Previously known open-source Android spyware makes its debut on Google Play

Martin Guay
Martin Guay - Chief Editor
4 Min Read
ESET researchers have discovered the first known instances of spyware based on the open-source espionage tool called AhMyth. AhMyth, from which the internet radio app borrowed its malicious functionality, was made publicly available in late 2017.

This particular spyware was posing as an internet radio app playing very specific Balochi music; however, the spying capabilities may be easily attached to any other app.

Since then, various malicious apps based on AhMyth have appeared. However, the above-mentioned app, named Radio Balouch, is the very first of them to make it onto the official Android app store, Google Play.

Here's the official ESET release statement:

- Advertisement -
Need some Privacy online? Want to ensure what your doing stays secure? Get Surfshark VPN!Need some Privacy online? Want to ensure what your doing stays secure? Get Surfshark VPN!

BRATISLAVA, August 22, 2019 – ESET researchers have discovered the first known instances of spyware based on the open-source espionage tool called AhMyth. This particular spyware was posing as an internet radio app playing very specific Balochi music; however, the spying capabilities may be easily attached to any other app.

AhMyth, from which the internet radio app borrowed its malicious functionality, was made publicly available in late 2017. Since then, various malicious apps based on AhMyth have appeared. However, the above-mentioned app, named Radio Balouch, is the very first of them to make it onto the official Android app store, Google Play.

ESET Mobile Security for Android has protected against AhMyth and its derivatives since January 2017, even before AhMyth went public. “The malicious functionality in AhMyth is not hidden, protected, or obfuscated. For this reason, it is trivial to identify the Radio Balouch app – and other derivatives – as malicious and classify them as belonging to the AhMyth family,” comments Lukáš Štefanko, a malware researcher at ESET who conducted the investigation. 

After ESET reported the discovery to Google, its security team removed the malicious Radio Balouch app from the store. The attackers, however, were quick to make the app reappear on Google Play. “We also detected and reported the second instance of this malware, which was then swiftly removed. However, the fact that Google let the same developer post this evident malware to the store repeatedly is disturbing,” says Lukáš Štefanko. 

Radio Balouch, detected by ESET as Android/Spy.Agent.AOX, has been promoted on a dedicated website, Instagram, and YouTube. After having been removed from Google Play, it is now only available on alternative app stores. 

This app is a fully functional internet radio application for music specific to the Balochi region. In the background, however, it spies on its users: it can steal contacts and harvest files stored on the affected device. “The open-source AhMyth espionage tool has a number of variants whose functionalities vary. The Radio Balouch app – and any other AhMyth-based malware, may receive further functions in the future,” warns Štefanko. 

According to ESET researchers, the repeated appearance of the malicious Radio Balouch app on the Google Play store should serve as a wake-up call to both the Google security team and Android users. “Unless Google improves its safeguarding capabilities, a new clone of Radio Balouch or any other derivative of AhMyth may soon appear on Google Play,” comments Lukáš Štefanko. “The key security imperative to stick with official sources of apps still holds; however, that alone can’t guarantee security. We highly recommend users to scrutinize every app they intend to install on their device and use a reputable mobile security solution,” concludes ESET’s Štefanko.

- Advertisement -
Need some Privacy online? Want to ensure what your doing stays secure? Get Surfshark VPN!Need some Privacy online? Want to ensure what your doing stays secure? Get Surfshark VPN!

Can't read the articles right now? Save it for later! Subscribe to Android News & All the Bytes by entering your email — so you can read it during your downtime!

We don’t spam! Read our privacy policy for more info.

Share This Article
Avatar
By Martin Guay Chief Editor
Follow:
I write, talk about technology, gadgets, the latest Android news as much as any other fellow geek, nerd, or enthusiast does. I work in the IT field as a System Administrator, and I enjoy gaming when possible. I'm into plenty of things, and you can usually find me around Ottawa, Canada!For all business inquiry email business-inquiry [@] cryovex [dot] com.
Olive Union Launches Next-Gen Hearing Aid Earbuds Stress Tips for Business Owners Level Up with Android: The Rise of Mobile Gaming Razer’s Groundbreaking New Laptop Screens Are a Game Changer Don’t Waste Money on These 5 Overkill PC Components