Endpoint/Device Security, Application security

Health app-posing spyware spread via Amazon Appstore

BleepingComputer reports that malicious actors have distributed Android spyware as the BMI CalculationVsn app through the Amazon Appstore, from which it has since been removed.

Despite showing straightforward body mass index calculating capabilities upon opening, BMI CalculationVsn — which is developed by PT Visionet Data Internasional — not only covertly triggered a screen recording service upon clicking the 'Calculate' button, with the saved recordings stored in an MP4 file, but also facilitated device scanning to fetch all apps installed in the targeted devices, according to an analysis from McAfee Labs researchers. BMI CalculationVsn was also discovered to have enabled the exfiltration of one-time passwords, verification codes, and other SMS messages in compromised devices, researchers said. Immediate uninstallation of BMI CalculationVsn has been urged among its users, who were also advised to perform device scanning to ensure the complete removal of the app. Such a development should also prompt Android users to only download apps from trusted publishers.

An In-Depth Guide to Application Security

Get essential knowledge and practical strategies to fortify your applications.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds