Malicious messaging apps used to spread malware on Google Play — delete these right now

Despite Google’s best efforts, cybercriminals are still coming up with ways to get their malicious apps onto the Play Store and remain there undetected.

As reported by BleepingComputer, a remote access trojan (RAT) called VajraSpy was discovered in 12 different malicious apps, though only six of them were available to download directly from the Google Play Store. The other six were distributed through unofficial, third-party app stores.

Regardless of where you might have downloaded one of these bad apps from, once they found their way onto one of the best Android phones, they install the VajraSpy malware. It’s capable of extracting a victim’s contacts, text messages, call logs, device location, a list of installed apps as well as pictures, PDFs, documents and other files with specific extensions.

Here’s everything you need to know about this latest batch of malicious apps including how to remove them from your own Android smartphone.

Delete these apps right now

According to a new report from the cybersecurity firm ESET, the six malicious apps discovered on the Play Store have now been removed. However, they were up on Google’s app store and available to download for more than two years between April of 2021 and September of 2023.

Even though these apps have now been removed, you will still need to manually uninstall them from your devices if you were tricked into installing them in the first place. Here are all 12 malicious apps along with where you might have downloaded them from:

  • Rafaqat – Play Store
  • Privee Talk – Play Store
  • MeetMe – Play Store
  • Let’s Chat – Play Store
  • Quick Chat – Play Store
  • Chit Chat – Play Store
  • Hello Chat – third-party app store
  • YohooTalk – third-party app store
  • TikTalk – third-party app store
  • Nidus – third-party app store
  • GlowChat – third-party app store
  • Wave Chat – third-party app store

As ESET points out, Wave Chat is the most dangerous of these malicious because it abuses Android’s accessibility services. Upon launch, the app asks for users to grant it extra permissions; if this is done, the app can then record phone calls, record WhatsApp, Signal and Telegram calls, log keystrokes, take pictures using a device’s camera, record audio and scan for Wi-Fi networks.

From romance scam to malware infection

amazon, android, malicious messaging apps used to spread malware on google play — delete these right now

((Image credit: Shutterstock))

So how did the cybercriminals behind these malicious apps trick their victims into downloading and installing them in the first place? According to ESET’s investigation into the matter, this was done by using a romance scam to lure potential victims into installing these malware-filled apps.

If you’ve ever used one of the best dating apps before, then you’ve likely come across a potential match that tried to get you to move off the app and use another platform instead. While ordinary people might ask you to switch from a dating app to communicating via text message or even WhatsApp, a sure fire sign of a romance scam is when they encourage you to download, install and then chat on an app you’ve never heard of before.

When a scammer or even a cybercriminal already has their hooks into a potential victim, they might fall for something like this, especially when they think the person on the other end of their phone is genuinely interested in them. For this reason, you always want to be extremely careful when someone you’re courting on a dating app asks you to switch to another app or service. If they send you a link to download an app though, your best course of action is to turn and run; under no circumstances should you click on the link.

Even if the link doesn’t take you to a third-party app store, it could take you to a phishing page designed to steal your credentials or even your money. As difficult as it is to date in person these days, meeting people in real life as opposed to online may actually be the better option if you don’t want to get scammed when looking for love.

How to stay safe from Android malware

amazon, android, malicious messaging apps used to spread malware on google play — delete these right now

((Image credit: Google))

When it comes to avoiding malicious apps and Android malware, the first and most important thing you can do is to limit the number of apps on your smartphone while being careful when installing any new apps.

You’re going to want to stick to official app stores like the Google Play Store, Amazon Appstore and the Samsung Galaxy Store instead of sideloading apps. Apps downloaded as APK files from third-party app stores don’t go through the same level of security checks as those distributed through official app stores. However, malicious apps can slip through the cracks which is why I recommend limiting the number of apps on your phone overall and even then, good apps can still go bad.

Fortunately though, Google Play Protect, which comes pre-installed on most Android phones, automatically scans all of your existing apps and any new ones you download for malware. For extra protection though, you also might want to consider one of the best Android antivirus apps as many of them include additional security software like a VPN or even a password manager alongside malware protection.

As for this latest batch of malicious apps, a Google spokesperson provided further insight on them in an email to Tom’s Guide, saying:

“We take security and privacy claims against apps seriously, and if we find that an app has violated our policies, we take appropriate action. All of the reported apps are no longer on Google Play. Users are protected by Google Play Protect, which can warn users of apps known to exhibit this malicious behavior on Android devices with Google Play Services, even when those apps come from sources outside of Play.”

Since cybercriminals are always coming up with new ways to deliver their malware though, this likely won’t be the last time we see malicious apps used to attack Android users. However, if you remain cautious — especially when talking to strangers online — and follow the guidance above, you should be able to steer clear of malicious apps and keep you and your data safe.

More from Tom’s Guide

    News Related

    OTHER NEWS

    FA confident that Man Utd starlet will pick England over Ghana

    Kobbie Mainoo made his first start for Man Utd at Everton (Photo: Getty) The Football Association are reportedly confident that Manchester United starlet Kobbie Mainoo will choose to represent England ... Read more »

    World Darts Championship draw throws up tricky tests for big names

    Michael Smith will begin the defence of his world title on the opening night (Picture: Getty Images) The 2024 World Darts Championship is less than three weeks away and the ... Read more »

    Pioneering flight to use repurposed cooking oil to cross Atlantic

    For the first time a long haul commercial aircraft is flying across the Atlantic using 100% sustainable aviation fuel (SAF). A long haul commercial flight is flying to the US ... Read more »

    King meets world business and finance figures at Buckingham Palace

    The King has met business and finance leaders from across the world at a Buckingham Palace reception to mark the conclusion of the UK’s Global Investment Summit. Charles was introduced ... Read more »

    What Lou Holtz thinks of Ohio State's loss to Michigan: 'They aren't real happy'

    After Ohio State’s 30-24 loss to Michigan Saturday, many college football fans were wondering where Lou Holtz was. In his postgame interview after the Buckeyes beat Notre Dame 17-14 in ... Read more »

    Darius Slay wouldn't have minded being penalized on controversial no-call

    Darius Slay wouldn’t have minded being penalized on controversial no-call No matter which team you were rooting for on Sunday, we can all agree that the officiating job performed by ... Read more »

    Mac Jones discusses Patriots future after latest benching

    New England Patriots quarterback Mac Jones (10) Quarterback Mac Jones remains committed to finding success with the New England Patriots even though his future is up in the air following ... Read more »
    Top List in the World