Innocent-seeming apps can be trojan horses for your information. | Image: Amar Toor / The Verge An Android recording app called iRecorder Screen Recorder began as an innocent screen recording
A phone with a recording app installed and running on screen
Innocent-seeming apps can be trojan horses for your information. | Image: Amar Toor / The Verge

An Android recording app called iRecorder Screen Recorder began as an innocent screen recording app but turned evil nearly a year after it was first released, as detailed by Ars Technica. The app first came out in September 2021, but after an update the following August, it began recording a minute of audio every 15 minutes and forwarding those recordings, through an encrypted link, to the developer’s server. The whole thing is documented in a blog post from Essential Security against Evolving Threats (ESET) researcher Lukas Stefanko.

In the post, Stefanko said the app was updated in August 2022 to include malicious code “based on the open-source AhMyth Android RAT (remote access trojan).” The app had 50,000 downloads by the time it was reported and removed from the Play store. Stefanko added that apps with AhMyth embedded in them had made it past Google’s filters before.

Scam apps aren’t new on either Apple’s or Google’s app stores. Recorder apps can be especially bad, sometimes having predatory subscription pricing and fake reviews to inflate their visibility on those platforms. And Stefanko’s blog post highlights a particularly sticky problem: apps turning to the dark side after you’ve had them for a while, using the permissions you granted them at the outset to gather sensitive information from your device and shuttle it off to the developer for nefarious activities.

This particular app is gone, but what’s to keep another sleeper agent from activating on your phone? Google is at least working on updates that will tell you via monthly notification which, and when, apps have changed their data-sharing practices — if it finds out, that is.

original link


You may also be interested in this

DoorDash charges iPhone u…

DoorDash charges iPhone users more than it charges Android users, at least according to a class-action lawsuit filed against the company. In the lawsuit, customers allege that DoorDash uses vague

Try Rode’s studio-worthy …

Our hands-on Rode NTH-50 headphones review find the on-ear wired cans a great value for pros and casual listeners alike. (via Cult of Mac - Your source for the latest

Nearly every Apple top ex…

Apple's mixed-reality headset is a big deal for the company, with many of the highest executives involved with the project to try and make it a success.A render of a

2 key items complete kill…

Today's M2 MacBook Air setup was "done" just weeks ago. Now new additions boost iPad functionality and pump up sound. (via Cult of Mac - Tech and culture through an

iOS 18’s generative AI fe…

Apple could reportedly rely on Google's Gemini AI model to power the generative AI features in iOS 18 and its upcoming iPhones. (via Cult of Mac - Apple news, rumors,

Level x Rejuvenation coll…

Today Level, creators of smart locks like , have announced a partnership with home goods brand Rejuvenation, which falls under the same umbrella as brands like Pottery Barn, Williams Sonoma,

The best Fourth of July d…

The Samsung Galaxy Watch 5 is on sale starting at $229.99 at multiple retailers. | Photo by Amelia Holowaty Krales / The Verge Amazon Prime Day is just around the

Apple Releases First Beta…

Following today's keynote event, Apple has released the first betas of iOS 17 and iPadOS 17 to developers for testing purposes. The betas are only available for those with a
X

A whimsical homage to the days in black and white, celebrating the magic of Mac OS. Dress up your blog with retro, chunky-grade pixellated graphics to evoke some serious computer nostalgia. Supports a custom menu, custom header image, custom background, two footer widget areas, and a full-width page template. I updated Stuart Brown's 2011 masterpiece to meet the needs of the times, made it responsive , got dark mode, custom search widget and more.You can download it from tigaman.com, where you can also find more useful code snippets and plugins to get even more out of wordpress.