Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Android Malware Capable Of Spying On Users Devices
News & Analysis

Android Malware Capable Of Spying On Users Devices

ISBuzz TeamBy ISBuzz TeamMarch 1, 2018Updated:March 5, 20185 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Lemon Group Exploits 8.9 Million Pre-Infected Android Phones
Lemon Group Exploits 8.9 Million Pre-Infected Android Phones
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

It has been reported that a newly uncovered form of Android malware called RedDrop has the ability to steal critical information from infected devices. The research was conducted by security company Wandera, which stated that RedDrop was able to harvest full audio recordings of phone calls and also had the capability of secretly sending SMS messages to a premium rate service, increasing the users phone bill. IT security experts commented below.

Craig Young, Computer Security Researcher at Tripwire:

“There is nothing new about this malware. This looks more like a very amateur trial run of Android malware rather than “one of the most sophisticated pieces of Android malware” as claimed by the researhers. Based on their report, this malware is not exploiting any vulnerabilities but instead relies on users installing a malicious application which requests many permissions.  While it may not be common for Android malware to record and upload calls, I suspect this is because it provides minimal value outside of targeted attacks and potentially makes the malware more apparent by draining victim’s battery quickly.

Android users do not need to do anything more than normal to guard against this threat.  Default settings on all supported releases of Android should be pretty well protected against by installing only from trusted sources and leaving Google Play Protect enabled.  It is also of course important to be mindful about what permissions are requested by apps.  With Android 6 (released 2015), apps will request permissions at runtime which should make it abundantly obvious when a malicious app wants to do something like sending SMS or recording audio. Users of older Android releases must rely instead on reviewing the requested permissions at install time to confirm that they are appropriate for the app.”

Nick Bilogorskiy, Cybersecurity Strategist at Juniper Networks:

“The Android platform has long been exploited by sophisticated spying trojans. We have seen this with both Pegasus and SunTeam.

Pegasus was an espionage campaign by the Israel-based NSO Group. capable of keylogging, screenshot capture, live audio and video capture, and data exfiltration from common social media applications.

Android phones are more likely to get malware than iPhones for two reasons. One, the Google Play app store is less strict at filtering malicious apps than the Apple App Store; and two, most Android phones are not up-to-date. According to Google’s developer dashboard, most Android users are on the 6.0 Marshmallow version – several versions behind, and less than one percent of users is running the newest 8.1 Oreo version.”

Mounir Hahad, Head of Tthreat Research at Juniper Networks:

“Android devices are a prime target for cyber criminals because they can natively download applications from non-Google approved marketplaces. Some of these application portals have little to no regard for the security risk of the applications they host. Even Google Play, for that matter, is not as good as the Apple App Store in picking up on malicious applications.

The real question is when are enterprises that allow BYOD going to start paying attention to this threat vector? It has been mostly ignored so far under the assumption that the enterprise does not own the device and therefore cannot remediate it. But,  BYOD devices are clearly posing a security risk if they can allow for spyware to run. Lateral movement in this case is just an executive with an infected device walking into a board meeting.”

Andrew Speakmaster, Founder and Chief Technology Officer at SiO4:

“This type of malware is very dangerous for a number of reasons. First, it causes personal financial liabilities to the victim by amassing SMS and other charges via a premium rate service. However, the most devastating reason is the data exfiltration of personal files that most likely contain some sort of PII (Personal Identifiable Information). Once the threat actor is able to extract PII from the device, the victim is open to identity fraud, compromised credentials and other malicious activities that can arise from this device breach.

The greatest threat from this malware is the potential to infiltrate a corporate network where IT assets are compromised and data can be exfiltrated. Many organizations have a BYOD policy which would be an ideal method of attack to create a devastating breach.

Third-party apps should never be downloaded onto a device, only apps from trusted sources like the Google Play Store Apple App Store should be used.”

Anthony James, Chief Marketing Officer at CipherCloud:

“RedDrop has rapidly emerged as one of the newest global cyber threats to target mobile phone users. Red Drop arms sophisticated attackers with a very comprehensive and highly sophisticated surveillance system that is unknowingly hosted by the targeted host, an Android phone.  The distributors of RedDrop appear to control thousands of malware-laced websites, and they use this infected network to lure and then compromise Android users.

Tools like RedDrop can enable the compromise of an entire corporate network, by clandestinely riding in camouflage within infected Android devices. This raises the imperative for enterprise and government to better understand how they will provide end-to-end data protection for cloud and on-premise based resources knowing that network penetration by an attacker becomes much more likely each and every day.”

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}