News

Government spyware found on Google Play Store

Researchers have discovered a new type of government malware that was visible to everyone in the official Android app store Google Play Store. Experts believe that this program was used for wiretapping users.

The malware was hiding in several applications hosted on the Google Play Store. During the months during which the program went unnoticed, hundreds of users managed to infect their devices.

As representatives of the Motherboard found out, this Android-malware was sold to the Italian authorities by a company engaged in the development of surveillance cameras. Experts say that the program could hit completely innocent people, because the authors did not figure out how to correctly target it.

Experts also tend to believe that this spyware program is illegal. Most of them once again pay attention to the fact that all protective measures of the Google Play Store at this stage can be circumvented.

The malicious program, trying to mislead users, tries to look like a completely safe application. For example, versions that were disguised as special offers from Italian telecom operators were noted.

Experts called this program Exodus. Once installed, the Exodus system checks the phone number and IMEI of the device. The malware then initiates the download of a ZIP file, which stores a program that cracks the phone and steals user data.

Exodus is interested in audio recording of everything that surrounds the device you are listening to, recording calls, browser history, calendar information, geolocation, Facebook Messenger logs, WhatsApp chats, and SMS messages.

Command and control servers of Exodus.

At the time of publication, the Italian State Police did not respond to multiple requests for comment on the technology subject to their tender, nor they had replied to questions on the use of this spyware. Questions to two Italian Public Prosecutor’s Offices went unanswered as well.

The police agent agreed that eSurv’s spyware lacked the right scope and safeguards to ensure it wouldn’t hit people who were not being under investigation.

Source: https://motherboard.vice.com

User Review
0 (0 votes)
Comments Rating 0 (0 reviews)
Daniel Zimmermann

Daniel Zimmermann has been writing on security and malware subjects for many years and has been working in the security industry for over 10 years. Daniel was educated at the Saarland University in Saarbrücken, Germany and currently lives in New York.

Recent Posts

Remove Re-captha-version-3-267.buzz pop-up ads (Virus Removal Guide)

Re-captha-version-3-267.buzz is a domain that tries to force you into subscribing to its browser notifications…

13 hours ago

Remove Lackgreyheat.live pop-up ads (Virus Removal Guide)

Lackgreyheat.live is a site that tries to force you into subscribing to its browser notifications…

13 hours ago

Remove Ceestaul pop-up ads (Virus Removal Guide)

Ceestaul.com is a domain that tries to trick you into subscribing to its browser notifications…

13 hours ago

Remove Alladvertisingdomclub.club pop-up ads (Virus Removal Guide)

Alladvertisingdomclub.club is a site that tries to force you into clik to its browser notifications…

13 hours ago

Remove Langrity.xyz pop-up ads (Virus Removal Guide)

Langrity.xyz is a domain that tries to trick you into clik to its browser notifications…

16 hours ago

Remove Segilner.xyz pop-up ads (Virus Removal Guide)

Segilner.xyz is a site that tries to force you into subscribing to its browser notifications…

16 hours ago