A popular Android app began secretly spying on its users months after it was listed on Google Play
· 2023-05-31

A popular Android app began secretly spying on its users months after it was listed on Google Play.

A cybersecurity firm says a popular Android screen recording app that racked up tens of thousands of downloads on Google’s app store subsequently began spying on its users, including by stealing microphone recordings and other documents from the user’s phone.


Research by ESET found that the Android app, “iRecorder — Screen Recorder,” introduced the malicious code as an app update almost a year after it was first listed on Google Play. The code, according to ESET, allowed the app to stealthily upload a minute of ambient audio from the device’s microphone every 15 minutes, as well as exfiltrate documents, web pages and media files from the user’s phone.


The app is no longer listed in Google Play. If you have installed the app, you should delete it from your device. By the time the malicious app was pulled from the app store, it had racked up more than 50,000 downloads.


ESET is calling the malicious code AhRat, a customized version of an open source remote access trojan called AhMyth. Remote access trojans (or RATs) take advantage of broad access to a victim’s device and can often include remote control, but also function similarly to spyware and stalkerware.


351ca528dd3af3b4dc204eac352be0a2.png


Lukas Stefanko, a security researcher at ESET who discovered the malware, said in a blog post that the iRecorder app contained no malicious features when it first launched in September 2021.


Once the malicious AhRat code was pushed as an app update to existing users (and new users who would download the app directly from Google Play), the app began stealthily accessing the user’s microphone and uploading the user’s phone data to a server controlled by the malware’s operator. Stefanko said that the audio recording “fit within the already defined app permissions model,” given that the app was by nature designed to capture the device’s screen recordings and would ask to be granted access to the device’s microphone.


It’s not clear who planted the malicious code — whether the developer or someone else — or for what reason. TechCrunch emailed the developer’s email address that was on the app’s listing before it was pulled, but has not yet heard back.


Stefanko said the malicious code is likely part of a wider espionage campaign — where hackers work to collect information on targets of their choosing — sometimes on behalf of governments or for financially motivated reasons. He said it was “rare for a developer to upload a legitimate app, wait almost a year, and then update it with malicious code.”


It’s not uncommon for bad apps to slip into the app stores, nor is it the first time AhMyth has crept its way into Google Play. Both Google and Apple screen apps for malware before listing them for download, and sometimes act proactively to pull apps when they might put users at risk. Last year, Google said it prevented more than 1.4 million privacy-violating apps from reaching Google Play.













热门文章
超级PAC筹资4800万美元:体育博彩势力加码
游戏风向
灰度世界杯嘉年华狂欢派对吉隆坡站即将开启,业务拓展人脉社交从马来西亚开始
灰度头条
2027 Global Game Connect(GGC)斯里兰卡招商全面开启!业务人脉尽在掌握!
灰度头条
印度最高法院受理公益诉讼,要求全国禁封“伪装”成社交游戏的赌博平台
游戏风向
GGC Awards 2026 璀璨科伦坡:致敬 iGaming 行业的领航者与创新力量
灰度头条
准备好了将你的收益最大化吗?尝试ProPush.me Constructor!
广告营销
菲律宾博彩技术赛道迎来新变局,B2B 供应模式加速渗透
东南亚资讯
横跨全球6个城市,灰度8场派对邀你共看世界杯,重塑高质量社交新场景
灰度头条
PropellerAds 分享了新的 iGaming 案例研究:在 3 个月实现 97,674 次安装和 12,701 笔存款
广告营销
张侨伟参议员排除全面禁止,敦促菲律宾规范网络赌博
东南亚资讯
灰度在iGB L!VE 2026展位T70和你相约7月,一起点燃伦敦的热情!
灰度头条
巴西颁布新法赋权央行封锁非法博彩账户及 Pix 交易
支付动态
JILI 宣布与全球板球传奇 AB de Villiers(ABD)达成重磅战略合作
体育游戏
哈萨克斯坦计划对在线赌场促销活动进行处罚
游戏风向
新泽西州7月博彩收入创6.06亿美元新高,颁布禁令
游戏风向
首页
游戏
合作
发现
我的