{"id":232537,"date":"2023-05-30T10:35:06","date_gmt":"2023-05-30T14:35:06","guid":{"rendered":"https:\/\/sftarticles.wpenginepowered.com\/es\/?p=291508"},"modified":"2025-07-01T19:03:59","modified_gmt":"2025-07-02T02:03:59","slug":"curious-case-popular-app-android-spy-users-one-year-after-exit-google-play","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/curious-case-popular-app-android-spy-users-one-year-after-exit-google-play\/","title":{"rendered":"The Hidden Dangers: A Deep Dive into the Android App That Secretly Spied on Users"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">A widely held belief among users is that <strong>Google Play<\/strong>, Google&#8217;s app store, typically maintains a minimum level of security and prevents criminals from uploading <strong>malicious apps<\/strong>. While the security of the virtual store <a href=\"https:\/\/en.softonic.com\/articles\/mozilla-reliability-labels-security-apps-google-play-store\" target=\"_blank\" rel=\"noreferrer noopener\">has been questioned on occasion<\/a>, and we can find <a href=\"https:\/\/en.softonic.com\/articles\/beware-with-fake-chatgpt-meta-alert-of-the-increase-of-scams-with-this-popular-ia\" target=\"_blank\" rel=\"noreferrer noopener\">countless clone apps of <strong>ChatGPT<\/strong><\/a>, it is not very common to come across apps that contain malware.<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"Google Play\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/d4d86336-96d0-11e6-963b-00163ec9f5fa\/3020431264\/google-play-store-logo\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Google Play<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/google-play-store.en.softonic.com\/android\" target=\"_self\" rel=\"noopener noreferrer\">DOWNLOAD<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/google-play-store.en.softonic.com\/android\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">It is not very common, but every now and then, one manages to slip through. <strong><a href=\"https:\/\/techcrunch.com\/2023\/05\/29\/popular-android-app-microphone-spying-google-play\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">TechCrunch<\/a><\/strong> has reported on an <a href=\"https:\/\/www.welivesecurity.com\/2023\/05\/23\/android-app-breaking-bad-legitimate-screen-recording-file-exfiltration\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">investigation<\/a> by ESET, which claims that the app <strong>&#8220;iRecorder &#8211; Screen Recorder&#8221;<\/strong> was spying on its users. What is most striking about this case is that the app enjoyed great popularity and <strong>had been on Google Play for a year already<\/strong>.<\/p>\n\n\n\n<div class=\"wp-block-image aligncenter size-large\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"742\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2023\/05\/irecorder-screen-recorder-1024x742.jpg\" alt=\"\" class=\"wp-image-232544\" srcset=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2023\/05\/irecorder-screen-recorder-1024x742.jpg 1024w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2023\/05\/irecorder-screen-recorder-300x217.jpg 300w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2023\/05\/irecorder-screen-recorder-768x557.jpg 768w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2023\/05\/irecorder-screen-recorder-18x12.jpg 18w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2023\/05\/irecorder-screen-recorder-150x109.jpg 150w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2023\/05\/irecorder-screen-recorder.jpg 1104w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">According to <strong>Lukas Stefanko<\/strong>, a security researcher at ESET, the app initially did not contain any malicious functions when it was first uploaded to Google Play. <strong>The malicious code was inserted in a recent update<\/strong>, allowing the app to record audio for one minute every 15 minutes and extract documents, web pages, and media files from the devices where it was installed. All of this was done <strong>without the user&#8217;s knowledge<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This type of malware is categorized as <strong>AhRat<\/strong> by ESET and is a customized version of an open-source remote access Trojan called <strong>AhMyth<\/strong>. Such trojans take advantage of their <strong>broad access to the victim&#8217;s device<\/strong>, having various permissions, and the ability to <strong>remotely control the infected devices<\/strong>.<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"Google Play\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/d4d86336-96d0-11e6-963b-00163ec9f5fa\/3020431264\/google-play-store-logo\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Google Play<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/google-play-store.en.softonic.com\/android\" target=\"_self\" rel=\"noopener noreferrer\">DOWNLOAD<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/google-play-store.en.softonic.com\/android\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Currently, it is unknown who installed the malicious code in the app&#8217;s update, which <strong>has already been removed from Google Play<\/strong>. It could have been the developer himself, &#8220;Coffeeholic Dev,&#8221; but it <strong>could also have been a third party<\/strong> who gained access to the developer&#8217;s account.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Some of the links added in the article are part of affiliate campaigns and may represent benefits for Softonic.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>An ESET investigation found malicious code in a popular Android app that had been hosted on Google Play for more than a year.<\/p>\n","protected":false},"author":9256,"featured_media":232541,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":1},"categories":[1015],"tags":[2421],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-232537","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-app-subdomain-redirectiongoogle-play-store"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/232537","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9256"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=232537"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/232537\/revisions"}],"predecessor-version":[{"id":319997,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/232537\/revisions\/319997"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/232541"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=232537"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=232537"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=232537"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=232537"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=232537"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=232537"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}