Wednesday, 31 March 2021 05:23

Dangerous Android app pretends to be a system update to steal your data

Rate this item
(0 votes)

Beware a newly discovered malicious app that pretends to update your phone but, in reality, is just a giant spyware application that can steal pretty much all your data while also monitoring your movements and online search history.

Simply called System Update, the Android app was discovered by researchers with mobile security firm Zimperium, who have classified it as a Remote Access Trojan (RAT)—a broad category of malware that typically allows a hacker to access and manipulate your device from afar.

This particular RAT is downloaded with the promise of helping you keep your device up to date but, instead, sends all your information back to a Command & Control server. Shridhar Mittal, Zimperium CEO, recently told TechCrunch that he thinks the app is part of a “targeted attack.”

“It’s easily the most sophisticated [RAT] we’ve seen,” Mittal told the outlet. “I think a lot of time and effort was spent on creating this app. We believe that there are other apps out there like this, and we are trying our very best to find them as soon as possible.”

The broad range of data that this sneaky little bastard is capable of stealing is pretty horrifying. It includes: instant messenger messages and database files; call logs and phone contacts; Whatsapp messages and databases; pictures and videos; all of your text messages; and information on pretty much everything else that is on your phone (it will inventory the rest of the apps on your phone, for instance).

The app can also monitor your GPS location (so it knows exactly where you are), hijack your phone’s camera to take pictures, review your browser’s search history and bookmarks, and turn on the phone mic to record audio.

The app’s spying capabilities are triggered whenever the device receives new information. Researchers write that the RAT is constantly on the lookout for “any activity of interest, such as a phone call, to immediately record the conversation, collect the updated call log, and then upload the contents to the C&C server as an encrypted ZIP file.” After thieving your data, the app will subsequently erase evidence of its own activity, hiding what it has been doing.

Thankfully, this hellish booby trap has never been offered on Google Play store, though it is available via a third-party store, researchers write. Rogue apps like this are becoming a bigger and bigger problem for consumers, so it’s a great idea to limit the number of apps you have on your phone and to do your homework before you download—lest your data fall into the hands of some dark web cretin.

 

Gizmodo

November 21, 2024

How small businesses can leverage dark social to drive word-of-mouth marketing

Key Takeaways Dark social refers to sharing online content through private communication channels like email,…
November 21, 2024

Northern leaders say won’t support Tinubu for re-election due to president’s incompetence, bad policies

The Arewa Consultative Forum (ACF) has announced its decision to support northerners running for the…
November 18, 2024

The magic and the minefield of confidence: Self doubt, hubris and everything in between - The Economist

Confidence is contagious. Someone declaring a position with ringing certainty is more likely to inspire…
November 16, 2024

Influencer eats pig feed in extreme attempt to save money

Popular Douyin streamer Kong Yufeng recently sparked controversy in China by eating pig feed on…
November 21, 2024

50 terrorists killed as Boko Haram insurgents ambush security personnel guarding national grid in Niger…

At least 50 Boko Haram fighters were killed on Tuesday and seven members of Nigeria's…
November 21, 2024

What to know after Day 1001 of Russia-Ukraine war

WESTERN PERSPECTIVE US reopens Kyiv embassy after Ukraine firing of ATACMS missiles into Russia prompted…
November 21, 2024

Nigeria comes top in instant payment system inclusivity index in Africa

Nigeria’s instant payment system is projected to advance to the maturity inclusion spectrum ahead of…
October 27, 2024

Nigeria awarded 3-0 win over Libya after airport fiasco

Nigeria have been awarded a 3-0 victory over Libya, and three vital points, from their…

NEWSSCROLL TEAM: 'Sina Kawonise: Publisher/Editor-in-Chief; Prof Wale Are Olaitan: Editorial Consultant; Femi Kawonise: Head, Production & Administration; Afolabi Ajibola: IT Manager;
Contact Us: [email protected] Tel/WhatsApp: +234 811 395 4049

Copyright © 2015 - 2024 NewsScroll. All rights reserved.