A Trojanized version of the latest addition - Angry Birds Space - has recently recently been spotted by Sophos researchers being offered on a number of unofficial Android app stores.
Users who download it may not even realize that they have downloaded a malicious app, as the packet appears to be a fully-functional version of the game, and the name and the icon of the app correspond with the ones used by the legitimate app, which was released on March 22.
But the bundled GingerBreak exploit works in the background to gain root access to the device and to use it to download and install additional malware from a remote website.
The compromised device is then at the mercy of the crooks behind the malware, and is now effectively part of a botnet. The criminals can make it download any additional packet they want or make the browser surf to any webpage they choose.
As always, users are advised to be extra careful when downloading apps from unofficial online markets. Here's a few tips on how to spot fake Android apps.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.