• About WordPress
    • WordPress.org
    • Documentation
    • Learn WordPress
    • Support
    • Feedback
Skip to content
May 26, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Malware
  • Google Play installer for Windows 11 Subsystem for Android secretly installed malware
  • Malware

Google Play installer for Windows 11 Subsystem for Android secretly installed malware

Ddos April 16, 2022 2 minutes read

After the launch of the Windows 11 Subsystem for Android, many users hope to install the Google Play Store, so that it is more convenient to download and install applications directly from the Play Store. But after all, the Google Play Store is a proprietary application, so it is impossible for Microsoft to pre-install it directly. On the contrary, Microsoft and Amazon reached an agreement to pre-install Amazon’s application store. In fact, it is only slightly troublesome to deploy the Google Play Store in the Windows 11 Subsystem for Android, so some hackers use this theme to spread the malware.

Windows Toolbox is hosted on Github and looks like open source software, and its developers claim that it only needs to be prompted to execute PowerShell commands to install Google Play in Windows Subsystem for Android. Features offered include uninstalling Microsoft’s pre-installed apps, improving Android subsystem performance, turning security updates on or off, and installing the Google Play Store. The tool even has a built-in activation module to provide system activation functions, apparently, so many functions are designed to lure users to execute malicious command lines.

When the user executes the command line according to the prompt, the tool will download a large number of files, copy the browser configuration file, and install malicious extensions on the browser. These malicious extensions are mainly used to hijack users’ access. For example, when users visit whatsapp.com, the script will redirect them to one of the following random URLs, which contain “make money” scams, browser notifications scams, and promotions of unwanted software.

After being found to be abnormal, some users submitted complaints to Github. At present, the hosting homepage of the software has been deleted, but some codes can still be seen. There is currently no security software that can solve it, and the user needs to check the system scheduled tasks, startup tasks, and system folders by themselves. If there is a C:\systemfile folder on the user’s system disk, it is very likely to be attacked. You can consider deleting this folder completely in safe mode, also delete the following folders: C:\Windows\security\pywinvera, C:\Windows\security\pywinveraa, and C:\Windows\security\winver.png and restart.

Via: bleepingcomputer

Rate this post

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram

Related posts:

  1. Facebook emphasized the surge in malware masquerading as ChatGPT
  2. AsukaStealer Malware Targets Browsers and Crypto Wallets for $80 a Month
  3. Malicious VS Code Extensions Deliver Spyware, Steal Crypto Credentials
  4. Dodi Repacks Malware: Why Your Adblocker Won’t Save You
  5. YouTube Ghost Network: The New GachiLoader Malware Hiding in Your Favorite Video Links
Tags: Google Play installer malware

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚑

Get notified instantly when a Proof of Concept (PoC) exploit is published.

πŸ”

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

πŸ“Š

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

πŸ”΄ Live Critical Threats

  • CVE-2026-3660CVSS 9.8
    IBM Engineering Lifecycle Management 7.0.3 ( through ) Interim Fix 021, 7.1.0...
  • CVE-2026-8633CVSS 9.8
    IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5,...
  • CVE-2026-46624CVSS 9.9
    Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical...
  • CVE-2026-44668CVSS 9.8
    FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3,...
  • CVE-2026-45721CVSS 9.0
    Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when...
  • CVE-2026-7251CVSS 9.8
    Eppendorf BioFlo 320Β is vulnerable to due to VNC server using a hard-coded...
  • CVE-2026-7374CVSS 9.9
    A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an...
  • CVE-2026-45247CVSS 9.8
    Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains...
  • CVE-2026-9543CVSS 9.8
    A vulnerability has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the...
  • CVE-2026-42774CVSS 9.3
    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
  • Exploited in the Wild: Maximum CVSS 10 SD-WAN Flaw (CVE-2026-20182) Grants Admin Control
  • Exploited in the Wild: Critical 9.8 CVSS RCE Hits Canon GUARDIANWALL MailSuite
  • Exploit Code Released: Public PoC Dumps for Windows BitLocker Bypass and SYSTEM Elevation Zero-Days
  • Exploited in the Wild: “Dirty Frag” Linux Vulnerability Grants Instant Root Access
  • Under Active Attack: Ivanti EPMM Zero-Day Exploited in the Wild via Harvested Admin Credentials
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    Copyright Daily CyberSecurity Β© All rights reserved.