• Home
  • News
  • About Us
  • Privacy Policy
  • Contact Us

Trending News Global

News Updates from around the world.

  • News
  • Health
  • Lifestyle
  • Technology
You are here: Home / Technology / New Android malware with full range of spying capabilities has been found

New Android malware with full range of spying capabilities has been found

March 29, 2021 by Lena Waldon

[ad_1]

New Android malware with full range of spying capabilities has been found

Getty Images

Researchers have discovered a new advanced piece of Android malware that finds sensitive information stored on infected devices and sends it to attacker-controlled servers.

The app disguises itself as a system update that must be downloaded from a third-party store, researchers from security firm Zimperium said on Friday. In fact, it’s a remote-access trojan that receives and executes commands from a command-and-control server. It provides a full-featured spying platform that performs a wide range of malicious activities.

Soup to nuts

Zimperium listed the following capabilities:

  • Stealing instant messenger messages
  • Stealing instant messenger database files (if root is available)
  • Inspecting the default browser’s bookmarks and searches
  • Inspecting the bookmark and search history from Google Chrome, Mozilla Firefox, and Samsung Internet Browser
  • Searching for files with specific extensions (including .pdf, .doc, .docx, and .xls, .xlsx)
  • Inspecting the clipboard data
  • Inspecting the content of the notifications
  • Recording audio
  • Recording phone calls
  • Periodically take pictures (either through the front or back cameras)
  • Listing of the installed applications
  • Stealing images and videos
  • Monitoring the GPS location
  • Stealing SMS messages
  • Stealing phone contacts
  • Stealing call logs
  • Exfiltrating device information (e.g., installed applications, device name, storage stats)
  • Concealing its presence by hiding the icon from the device’s drawer/menu

Messaging apps that are vulnerable to the database theft include WhatsApp, which billions of people use, often with the expectation that it provides greater confidentiality than other messengers. As noted, the databases can be accessed only if the malware has root access to the infected device. Hackers are able to root infected devices when they run older versions of Android.

Advertisement

If the malicious app doesn’t acquire root, it can still collect conversations and message details from WhatsApp by tricking users into enabling Android accessibility services. Accessibility services are controls built into the OS that make it easier for users with vision impairments or other disabilities to use devices by, for instance, modifying the display or having the device provide spoken feedback. Once accessibility services are enabled, the malicious app can scrape the content on the WhatsApp screen.

Another capability is stealing files stored in a device’s external storage. To reduce bandwidth consumption that could tip off a victim that a device is infected, the malicious app steals image thumbnails, which are much smaller than the images they correspond to. When a device is connected to Wi-Fi, the malware sends stolen data from all folders to the attackers. When only a mobile connection is available, the malware sends a more limited set of data.

As full-featured as the spying platform is, it suffers from a key limitation—namely, the inability to infect devices without first tricking users into making decisions that more experienced people know aren’t safe. First, users must download the app from a third-party source. As problematic as Google’s Play Store is, it’s generally a more trustworthy place to get apps. Users must also be social engineered into enabling accessibility services for some of the advanced features to work.

Google declined to comment except to reiterate that the malware was never available in Play.

[ad_2]

Source link

Filed Under: Technology

Recent Posts

How AI Could Reshape Wealth Distribution: Insights from Geoffrey Hinton

Geoffrey Hinton’s Perspective on AI and Wealth Inequality Geoffrey Hinton, a … [Read More...]

P15M Smuggled Cigarettes Seized in Cotabato: Economic Impacts Explored

P15M Alleged Smuggled Cigarettes Seized at Cotabato CheckpointOn September 4, … [Read More...]

Marcos Signs Law Granting 99-Year Land Lease to Foreign Investors

Marcos Signs Law Granting 99-Year Land Lease to Foreign Investors On September … [Read More...]

Ghost Projects Uncovered: DPWH Engineers in the Philippines Face Scrutiny

In recent reports, the Department of Public Works and Highways (DPWH) engineers … [Read More...]

DPWH Faces Major Shakeup Amid Fraud Scandals

DPWH Faces Major Shakeup Amid Fraud Scandals

DPWH Faces Major Shakeup Amid Fraud Scandals The Department of Public Works and … [Read More...]

  • Taylor Swift Teases Fans with YouTube Live During Munich Show
  • Japan Adds ‘Most Severe’ Category to Heatstroke Index Amid Deadly Summer
  • Dali Grocery Chain Ordered to Cease Sale of Allegedly Infringing Products
  • Ukraine’s Largest Children’s Hospital Hit by Russian Missile: Anger Mounts
  • Extreme Heat Waves in 2024 Highlight Impact of Climate Change
  • Houthi Rebels Target Commercial Ship in Gulf of Aden Amid Escalation
  • China’s New Maritime Rules in South China Sea Escalate Tensions with Philippines
  • Grieving Families Mourn as Bodies of Indian Migrant Workers Return from Kuwait Fire
  • UN Investigation Accuses Israel of Crimes Against Humanity in Gaza
  • Tim Cook Acknowledges Apple Intelligence’s Imperfect Accuracy

Follow Us!

  • Facebook
Copyright © 2026 Trending News Global | Sitemap