New Android malware has advanced spying capabilities

By
Follow google news

Reminiscent of the Hacking Team malware.

A new spyware for Google's Android mobile operating system contains advanced capabilities for attackers, researchers have found.

New Android malware has advanced spying capabilities
Source: Kaspersky

Security vendor Kaspersky found the Skygofree malware in the beginning of October last year, and said it appears to be at least three years old. It is currently being used to surveil targets in Italy, the vendor said.

Skygofree stands out because it provides new surveillance functionality such as recording surrounding audio when infected devices are in specific locations, according to Kaspersky.

The malware can also capture messages from communications program WhatsApp via Android's accessibility services feature, and connect to compromised wi-fi networks controlled by attackers.

Video and photo capture through the front-facing smartphone camera when the surveillance target unlocks the device is also possible with Skygofree, Kaspersky said.

Huawei smartphones get special attention from Skygofree, which is able to add itself to the whitelist of programs that shouldn't be terminated by the operating system in order to save battery.

Skygofree has so far only been found infecting Italian users. Sifting through the malware code, Kaspersky said it is "pretty confident that the developer of the Skygofree implants is an Italian company that works on surveillance solutions, just like Hacking Team".

Hacking Team sells spyware to governments around the world. It rose to fame two years ago after the company itself was hacked and its sensitive corporate information posted online.

During the Skygofree investigation, Kaspersky also found spyware tools for Windows that could be implanted on target systems in order to to exfiltrate data.

The security vendor couldn't confirm if the Windows tools, which were compiled early last year, have been used in the wild, and did not say how it obtained the samples.

Kaspersky named the spyware Skygofree after finding the term in one of the domains of sites that impersonate real domains of mobile telcos,ctors.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

National photo licence recognition system set to go live in 2025

National photo licence recognition system set to go live in 2025

Age verification IDs taken in Discord data breach

Age verification IDs taken in Discord data breach

Qantas says customer data released by cyber criminals

Qantas says customer data released by cyber criminals

NSW gov contractor uploaded Excel spreadsheet of flood victims' data to ChatGPT

NSW gov contractor uploaded Excel spreadsheet of flood victims' data to ChatGPT

Log In

  |  Forgot your password?