RM2,499

March 5, 2026

EV charger hogging is getting worse in Malaysia? | Let’s Talk About #137

March 9, 2026

MacBook Air 2026: Powerful M5 chip, 512GB base storage with faster SSD, WiFi 7 and priced from RM4,699

March 4, 2026

SEDC Energy x JomCharge slashes DC Charger pricing by 50%, no longer most expensive CPO in Malaysia

March 7, 2026

Copyright © 2025 · SoyaCincau.com
Mind Blow Sdn Bhd (1076827-P)

  • ADVERTISE
  • DISCLAIMER

Copyright © 2026 · SoyaCincau.com – Mind Blow Sdn Bhd (1076827-P)

  • ADVERTISE
  • DISCLAIMER