Researchers at Sophos have identified a new type of attack on users of Android devices. Cybercriminals created fake versions of, among others, the official government app of Pakistan, an insurance company's app, and a mobile operator price comparison tool.
The malicious versions of the programs intercept contacts, SMS message content, identity document data, location information, and photos from devices, then send them to the criminals' servers. So far, the targets have been apps for users in Pakistan, but the attack can easily be replicated anywhere in the world.
Phones under surveillance
Phones under surveillance
The fake apps are identical to their legitimate counterparts available in the Google Play Store, and they also allow the same functions to be used. The criminals chose five apps operating in Pakistan: the official government app Pakistan Citizen Portal, a Muslim prayer clock, an app for comparing mobile operator offers, a tool for checking SIM card validity, and an insurance company's program.
Once launched, the malicious tools intercept the device's unique IMEI identifier, location information, the full contact list, text message content, call logs, and SD card directories. The Pakistan Citizen Portal app also prompts users to provide their national ID number, passport details, and passwords for Facebook and other services. Some of the counterfeit apps contain a mechanism that enables recording phone calls and sounds captured by the device. However, these functions have not yet been activated by the criminals.
A “red flag” for all users
A “red flag” for all users
New Android attack: how to protect yourself from spyware apps
The fake versions of the apps are not available in the official Google Play Store, but on websites imitating, among others, the Pakistani government service. Users may have received links with instructions to download the programs via SMS or email. The cybercriminals encrypt the code they create, so the installed app is not identified as malicious during the device's initial scan.
The discovered spyware is a warning sign for users not only in Pakistan but also around the world. Criminals are increasingly attacking mobile phones to intercept sensitive data and gain real-time access to the location of an infected device, or even conversations taking place within its range.
– Anyone who uses a mobile phone should remember the basic security rules: do not click on links received by email or SMS, and download apps only from official sources. It is also important to pay attention to the permissions requested by the installed program. If a clock or an offer comparison app asks for access to messages, contacts, or photos, that should raise suspicion. It is also worth considering installing antivirus software on a mobile device to protect data against similar threats – says Łukasz Formas, engineering team manager at Sophos.
Summary
Sophos researchers detected a spy campaign targeting Android users in Pakistan. Cybercriminals created fake versions of five popular apps, including the government portal Pakistan Citizen Portal, which after installation intercept personal data, SMS messages, contacts, location, and photos, and even enable call recording. The programs are not available in Google Play, but on websites imitating legitimate services, and their malicious code is encrypted, which makes detection during scanning difficult.
Experts warn that similar attacks can easily be repeated around the world, so they remind users of the basic security rules: download apps only from official sources and verify the permissions of installed programs.