Android users are facing new threats to their privacy with the recent discovery of over a thousand spyware apps on the loose. A security firm found that at least three of these appsâwhich are capable of covertly taking photos, recording audio, retrieving call logs, and moreâwere available for download on Google Play.
Google has removed the apps from its store, according to mobile security firm Lookout, but the search company did not respond to multiple press inquiries regarding how spyware is imperiling its customersâ security.
Google has touted relativistic success in combating trojans and apps featuring backdoors, however, announcing in March that only 0.05 percent of Android devices downloaded malicious apps from Google Play last year.
The spyware discovery was first published by Lookout this week. The firm, which presented a method for jailbreaking the Apple Watch at this yearâs DEFCON, wrote that a threat actor based in Iraq was likely the culpritâthe account responsible at least is called âiraqwebservice.â
âBelonging to the family âSonicSpy,â these samples have been aggressively deployed since February 2017, with several making their way onto the Google Play Store,â Lookout research lead Michael Flossman writes. âGoogle removed at least one of the apps after Lookout alerted the company.â The spyware discovered on Google Play went by name âSoniacâ and presented itself as a messaging app. It was determined to be a customized version of Telegraph, meaning it provided actual messaging capabilities.
Yet the spyware-infested app also gave the author significant control over the device once downloaded, including the ability to âsilently record audio, take photos with the camera, make outbound calls, send text messages to attacker specified numbers, and retrieve information such as call logs, contacts and information about Wi-Fi access points.â
According to Lookout, the app was capable of executing up to 73 remote instructions. Users who downloaded Soniac likely forgot soon after, since after the first execution the Soniac icon disappears.
Although Google did remove Soniac, itâs unclear whether the company also removed two previous spyware apps which have been attributed to the same author: Hulk Messenger and Troy Chat, both of which contained the same SonicSpy capabilities.
âThe actors behind this family have shown that theyâre capable of getting their spyware into the official app store,â Flossman wrote, âand as itâs actively being developed, and its build process is automated, itâs likely that SonicSpy will surface again in the future.â
[Lookout]