{"id":20356,"date":"2023-05-29T23:05:27","date_gmt":"2023-05-29T23:05:27","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2023\/05\/29\/a-popular-android-app-began-secretly-spying-on-its-users-months-after-it-was-listed-on-google-play\/"},"modified":"2023-05-29T23:05:27","modified_gmt":"2023-05-29T23:05:27","slug":"a-popular-android-app-began-secretly-spying-on-its-users-months-after-it-was-listed-on-google-play","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2023\/05\/29\/a-popular-android-app-began-secretly-spying-on-its-users-months-after-it-was-listed-on-google-play\/","title":{"rendered":"A popular Android app began secretly spying on its users months after it was listed on Google Play"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\">A cybersecurity firm says a popular Android screen recording app that racked up tens of thousands of downloads on Google\u2019s app store subsequently began spying on its users, including by stealing microphone recordings and other documents from the user\u2019s phone.<\/p>\n<p>Research by ESET found that the Android app, \u201ciRecorder \u2014 Screen Recorder,\u201d introduced the malicious code as an app update almost a year after it was first listed on Google Play. The code, according to ESET, allowed the app to stealthily upload a minute of ambient audio from the device\u2019s microphone every 15 minutes, as well as exfiltrate documents, web pages and media files from the user\u2019s phone.<\/p>\n<p>The app is <a href=\"https:\/\/web.archive.org\/web\/20221028133951\/play.google.com\/store\/apps\/details?id=com.tsoft.app.iscreenrecorder\" target=\"_blank\" rel=\"noopener\">no longer listed<\/a> in Google Play. If you have installed the app, you should delete it from your device. By the time the malicious app was pulled from the app store, it had racked up more than 50,000 downloads.<\/p>\n<p>ESET is calling the malicious code AhRat, a customized version of an open-source remote access trojan called AhMyth. Remote access trojans (or RATs) take advantage of broad access to a victim\u2019s device and can often include remote control, but also function similarly to <a href=\"https:\/\/techcrunch.com\/2021\/03\/26\/android-malware-system-update\/\" target=\"_blank\" rel=\"noopener\">spyware<\/a> and <a href=\"https:\/\/techcrunch.com\/2022\/02\/22\/remove-android-spyware\/\" target=\"_blank\" rel=\"noopener\">stalkerware<\/a>.<\/p>\n<div id=\"attachment_2550081\" style=\"width: 1034px\" class=\"wp-caption aligncenter\"><\/p>\n<p id=\"caption-attachment-2550081\" class=\"wp-caption-text\">A screenshot of iRecorder listed in Google Play as it was cached in the Internet Archive in 2022. <b>Image Credits:<\/b> TechCrunch (screenshot)<\/p>\n<\/div>\n<p>Lukas Stefanko, a security researcher at ESET who discovered the malware, <a href=\"https:\/\/www.welivesecurity.com\/2023\/05\/23\/android-app-breaking-bad-legitimate-screen-recording-file-exfiltration\/\" target=\"_blank\" rel=\"noopener\">said in a blog post<\/a> that the iRecorder app contained no malicious features when it first launched in September 2021.<\/p>\n<p>Once the malicious AhRat code was pushed as an app update to existing users (and new users who would download the app directly from Google Play), the app began stealthily accessing the user\u2019s microphone and uploading the user\u2019s phone data to a server controlled by the malware\u2019s operator. Stefanko said that the audio recording \u201cfit within the already defined app permissions model,\u201d given that the app was by nature designed to capture the device\u2019s screen recordings and would ask to be granted access to the device\u2019s microphone.<\/p>\n<p>It\u2019s not clear who planted the malicious code \u2014 whether the developer or by someone else \u2014 or for what reason. TechCrunch emailed the developer\u2019s email address that was on the app\u2019s listing before it was pulled, but has not yet heard back.<\/p>\n<p>Stefanko said the malicious code is likely part of a wider espionage campaign \u2014 where hackers work to collect information on targets of their choosing \u2014 sometimes on behalf of governments or for financially motivated reasons. He said it was \u201crare for a developer to upload a legitimate app, wait almost a year, and then update it with malicious code.\u201d<\/p>\n<p>It\u2019s <a href=\"https:\/\/techcrunch.com\/2022\/03\/03\/teabot-data-steal-google-play\/\" target=\"_blank\" rel=\"noopener\">not uncommon for bad apps<\/a> to slip into the app stores, nor is it the first time AhMyth has <a href=\"https:\/\/www.welivesecurity.com\/2019\/08\/22\/first-spyware-android-ahmyth-google-play\/\" target=\"_blank\" rel=\"noopener\">crept its way<\/a> into Google Play. Both Google and Apple screen apps for malware before listing them for download, and sometimes act proactively to <a href=\"https:\/\/techcrunch.com\/2023\/03\/20\/google-flags-apps-made-by-popular-chinese-e-commerce-giant-as-malware\/\" target=\"_blank\" rel=\"noopener\">pull apps<\/a> when they might put users at risk. Last year, Google <a href=\"https:\/\/security.googleblog.com\/2023\/04\/how-we-fought-bad-apps-and-bad-actors.html\" target=\"_blank\" rel=\"noopener\">said<\/a> it prevented more than 1.4 million privacy-violating apps from reaching Google Play.<\/p>\n<\/p><\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2023\/05\/29\/popular-android-app-microphone-spying-google-play\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A cybersecurity firm says a popular Android screen recording app that racked up tens of thousands of downloads on Google\u2019s app store subsequently began spying on its users, including by stealing microphone recordings and other documents from the user\u2019s phone. Research by ESET found that the Android app, \u201ciRecorder \u2014 Screen Recorder,\u201d introduced the malicious [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":20357,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-20356","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/20356","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=20356"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/20356\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/20357"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=20356"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=20356"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=20356"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}