6 Android apps reportedly recording users' conversations — delete, delete, delete
We've all had that eerie feeling that our phone is listening to every word we say. And for some users, it really could be.
ESET cybersecurity researchers claim to have identified six malicious Android apps that reportedly spy on users, extract WhatsApp and Signal messages, and record their conversations. One of them, an app called WaveChat, could even record background audio when users weren't using their phone's microphone, according to ESET. After users download one of the malicious apps, the researchers say the apps run a remote access trojan (RAT) code known as VajraSpy.
The good news is that these VajraSpy spyware apps were not designed to target users in the United States, and the Android apps were only downloaded around 1,400 times. ESET researchers say the apps were primarily targeted at users in India and Pakistan. They concluded that "the threat actors behind the trojanized apps probably used a honey-trap romance scam to lure their victims into installing the malware."
You May Also Like
Apple AirPods Pro 3 Noise Cancelling Heart Rate Wireless Earbuds — $219.99 (List Price $249.00)
Apple iPad 11" 128GB Wi-Fi Retina Tablet (Blue, 2025 Release) — $274.00 (List Price $349.00)
Amazon Fire HD 10 32GB Tablet (2023 Release, Black) — $69.99 (List Price $139.99)
Sony WH-1000XM5 Wireless Noise Canceling Headphones — $248.00 (List Price $399.99)
Blink Outdoor 4 1080p Security Camera (5-Pack) — $159.99 (List Price $399.99)
Fire TV Stick 4K Streaming Device With Remote (2023 Model) — $24.99 (List Price $49.99)
Shark AV2511AE AI Robot Vacuum With XL Self-Empty Base — $249.99 (List Price $599.00)
Apple Watch Series 11 (GPS, 42mm, S/M Black Sport Band) — $339.00 (List Price $399.00)
WD 6TB My Passport USB 3.0 Portable External Hard Drive — $138.65 (List Price $179.99)
Dell 14 Premium Intel Ultra 7 512GB SSD 16GB RAM 2K Laptop — $999.99 (List Price $1549.99)
The ESET research is outlined in a new post on WeLiveSecurity, an online publication and ESET partner. The researchers say they identified 12 spyware apps in total, including six Android apps available on the Google Play Store. The other six apps were available on VirusTotal, a well-known cybersecurity tool.
The malicious Android apps were called:
Privee Talk
MeetMe*
Let’s Chat
Quick Chat
Rafaqat رفاق
Chit Chat
*The researchers also noted that other apps by the same name may be available on the app store in your area. Specifically, the popular MeetMe app, which has been downloaded more than 100 million times, is not related to these spyware apps.
Remember: Just because an app is available on the Google Play or Apple App Store does not mean it is necessarily safe. Only download trusted apps from reputable companies, and be careful about what permissions you grant them. Malicious apps often mimic popular ones, as seen recently with imposter Sora apps.
In October, ESET researchers discovered two spyware apps disguised as the Android Signal app, targeting users in the United Arab Emirates.
Interestingly, one of the malicious VajraSpy apps may have preyed on fans of a popular Pakistani cricket player. One of the apps was uploaded by a user called Mohammad Rizwan, which is also the name of a popular professional cricket player (Rizwan is not associated with this scam).
ESET researchers concluded that the spyware apps were the work of Patchwork APT, a known threat in the cybersecurity world.
Topics Cybersecurity
Timothy Beck Werth is the Tech Editor at Mashable, where he leads coverage and assignments for the Tech and Shopping verticals. Tim has over 15 years of experience as a journalist and editor, and he has particular experience covering and testing consumer technology, smart home gadgets, and men’s grooming and style products. Previously, he was the Managing Editor and then Site Director of SPY.com, a men's product review and lifestyle website. As a writer for GQ, he covered everything from bull-riding competitions to the best Legos for adults, and he’s also contributed to publications such as The Daily Beast, Gear Patrol, and The Awl.
Tim studied print journalism at the University of Southern California. He currently splits his time between Brooklyn, NY and Charleston, SC. He's currently working on his second novel, a science-fiction book.