Kaspersky uncovers 'world's most powerful' Android spyware tool, Skygofree

The spyware steals WhatsApp messages and your passwords

Trojan virus

KasperskyLab has uncovered a new security vulnerability affecting Android devices, claiming it's one of the world's most powerful Android spyware tools.

Named 'Skygofree', the threat apparently enables attackers to hack into Android smartphones and tablets and extract WhatsApp messages from victims' devices.

"The malware can also monitor popular apps such as Facebook Messenger, Skype, Viber, and WhatsApp," Kaspersky'sAnna Markovskaya revealed in a blog post. "In the latter case, the developers again showed savvy; the Trojan reads WhatsApp messages through Accessibility Services."

The tool is not a new one, either. While it was only recently discovered, the Russian security giant says it dates back as far as 2014.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

Warning of the dangers of the spyware tool,Markovskaya explained that Skygofree can not only take audio from a smartphone's microphone when it's in a certain location, but also force infected devices to surreptitiously connect to a Wi-Fi network and gather even more personal data. This, the firm said, lets it collect and analyse a victim's web traffic, meaning someone somewhere will know exactly what sites they looked at and what logins, passwords, and card numbers they entered.

"The payload uses the Android Accessibility Service to get information directly from the displayed elements on the screen, so it waits for the targeted application to be launched and then parses all nodes to find text messages,"Markovskaya said.

"Essentially, Accessibility Services provide[s] a nice route into other applications as they have permission to do so, via an application programming interface (API)."

In a seperate SecureList blog, Kaspersky security experts concluded thatSkygofree is "one of the most powerful spyware tools that we have ever seen for this platform". Nevertheless, the teamsaid it has only logged a few infections of the tool, and those have all been in Italy. While that doesn't sound very scary unless you live in Italy, the firm said that this doesn't mean that users in other countries can let their guard down, as malware distributors can change their target audience at any moment.

Kaspersky'sMarkovskaya issued three ways users can protect themselves against this advanced Trojan, just like any other infection.

The first is by only installing apps only from official stores and disabling installation of apps from third-party sources, which you can do in your smartphone settings.

Advertisement - Article continues below

The second is by not downloading an app if you're in any doubt whatsoever.

"Pay attention to misspelled app names, small numbers of downloads, or dubious requests for permissions any of these things should raise flags,"Markovskaya also warned.

Finally, she advised that users should install a reliable security solution in order to protect your device from most malicious apps and files, suspicious websites, and dangerous links.

Featured Resources

Transform the operator experience with enhanced automation & analytics

Bring networking into the digital era

Download now

Artificially intelligent data centres

How the C-Suite is embracing continuous change to drive value

Download now

Deliver secure automated multicloud for containers with Red Hat and Juniper

Learn how to get started with the multicloud enabler from Red Hat and Juniper

Download now

Get the best out of your workforce

7 steps to unleashing their true potential with robotic process automation

Download now
Advertisement

Recommended

Visit/security/354156/google-confirms-android-cameras-can-be-hijacked-to-spy-on-you
Security

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019

Most Popular

Visit/operating-systems/microsoft-windows/354297/this-exploit-could-give-users-free-windows-7-updates
Microsoft Windows

This exploit could give users free Windows 7 updates beyond 2020

9 Dec 2019
Visit/security/vulnerability/354309/patch-issued-for-critical-windows-bug
vulnerability

Patch issued for critical Windows bug

11 Dec 2019
Visit/cloud/microsoft-azure/354230/microsoft-not-amazon-is-going-to-win-the-cloud-wars
Microsoft Azure

Microsoft, not Amazon, is going to win the cloud wars

30 Nov 2019
Visit/data-insights/big-data/354311/google-reveals-uks-most-searched-for-terms-in-2019
big data

Google reveals UK’s most searched for terms in 2019

11 Dec 2019