Google blocks spyware from Play after Android users targeted

Lipizzan spyware could read emails and record calls, but wasn't installed on many phones

Google has warned that spyware apps are targeting Android, removing 20 from its own Play Store.

In response, the company has added new tools to detect such spyware in apps on its store, according to a post on the Android Developers blog, written by Megan Ruthven, researcher at Android Security and Ken Bodzak, researcher at Neel Mehta Threat Analysis Group.

The apps in question used spyware called Lipizzan, which the researchers said is connected to a "cyber arms company," known as Equus Technologies. The spyware can monitor and nab email, SMS messages, your location, voice calls and other media stored on your handset.

But while 20 apps with Lipizzan code were found on the Google Play Store, they only managed to target fewer than 100 devices, Google said, adding it has "notified all affected devices and removed the Lipizzan apps".

Advertisement - Article continues below

The Lipizzan tool worked in two stages, Google said, usually disguising itself as a backup or cleaner tool.  "Upon installation, Lipizzan would download and load a second 'license verification' stage, which would survey the infected device and validate certain abort criteria," the researchers said. "If given the all-clear, the second stage would then root the device with known exploits and begin to exfiltrate device data to a Command & Control server."

In that second stage, it could take screenshots and photos, steal user data on contacts and files, record calls, monitor location, and even record from the device microphone. It specifically targeted Gmail, Hangouts, LinkedIn, WhatsApp, Messenger, Skype and Snapchat, as well as Telegram.

The attackers were responsive to Google's efforts. When the first round of Lipizzan tools were knocked off the app store, they created new ones. "The apps changed from 'backup' apps to looking like a 'cleaner', 'notepad', 'sound recorder', and 'alarm manager' app," the researchers said. "The new apps were uploaded within a week of the takedown, showing that the authors have a method of easily changing the branding of the implant apps."

Google said it's boosted the security protections of its app store to better detect spyware in the future.

Featured Resources

The IT Pro guide to Windows 10 migration

Everything you need to know for a successful transition

Download now

Managing security risk and compliance in a challenging landscape

How key technology partners grow with your organisation

Download now

Software-defined storage for dummies

Control storage costs, eliminate storage bottlenecks and solve storage management challenges

Download now

6 best practices for escaping ransomware

A complete guide to tackling ransomware attacks

Download now



Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019

Most Popular

Microsoft Azure

Microsoft, not Amazon, is going to win the cloud wars

30 Nov 2019
Amazon Web Services (AWS)

What to expect from AWS Re:Invent 2019

29 Nov 2019
Business strategy

Huawei takes the US trade sanctions into its own hands

3 Dec 2019

Five signs that it’s time to retire IT kit

29 Nov 2019