PCMag editors select and review products independently. If you buy through affiliate links, we may earn commissions, which help support our testing.

Mobile Threat Monday: It Hits the Fan

 & Jordan Minor Principal Writer, Software

Our team tests, rates, and reviews more than 1,500 products each year to help you make better buying decisions and get more from technology.

Our Expert
LOOK INSIDE PC LABS HOW WE TEST
65 EXPERTS
43 YEARS
41,500+ REVIEWS

We say it time and time again but one of the best ways to keep your Android device safe and malware-free is to only download apps from the Google Play store. Even trustworthy third-party app markets tend to be needlessly risky to install (looking at you Amazon Instant Video), and malicious apps thrive on stores with fewer regulations.

If you need more convincing consider this week's mobile threat tip, which was actually first spotted by a Malwarebytes forum member. Pou is a popular virtual pet game for iOS and Android. However, if you obtain it from Mobogenie's separate Android app store, you'll be getting some unwanted and potentially dangerous downloads along with a little brown alien to take care of. 

Pou Pou

According to Malwarebytes, if you download Pou from Mobogenie's app market, the game secretly installs a downloader add-on as well. The downloader is identified as Android/Trojan.Downloader.WalkFree.a. And don't confuse it with the Walk Free pedometer app also on the Mobogenie store, although as far as we know that app could contain the library as well since WalkFree is also bundled with other, unknown Mobogenie apps.

What makes WalkFree so threatening is that it installs apps without telling you. Apps are downloaded to a hidden folder called ".walkfree" on your device's external storage. Pou (or any other affected app) then pushes downloaded apps via the Notification bar. Unfortunately, these unwanted new APKs could very well be malware. For example, the Pou app downloaded an APK called com.polaris.BatteryIndicatorPro. In reality, this app was a Trojan identified as Trojan.Spy.Agent.el. Malware that leads to even more malware is a recurring tactic among hackers, as is exploiting fans of successful apps like Pou. 

Staying Safe

Again, the best way to stay safe if you're an Android owner is to stick to downloading apps from the Google Play store. The Malwarebytes forum member who first discovered WalkFree explained that the Trojan only appeared when they downloaded Pou from Mobogenie's store. The Google Play version was totally clean, so if you're interested in checking out the game for yourself you do have better options. We know that not everyone in the world has access to these officials channels, which helps malware like this spread, but if you do, there's really no excuse.

As always, you'll also want to get some kind of security software for your android device like Malwarebytes Anti-Malware for Android, as well as our Editors' Choice award winners Avast! Mobile Security & Antivirus and Bitdefender Mobile Security and Antivirus. Pou players should know the game only wants to give you something to love, so make sure you don't get saddled with malware, too. 

About Our Expert

Jordan Minor

Jordan Minor

Principal Writer, Software

My PCMag career began in 2013 as an intern. Now, I'm a senior writer, using the skills I acquired at Northwestern University to write about dating apps, meal kits, programming software, website builders, video streaming services, and video games. I was previously a senior editor at Geek.com and have written for The A.V. Club, Kotaku, and Paste Magazine. I'm the author of the gaming history book Video Game of the Year: A Year-by-Year Guide to the Best, Boldest, and Most Bizarre Games from Every Year Since 1977, and the reason everything you know about Street Sharks is a lie.

The Technology I Use

I use the newest Android and iOS smartphones for testing, but I currently use an iPhone 14 as my personal phone. I just hate that we gave up headphone jacks.

I've always favored gaming laptops over desktops. On that note, I have a 16-inch HP Envy with an Intel Core i9-13900H CPU and Nvidia GeForce RTX 4060 GPU. No matter what machine I’m working on, an alarming amount of my personal and professional life revolves around cloud-synced Google Drive files.

For food subscriptions, my household sticks with CookUnity and HelloFresh for meals. Video streaming is a bit more complicated. While there are too many services to list, we're subscribed to most of the major ones. These days, I find myself drawn to HBO Max's movies and shows, as well as Peacock's reality trash.

I've been a lifelong Nintendo fan, and I sincerely believe the Nintendo Switch will go down as one of the best gaming consoles of all time. It has an unbelievable library of new and old games from Nintendo and third-party companies. The handheld/console hybrid approach makes playing games so much more flexible, a legacy that continues with the Nintendo Switch 2 and Valve’s Steam Deck.

Read full bio