5

A Google Play app started recording users without their knowledge - The Verge

 11 months ago
source link: https://www.theverge.com/2023/5/24/23736180/irecorder-android-google-play-spying-security-risk
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.

An Android app started secretly recording users almost a year after it was listed on Google Play

/

Smartphone apps can change their behavior well after you download them, turning a once innocent-seeming app into something much worse.

By Wes Davis, a weekend editor who covers the latest in tech and entertainment. He has written news, reviews, and more as a tech journalist since 2020.

May 24, 2023, 11:51 PM UTC|

Share this story

A phone with a recording app installed and running on screen
Innocent-seeming apps can be trojan horses for your information.Image: Amar Toor / The Verge

An Android recording app called iRecorder Screen Recorder began as an innocent screen recording app but turned evil nearly a year after it was first released, as detailed by Ars Technica. The app first came out in September 2021, but after an update the following August, it began recording a minute of audio every 15 minutes and forwarding those recordings, through an encrypted link, to the developer’s server. The whole thing is documented in a blog post from Essential Security against Evolving Threats (ESET) researcher Lukas Stefanko.

In the post, Stefanko said the app was updated in August 2022 to include malicious code “based on the open-source AhMyth Android RAT (remote access trojan).” The app had 50,000 downloads by the time it was reported and removed from the Play store. Stefanko added that apps with AhMyth embedded in them had made it past Google’s filters before.

Scam apps aren’t new on either Apple’s or Google’s app stores. Recorder apps can be especially bad, sometimes having predatory subscription pricing and fake reviews to inflate their visibility on those platforms. And Stefanko’s blog post highlights a particularly sticky problem: apps turning to the dark side after you’ve had them for a while, using the permissions you granted them at the outset to gather sensitive information from your device and shuttle it off to the developer for nefarious activities.

This particular app is gone, but what’s to keep another sleeper agent from activating on your phone? Google is at least working on updates that will tell you via monthly notification which, and when, apps have changed their data-sharing practices — if it finds out, that is.


About Joyk


Aggregate valuable and interesting links.
Joyk means Joy of geeK