Researchers at FireEye, an American security firm, have discovered a new malicious adware family that is rapidly affecting Android devices worldwide. Dubbed as “Kemoge”, the adware is suspected to have originated in China.
FireEye that Kemoge has affected users in more than 20 countries, including governments and large-scale industries, which allows for complete takeover of a user’s Android device. It disguises itself as popular apps via repackaging, so it spreads widely.
Upon initial launch, Kemoge gathers device information and uploads it to the ad server and then it pervasively serves ads from the background. This causes ad banners to pop up on mobile screen regardless of the current activity (ads even pop up when the user stays on the Android home screen).
In addition, the adware registers MyReceiver in the AndroidManifest to automatically launch when the user unlocks the device screen or the network connectivity changes. Researchers have provided a detailed report explaining how ultimately aps.kemoge.net is contacted for commands.
To dodge detection, Kemoge does not constantly communicate to the server. Instead, it only asks for commands on the first launch or after 24 hours from its last command. In each communication, it first posts the IMEI, IMSI, storage info, and installed app info to the remote server.
FireEye observed that all samples (examples of Kemoge) contain simplified Chinese characters in the code and that one sample is also published on Google Play.
The security firm suggests:
- Never click on suspicious links from emails/SMS/websites/advertisements.
- Don’t install apps outside the official app store.
- Keep Android devices updated to avoid being rooted by public known bugs. (Upgrading to the latest version of OS will provide some security, but it does not guarantee that you will remain protected.)


Senate Sets December 8 Vote on Trump’s NASA Nominee Jared Isaacman
Quantum Systems Projects Revenue Surge as It Eyes IPO or Private Sale
Banks Consider $38 Billion Funding Boost for Oracle, Vantage, and OpenAI Expansion
Sam Altman Reportedly Explored Funding for Rocket Venture in Potential Challenge to SpaceX
Apple Alerts EU Regulators That Apple Ads and Maps Meet DMA Gatekeeper Thresholds
YouTube Agrees to Follow Australia’s New Under-16 Social Media Ban
TSMC Accuses Former Executive of Leaking Trade Secrets as Taiwan Prosecutors Launch Investigation
Norway’s Wealth Fund Backs Shareholder Push for Microsoft Human-Rights Risk Report
Vietnam’s Growing Use of Chinese 5G Technology Raises Western Concerns
Wikipedia Pushes for AI Licensing Deals as Jimmy Wales Calls for Fair Compensation
Apple Leads Singles’ Day Smartphone Sales as iPhone 17 Demand Surges
OpenAI Moves to Acquire Neptune as It Expands AI Training Capabilities
Samsung Launches Galaxy Z TriFold to Elevate Its Position in the Foldable Smartphone Market
Hikvision Challenges FCC Rule Tightening Restrictions on Chinese Telecom Equipment
Baidu Cuts Jobs as AI Competition and Ad Revenue Slump Intensify
AI-Guided Drones Transform Ukraine’s Battlefield Strategy
EU Prepares Antitrust Probe Into Meta’s AI Integration on WhatsApp 



