Cellik Android Malware-as-a-Service Leverages Google Play Apps
Summary
Hide ▲
Show ▼
A new Android malware-as-a-service (MaaS) named Cellik is being advertised on underground forums. It offers capabilities to embed malicious code into legitimate Google Play apps, creating trojanized versions that appear trustworthy. The malware can capture screen activity, intercept notifications, exfiltrate files, and communicate via encrypted channels. It is sold for $150/month or $900 for lifetime access. Cellik's ability to integrate with Google Play apps may help it bypass Play Protect, although this claim is unconfirmed. The malware can overlay fake login screens, inject malicious code into apps, and turn trusted apps rogue. Users are advised to avoid sideloading APKs, keep Play Protect active, review app permissions, and monitor for unusual activity.
Timeline
-
17.12.2025 00:59 1 articles · 22h ago
Cellik Android Malware-as-a-Service Discovered
A new Android malware-as-a-service (MaaS) named Cellik is being advertised on underground forums. It offers capabilities to embed malicious code into legitimate Google Play apps, creating trojanized versions that appear trustworthy. The malware can capture screen activity, intercept notifications, exfiltrate files, and communicate via encrypted channels. It is sold for $150/month or $900 for lifetime access. Cellik's ability to integrate with Google Play apps may help it bypass Play Protect, although this claim is unconfirmed. The malware can overlay fake login screens, inject malicious code into apps, and turn trusted apps rogue. Users are advised to avoid sideloading APKs, keep Play Protect active, review app permissions, and monitor for unusual activity.
Show sources
- Cellik Android malware builds malicious versions from Google Play apps — www.bleepingcomputer.com — 17.12.2025 00:59
Information Snippets
-
Cellik is a new Android malware-as-a-service (MaaS) advertised on underground forums.
First reported: 17.12.2025 00:591 source, 1 articleShow sources
- Cellik Android malware builds malicious versions from Google Play apps — www.bleepingcomputer.com — 17.12.2025 00:59
-
Cellik can create trojanized versions of legitimate Google Play apps.
First reported: 17.12.2025 00:591 source, 1 articleShow sources
- Cellik Android malware builds malicious versions from Google Play apps — www.bleepingcomputer.com — 17.12.2025 00:59
-
The malware can capture screen activity, intercept notifications, exfiltrate files, and communicate via encrypted channels.
First reported: 17.12.2025 00:591 source, 1 articleShow sources
- Cellik Android malware builds malicious versions from Google Play apps — www.bleepingcomputer.com — 17.12.2025 00:59
-
Cellik is sold for $150/month or $900 for lifetime access.
First reported: 17.12.2025 00:591 source, 1 articleShow sources
- Cellik Android malware builds malicious versions from Google Play apps — www.bleepingcomputer.com — 17.12.2025 00:59
-
The malware can overlay fake login screens and inject malicious code into apps.
First reported: 17.12.2025 00:591 source, 1 articleShow sources
- Cellik Android malware builds malicious versions from Google Play apps — www.bleepingcomputer.com — 17.12.2025 00:59
-
Cellik's ability to bypass Play Protect is unconfirmed.
First reported: 17.12.2025 00:591 source, 1 articleShow sources
- Cellik Android malware builds malicious versions from Google Play apps — www.bleepingcomputer.com — 17.12.2025 00:59