Malware

Two spyware apps on Google Play with 1.5M users sends data to China

0

Two apps on the Google Play Store that have more than 1.5 million downloads were found spying on users and sending data to China.

The two malicious apps on Google Play were discovered by researchers from cybersecurity firm Pradeo. Both applications are file management apps from the same developer and have been discovered sending data to multiple servers in China.

The first app named “File Recovery and Data Recovery” (com.spot.music.filedate) has over 1 million installs, and the second one named “File Manager” (com.file.box.master.gkd) has over 500,000 installs.

According to the analysis published by Pradeo, the apps were programmed to launch without users’ interaction, and to silently exfiltrate sensitive users’ data towards various malicious servers based in China. They have alerted Google of the discovery before publishing this alert.

The two apps have been designed to steal a broad range of information, including users’ contact lists, media files (Pictures, audio and video contents), real-time location, mobile country code, network provider name, network code of the SIM provider, operating system version, device brand, and model.

The researchers noticed that both app perform more than a hundred transmissions of the collected data, which is not common for modern spyware.

The two apps have a large number of users but no reviews. They have advanced permissions that allow them to hide their icons from the general view to make their uninstallation harder.

The experts recommend anyone using these applications to delete them.

Pradeo suggests that individuals should be cautious when downloading apps, especially those without ratings if they claim a large user base. It is extremely critical to read and understand app permissions before accepting them to prevent breaches like this.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Main suspect linked to notorious OPERA1ER cybercrime operation arrested

Previous article

RomCom hackers target NATO Summit guests in phishing attacks

Next article

You may also like

More in Malware

Comments

Leave a reply

Your email address will not be published. Required fields are marked *