'Coronavirus safety mask' scam will text-spam all of your friends: How to avoid it
Strange site offers face mask if you sideload Android app
Do you want a "Coronavirus safety mask"? Do you think an Android app can get one for you? If so, then you're ripe to be victimized by a bizarre multi-step scam spotted by Zscaler researchers.
The scam begins with a website, still up as of this writing, that simply states, "Download App From Below Button And Install. You Will Get A Corona Safety Mask."
- Looking to DIY? How to make a face mask at home
- Coronavirus drive-through testing locations: Where to go in your state
- Just in: Amazon warehouse closed by coronavirus: What it means for you
If you click the button, you download an Android app installation file to your computer or mobile devices, which you can sideload or install onto an Android device.
Launch the app, and you're presented with another button labeled "GET SAFETY MASK." Tap it, and you're taken to a second scam site purportedly selling masks. But right now, the mask-selling site is not selling anything, because apparently "You infected [the mask site] with High Dose of Traffic."
So you get no mask. But the app makers get all your contacts from your Android phone and then spam everyone you know with texts luring them to the first "Coronavirus Safety Mask" site, and the cycle of absurdity begins again. (You can deny the app privileges to read contacts or send SMS messages during installation.)
How to avoid the 'coronavirus safety mask' scam
Avoiding this scam is pretty simple. Don't install Android apps from anywhere other than the official Google Play store. Install and run one of the best Android antivirus apps. And don't believe random websites that tell you they can sell you with hard-to-find medical supplies.
Just getting warmed up
That's all that this scam does so far, but Zscaler's Shivang Desai thinks it could do much more.
Sign up to get the BEST of Tom's Guide direct to your inbox.
Get instant access to breaking news, the hottest reviews, great deals and helpful tips.
"There's the threat that the malware could ask the victim to pay online for the mask and steal the credit card information, but we did not find any such functionality in the app," Desai wrote in a company blog posting. "We believe the app is in its early stages and this (and other) functionalities will be added as the app is updated."
Paul Wagenseil is a senior editor at Tom's Guide focused on security and privacy. He has also been a dishwasher, fry cook, long-haul driver, code monkey and video editor. He's been rooting around in the information-security space for more than 15 years at FoxNews.com, SecurityNewsDaily, TechNewsDaily and Tom's Guide, has presented talks at the ShmooCon, DerbyCon and BSides Las Vegas hacker conferences, shown up in random TV news spots and even moderated a panel discussion at the CEDIA home-technology conference. You can follow his rants on Twitter at @snd_wagenseil.