Eblogtip.com
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions

Archives

  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • December 2022

Categories

  • News
  • Technology
  • Uncategorized
eBlogTip
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions
  • Technology

A popular Android app began secretly spying on its users months after it was approved on Google Play

  • May 29, 2023
Total
0
Shares
0
0
0

A cybersecurity firm says a popular Android screen recording app that racked up tens of thousands of downloads on Google’s app store subsequently began spying on its users, including by stealing microphone recordings and other documents from the user’s phone.

Research by ESET found that the Android app, “iRecorder — Screen Recorder,” introduced the malicious code as an app update almost a year after it was first listed on Google Play. The code, according to ESET, allowed the app to stealthily upload a minute of ambient audio from the device’s microphone every 15 minutes, as well as exfiltrate documents, web pages and media files from the user’s phone.

The app is no longer listed in Google Play. If you have installed the app, you should delete it from your device. By the time the malicious app was pulled from the app store, it had racked up more than 50,000 downloads.

ESET is calling the malicious code AhRat, a customized version of an open-source remote access trojan called AhMyth. Remote access trojans (or RATs) take advantage of broad access to a victim’s device and can often include remote control, but also function similarly to spyware and stalkerware.

A screenshot of iRecorder, the affected app, in Google Play as it was cached in the Internet Archive in 2022.

A screenshot of iRecorder listed in Google Play as it was cached in the Internet Archive in 2022. Image Credits: TechCrunch (screenshot)

Lukas Stefanko, a security researcher at ESET who discovered the malware, said in a blog post that the iRecorder app contained no malicious features when it first launched in September 2021.

Once the malicious AhRat code was pushed as an app update to existing users (and new users who would download the app directly from Google Play), the app began stealthily accessing the user’s microphone and uploading the user’s phone data to a server controlled by the malware’s operator. Stefanko said that the audio recording “fit within the already defined app permissions model,” given that the app was by nature designed to capture the device’s screen recordings and would ask to be granted access to the device’s microphone.

It’s not clear who planted the malicious code — whether the developer or by someone else — or for what reason. TechCrunch emailed the developer’s email address that was on the app’s listing before it was pulled, but has not yet heard back.

Stefanko said the malicious code is likely part of a wider espionage campaign — where hackers work to collect information on targets of their choosing — sometimes on behalf of governments or for financially motivated reasons. He said it was “rare for a developer to upload a legitimate app, wait almost a year, and then update it with malicious code.”

It’s not uncommon for bad apps to slip into the app stores, nor is it the first time AhMyth has crept its way into Google Play. Both Google and Apple screen apps for malware before listing them for download, and sometimes act proactively to pull apps when they might put users at risk. Last year, Google said it prevented more than 1.4 million privacy-violating apps from reaching Google Play.


Source link

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Previous Article
  • Technology

Max Q: Galactic | TechCrunch

  • May 29, 2023
View Post
Next Article
  • News

MSI partners with Mercedes-AMG Motorsport for a ‘luxury’ laptop experience

  • May 30, 2023
View Post
You May Also Like
View Post
  • Technology

Yes, you have to update your Apple devices again, because spyware is bad

  • September 22, 2023
View Post
  • Technology

Akowe wants to fix Africa’s broken certificate system with blockchain

  • September 22, 2023
View Post
  • Technology

PixePixel Pals delivers a cute and clever update that takes advantage of new iOS features

  • September 22, 2023
View Post
  • Technology

Google’s Parisa Tabriz on how the company stays ahead of hackers

  • September 22, 2023
View Post
  • Technology

Power amplifier startup Falcomm to close $4M, taking on Qualcomm and Broadcom

  • September 22, 2023
View Post
  • Technology

Microsoft’s mobile keyboard app SwiftKey gains new AI-powered features

  • September 22, 2023
View Post
  • Technology

Microsoft Bing to gain more personalized answers, support for DALLE-E 3, and watermarked AI images

  • September 22, 2023
View Post
  • Technology

Chris Lehane: The SEC isn’t handling crypto regulation ‘strategically’

  • September 22, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

eBlogTip.com
  • Categories

Input your search keywords and press Enter.