It could be “game over” for Minecraft fans who downloaded unauthorized mods (modifications) for their Android smartphone or tablet.
Instead of finding new content or tools to tweak the wildly popular Minecraft: Pocket Edition mobile game, more than 80 malicious apps — disguised as Minecraft mods — contained Trojans that bombarded users with advertisements or redirected them to scam websites, says ESET, a Slovakia-based cybersecurity company.
Lukas Stefanko, the malware researcher who discovered the fake mods, says there have been nearly 1 million downloads of the malicious apps from the Google Play store. “Users often fall for phony apps because they’re promising to deliver something new for a famous game like Minecraft, plus many have positive — but fabricated — ratings,” Stefanko says in an interview with USA TODAY.
Once launched, the apps displayed a screen with a download button, which didn’t install a mod but took users to a Web browser with “scareware” messages falsely notifying users of a found virus on their device and promoting them to download a new app.
Other apps displayed numerous advertisements.
ESET says it reported these two groups of apps to Google on March 16 and 21, respectively. If anyone suspects any of these apps are installed, the company offers step-by-step instructions on how to properly remove them at welivesecurity.com.
Along with running a mobile security solution, Stefanko says, ESET suggests Android users download apps only from trustworthy developers or official stores and be cautious when giving app permissions.
Microsoft did not comment on the ESET findings but said in a statement, “Customers should use caution when dealing with publishers who aren’t known or reputable. We recommend downloading games and apps from trusted sources, such as Microsoft and Mojang.”
Google had no comment.
This isn’t the first time unauthorized Minecraft-related malware has been found on Google Play. In May 2015, ESET discovered and reported 30 applications that pretended to be cheats for the popular game, installed by more than 600,000 Android users.
Minecraft was developed and published by Mojang in 2011, originally for personal computers, and agreed to a purchase by Microsoft for roughly $2.5 billion in the fall of 2014.