PCMag editors select and review productsindependently. If you buy through affiliate links, we may earn commissions, which help support ourtesting.

New Android Malware Poses as Security Update to Take Control of Devices

The malware can record calls, take photos, and perform a variety of invasive actions.

(Image: Getty Images)

Before you approve what appears to be a new Android update, you may want to verify that you're installing the real thing.

According to mobile security firmZimperium zLabs(Opens in a new window), a new form ofmalwaredisguised as a system update is making the rounds on Android devices. Instead of actually upgrading users to a new version of the operating system, the malware commandeers the phone to take advantage of several functions. It lets bad actors record audio, phone calls, take photos, access messages within third-party messengers like WhatsApp, and even search for specific file types present on the phone.

This invasive "app" is considered a "sophisticated spyware campaign with complex capabilities," according to zLabs researchers. After installation, the device becomes registered with the Firebase Command and Control (C&C) and reports information about WhatsApp, storage information, the internet connection, and a swath of other details.

Triggering the spyware comes in different ways: installing a new app, receiving a text, or even adding a new contact. From there, call recording can begin if calls are made or received. Messages can be logged. It's a whole suite of bad news, especially when users have no idea it's all taking place.

So when accepting updates or before installing new apps on your Android device, it's important to know where the software you're using comes from. Android updates will never come in the form of a new, self-contained app. Be sure not to install anything you're sent via text message unless it's from a trusted source you're expecting to share it.

SecurityWatch<\/strong> newsletter for our top privacy and security stories delivered right to your inbox.","first_published_at":"2021-09-30T21:22:09.000000Z","published_at":"2022-03-24T14:57:33.000000Z","last_published_at":"2022-03-24T14:57:28.000000Z","created_at":null,"updated_at":"2022-03-24T14:57:33.000000Z"})" x-show="showEmailSignUp()" class="rounded bg-gray-lightest text-center md:px-32 md:py-8 p-4 mt-8 container-xs">

Like What You're Reading?

Sign up forSecurityWatchnewsletter for our top privacy and security stories delivered right to your inbox.

This newsletter may contain advertising, deals, or affiliate links. Subscribing to a newsletter indicates your consent to ourTerms of UseandPrivacy Policy. You may unsubscribe from the newsletters at any time.


那nks for signing up!

你的预订已经确认。留个心眼on your inbox!

Sign up for other newsletters

PCMag Stories You’ll Like

About Brittany Vincent

Brittany Vincent has been covering video games and tech for over a decade for publications like G4, Popular Science, Playboy, Empire, Complex, IGN, GamesRadar, Polygon, Kotaku, Maxim, and more. When she’s not writing or gaming, she’s looking for the next great visual novel in the vein of Saya no Uta.

Read Brittany's full bio

Read the latest from Brittany Vincent

Baidu
map