This Android update is really nasty spyware — what you need to know

(Image credit: Shutterstock)

Android malware is getting more sophisticated and getting better at hiding its true intentions. The latest nasty spyware uncovered by security firm Zimperium masquerades as a system-update app to make you unaware that it’s actually recording your calls, tracking your location and accessing your WhatsApp messages.

While Remote Access Trojans (RATs) such as this one are nothing new, malware pretending to be an Android update is certainly unusual. 

Once downloaded to an unsuspecting Android user’s phone, the app registers the device with Google’s Firebase Command & Control and then takes the resulting token to send system commands of its own through Cloud Messaging.

“The spyware creates a notification if the device’s screen is off when it receives a command using the Firebase messaging service,” explains Zimperium in a blog post. As you can see from the screenshot below, it appears as “Searching for update…” which isn’t a legitimate Android message.

The message shown by the fake system update app

(Image credit: Zimperium)

The malware actively waits for interesting activity and then springs into action. If you make a call, it will record the conversation, collect the updated call log and then send it to the C&C server as an encrypted .zip file. 

It’s also pretty good at covering its tracks, and will delete the evidence as soon as the server returns the “success” response. 

Curiously, this spyware is especially interested in WhatsApp conversations. After gaining access to the phone’s Accessibility Services (something the user has to be convinced to do via social engineering), the malware will scrape the contents of the screen when it detects WhatsApp running. If root access is available, it’ll steal the WhatsApp database files from the app’s private storage, too. 

Another unusual element: While the malware is interested in the images and videos on your external storage, it will initially scrape the thumbnail images rather than uploading the whole file. 

This, Zimperium reckons, is another attempt to evade detection, as it would “significantly reduce the bandwidth consumption and avoid showing any sign of data exfiltration over the internet.”

The good news? The app “was not and has never been on Google Play,” according to the researchers. 

In other words, it’s limited to third-party stores and sideloading, which means the majority of Android owners don’t need to worry about this particular app. 

Still, it’s a timely reminder that although Google’s advice to stick to its own store is evidently self-interested, there’s a good reason that inexperienced users should follow the suggestion anyway.

Alan Martin

Freelance contributor Alan has been writing about tech for over a decade, covering phones, drones and everything in between. Previously Deputy Editor of tech site Alphr, his words are found all over the web and in the occasional magazine too. When not weighing up the pros and cons of the latest smartwatch, you'll probably find him tackling his ever-growing games backlog. Or, more likely, playing Spelunky for the millionth time.

Read more
Green skull on smartphone screen.
Hackers are using the Amazon Appstore to spread malware — delete this malicious app now
Green skull on smartphone screen.
This Android banking trojan steals passwords to take over your accounts — and all it takes is a single text message
A hacker typing quickly on a keyboard
Hackers are posing as Apple and Google to infect Macs with malware — don’t fall for these fake browser updates
Green skull on smartphone screen.
Only 3 of the top 150 Android apps can detect reverse engineering tool Frida — here's why that's bad
Green skull on smartphone screen.
Hackers are spreading info-stealing malware and taking over accounts using fake wedding invitations — how to stay safe
Mobile malware
New malware uses infected VPN apps to take over your device — here's how to stay safe
Latest in Malware & Adware
Green skull on smartphone screen.
Over 1 million Android devices infected with password-stealing, pre-installed botnet malware — how to stay safe
Green skull on smartphone screen.
This Android banking trojan steals passwords to take over your accounts — and all it takes is a single text message
PayPal logo on iPhone
Watch out! Scammers are using this PayPal setting to take over your PC
A laptop displaying the Chrome logo
Don't click this — malicious ads impersonating Google Chrome spreading dangerous malware
and image of the Google Chrome logo on a laptop
Google Docs under attack from info-stealing malware — how to keep your data and your emails safe
MacBook Pro 2021 (16-inch) on a patio table
Millions of Mac owners urged to be on alert for info-stealing malware
Latest in News
A render of the iPhone 17 Pro Max
iPhone 17 Pro Max — this new rumor could push people towards iPhone 17 Air
Isabela Merced as Dina and Bella Ramsey as Ellie in The Last of Us Season 2
New 'The Last of Us' season 2 trailer shows off my favorite moment from 'Part II'
apple watch 4
Apple Watch escapes U.S. import ban after court victory in patent case
samsung galaxy s25 edge mockups at galaxy unpacked 2025
iPhone 17 Air and Samsung Galaxy S25 Edge could get yet another ultra-thin rival
NYTimes Connections
NYT Connections today hints and answers — Sunday, March 9 (#637)
Prime Gaming's selection of free games for March 2025
Amazon Prime is giving away these 20 games in March — get Fallout, Saints Row 3, and more free games now