Google warns of legit VPN apps being used to infect devices with malware

malware
Image Credit: Flickr (Image credit: Shutterstock)

Attackers are reportedly using popular VPN applications as a backdoor to inject malware and gain remote control of infected devices.

This is the worrying finding coming from Google's Managed Defense team, which shed light on how malicious actors employ SEO poisoning tactics to spread what's known as Playfulghost malware.

"The malware is bundled with popular applications, like LetsVPN, and distributed through SEO poisoning," wrote the expert. "This involves manipulating search engine results to make the bundled software appear at the top of searches, making it seem like a legitimate download."

Phishing attacks, meaning malicious emails that trick users into clicking on dangerous links to download malware, are another known distribution method.

The dangers of the Playfulghost backdoor

As Google's expert explains in a blog post, Playfulghost is "a backdoor that shares functionality with Gh0st RAT." The latter is a remote administration tool that has been known among the security community since 2008.

Playfulghost, however, has distinct traffic patterns and encryption that differentiate it from the known threat.

Attackers use both phishing and SEO poisoning tactics to trick victims into downloading the malicious software on their devices. In one case, the Google expert explains, the victim was tricked into opening an infected image file to execute Playfulghost from a remote server.

Similarly, SEO poisoning tactics involved using trojanized virtual private network (VPN) apps to download Playfulghost components from a remote server into the victims' devices (see the GIF below).

Playfulghost is a particularly dangerous strain of malware that enables attackers to remotely execute a range of activities once the device is infected. Data mining capabilities include keylogging, screenshot capture, and audio capture. Attackers can also carry on file management activities like opening, deleting, and writing new files, among other things.

You can read all of Playfulghost's technical details in Google's blog post here.

Gif showing how an installer dropped a malicious executable which downloads PLAYFULGHOST

(Image credit: Google)

The Playfulghost malware case is yet another reminder to remain on alert when downloading new software.

Sticking to reputable names, like the best VPN applications, on a search engine isn't enough to stay safe. The same goes for App Stores, unfortunately, as copycat malicious applications may slip through the security checks.

I recommend going through reputable sources, like TechRadar, whenever possible and using the on-page links to download new software – whether this is a new VPN, antivirus, or password manager tool. Heading directly to the provider's official website is another way to ensure your download is a legitimate and secure application.

If you notice your device acting oddly, I suggest looking for applications you don't recognize and running a malware removal service if possible. You should also consider a system reboot to eradicate the potential threat.

TOPICS
Chiara Castro
News Editor (Tech Software)

Chiara is a multimedia journalist committed to covering stories to help promote the rights and denounce the abuses of the digital side of life – wherever cybersecurity, markets, and politics tangle up. She writes news, interviews, and analysis on data privacy, online censorship, digital rights, cybercrime, and security software, with a special focus on VPNs, for TechRadar and TechRadar Pro. Got a story, tip-off, or something tech-interesting to say? Reach out to chiara.castro@futurenet.com

Read more
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
China-linked cyberespionage group PlushDaemon used South Korean VPN service to inject malware
 laptop with warning symbol on desk
Experts predict malware may impact 39% of free Android VPNs by 2025 – but that's not the only worry
NordVPN
US hit with over 1.9 billion malware threats last year - here's how to stay safe
A VPN runs on a mobile phone placed on a laptop keyboard
Major new online tunneling vulnerability could put millions of devices at risk
A padlock resting on a keyboard.
Understanding and avoiding malvertizing attacks
Pirate skull cyber attack digital technology flag cyber on on computer CPU in background. Darknet and cybercrime banner cyberattack and espionage concept illustration.
Mac users targeted with new malware, so be on your guard
Latest in VPN
Homepage of CloudFlare website on the display of PC, url - CloudFlare.com.
"Network blocking is never going to be the solution" – Cloudflare slams anti-piracy tactics
Man and woman watching TV
How can a VPN help with streaming? A complete guide to securing your favorite shows
 Amazon Fire TV Stick VPN
How do obfuscated VPN servers help with streaming? Here's everything you need to know
Panels at RightsCon 2025 during a press briefing about the latest Access Now report of internet shutdowns
2024 was the worst year on record for internet freedoms – again
ExpressVPN apps running on a laptop and mobile during TechRadar's testing
What's new in Lightway 2.0? Here are the 4 biggest changes I'm excited for
A VPN running on a mobile device
A new era for VPN testing? ATMSO publishes the first-ever testing standards in an "important milestone"
Latest in News
A hand holding a phone showing the Android Find My Device network
Android's Find My Device can now let you track your friends – and I can't decide if that's cool or creepy
Insta360 X4 360 degree camera without lens protector
Leaked DJI Osmo 360 image suggests GoPro and Insta360 should be worried – here's why
A YouTube Premium promo on a laptop screen
A cheaper YouTube Premium Lite plan just rolled out in the US – but you’ll miss out on these 4 features
Viaim RecDot AI true wireless earbuds
These AI-powered earbuds can also act as a dictaphone with transcription when left in their case
The socket interface of the Intel Core Ultra processor
Intel unveils its most powerful AI PCs yet - new Intel Core Ultra Series 2 processors pack in vPro for lightweight laptops and high-performance workstations alike
An Nvidia GeForce RTX 5070
Nvidia confirms that an RTX 5070 Founders Edition is coming... just not on launch day