{"id":291508,"date":"2023-05-30T15:45:32","date_gmt":"2023-05-30T13:45:32","guid":{"rendered":"https:\/\/sftarticles.wpenginepowered.com\/es\/?p=291508"},"modified":"2025-06-12T20:02:10","modified_gmt":"2025-06-12T18:02:10","slug":"curioso-caso-popular-app-android-espiar-usuarios-un-ano-despues-salida-google-play","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/es\/curioso-caso-popular-app-android-espiar-usuarios-un-ano-despues-salida-google-play\/","title":{"rendered":"El curioso caso de una popular app de Android que comenz\u00f3 a espiar a sus usuarios un a\u00f1o despu\u00e9s de su salida en Google Play"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Una creencia muy extendida entre los usuarios es que <strong><a href=\"https:\/\/www.softonic.com\/articulos\/como-registrarse-google-play-store\" target=\"_blank\" rel=\"noreferrer noopener\">Google Play<\/a><\/strong>, la tienda de apps de Google, suele mantener un m\u00ednimo de seguridad e impide que los criminales puedan subir <strong>apps maliciosas<\/strong>. Si bien la seguridad de la tienda virtual <a href=\"https:\/\/www.softonic.com\/articulos\/mozilla-fiabilidad-etiquetas-seguridad-apps-google-play-store\" target=\"_blank\" rel=\"noreferrer noopener\">se ha puesto en entredicho en alguna ocasi\u00f3n<\/a> y podemos encontrar <a href=\"https:\/\/www.softonic.com\/articulos\/cuidado-con-los-falsos-chatgpt-meta-alerta-del-aumento-de-estafas-con-esta-popular-ia\" target=\"_blank\" rel=\"noreferrer noopener\">mil apps cl\u00f3nicas de <strong>ChatGPT<\/strong><\/a>, no es muy com\u00fan encontrarse con apps que contengan malware.<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/d4d86336-96d0-11e6-963b-00163ec9f5fa\/3020431264\/google-play-store-logo\" alt=\"Google Play\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Google Play<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/google-play-store.softonic.com\/android\" target=\"_self\" rel=\"noopener noreferrer\">DESCARGAR<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/google-play-store.softonic.com\/android\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">No es muy com\u00fan\u2026, pero alguna vez que otra acaba col\u00e1ndose una. <strong><a href=\"https:\/\/techcrunch.com\/2023\/05\/29\/popular-android-app-microphone-spying-google-play\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">TechCrunch<\/a><\/strong> se ha hecho eco de una <a href=\"https:\/\/www.welivesecurity.com\/2023\/05\/23\/android-app-breaking-bad-legitimate-screen-recording-file-exfiltration\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">investigaci\u00f3n<\/a> de ESET que afirma que la app <strong>\u201ciRecorder &#8211; Screen Recorder\u201d<\/strong> se dedicaba a espiar a sus usuarios. Lo m\u00e1s llamativo de este caso es que la app gozaba de una gran popularidad y <strong>llevaba ya un a\u00f1o en Google Play<\/strong>.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/techcrunch.com\/wp-content\/uploads\/2023\/05\/irecorder-screen-recorder.jpg\" alt=\"\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Seg\u00fan <strong>Lukas Stefanko<\/strong>, investigador de seguridad de ESET, la app realmente no conten\u00eda ninguna funci\u00f3n maliciosa cuando se subi\u00f3 por primera vez a Google Play. <strong>El c\u00f3digo malicioso se insert\u00f3 en una actualizaci\u00f3n reciente<\/strong>, y permit\u00eda a la app grabar audio durante un minuto cada 15 minutos, as\u00ed como extraer documentos, p\u00e1ginas web y archivos multimedia de los dispositivos donde estuviese instalado. Todo ello <strong>sin que el usuario tuviera constancia de estas acciones<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Este tipo de malware est\u00e1 categorizado como <strong>AhRat<\/strong> por parte de ESET, y se tratar\u00eda de una versi\u00f3n personalizada de un troyano de acceso remoto llamado <strong>AhMyth<\/strong>, de c\u00f3digo abierto. Este tipo de troyanos se aprovechan por tener un <strong>acceso amplio al dispositivo de la v\u00edctima<\/strong>, gozando de multitud de permisos diferentes, y por tener la capacidad de <strong>controlar de forma remota los dispositivos infectados<\/strong>.<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/d4d86336-96d0-11e6-963b-00163ec9f5fa\/3020431264\/google-play-store-logo\" alt=\"Google Play\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Google Play<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/google-play-store.softonic.com\/android\" target=\"_self\" rel=\"noopener noreferrer\">DESCARGAR<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/google-play-store.softonic.com\/android\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">De momento, se desconoce qui\u00e9n instal\u00f3 el c\u00f3digo malicioso en la actualizaci\u00f3n de la app, que <strong>ya est\u00e1 retirada de Google Play<\/strong>. Podr\u00eda tratarse del propio desarrollador, \u201cCoffeeholic Dev\u201d, aunque tambi\u00e9n <strong>podr\u00eda haber sido un tercero<\/strong> que hubiese tenido acceso a la cuenta de desarrollador.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Algunos de los enlaces a\u00f1adidos en el art\u00edculo forman parte de campa\u00f1as de afiliaci\u00f3n y pueden representar beneficios para Softonic.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Una investigaci\u00f3n de ESET hall\u00f3 c\u00f3digo malicioso en una popular app de Android que llevaba m\u00e1s de un a\u00f1o alojada en Google Play.<\/p>\n","protected":false},"author":9256,"featured_media":291529,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[9317],"tags":[9725],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-291508","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-app-subdomain-redirectiongoogle-play-store"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/posts\/291508","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/users\/9256"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/comments?post=291508"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/posts\/291508\/revisions"}],"predecessor-version":[{"id":363986,"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/posts\/291508\/revisions\/363986"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/media\/291529"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/media?parent=291508"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/categories?post=291508"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/tags?post=291508"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/usertag?post=291508"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/vertical?post=291508"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/content-category?post=291508"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}