According to their study, the researchers found at least 25 different Android apps with malicious behaviors from 22 developers. Most of them either posed as fashion apps or photo utility apps. However, these apps shared similar code and app content. Thus, the researchers believe they belonged to the same developer or group of developers.
These apps, after installation, kept their icons visible for some time to let the user interact. However, in the background, the apps used to download a remote configuration file which triggered malicious behavior, such as icon-hiding and ads-related settings. The malware would then extract the settings and apply them on the infected device.
Specifically, the apps displayed ads after hiding the icons, thus making it difficult for the victim to remove the apps.
Considering this behavior, it is highly possible that such apps will keep on emerging within the Google Play Store in future too. Therefore, users must remain vigilant enough to mitigate possible attacks. Like always, one should never download an app from an untrusted source.