Search

Google Removes Android Screen Recording App Found Spying on Users With Remote Access Trojan

The iRecorder app is capable of recording and sharing audio with the attacker and exfiltrating files with extensions for images, audio, and video.

Advertisement
Highlights
  • Google has removed the iRecorder screen recording app from the Play Store
  • ESET researchers have dubbed the newly discovered trojan AhRat
  • Users will have to manually remove the infected app from their devices
Google Removes Android Screen Recording App Found Spying on Users With Remote Access Trojan

AhRat is a customization of the open-source AhMyth remote access trojan (RAT)

Photo Credit: Pexels/ Sora Shizamaki

Google recently removed a trojan-infected Android app, that was installed on over 50,000 devices, from the Play Store. According to the security firm that detected the trojan, the app was first uploaded by the developer in 2021 and then infected with malicious code a year later. The app was also capable of extracting and uploading users' files by detecting extensions for audio, video, and web pages. While the app has been removed from the Play Store, users who downloaded it will have to manually remove the app from their devices.

According to a report published by ESET researchers, the iRecorder app was uploaded to the Play Store for the first time in September 2019, without any malicious functionality. Nearly a year later, the app was infected with the open-source AhMyth Android RAT (remote access trojan) in a variant that the researchers dubbed AhRat. Users who updated the app, or downloaded it for the first time since August 2022 would have the infected app on their device.

irecorder app trojan screenshot eset irecorder malware trojan

The iRecorder app had over 50,000 downloads on the Google Play store
Photo Credit: Screenshot/ ESET

 

While the initial version of the app did not have any malicious functionality, ESET states that it was later updated with code that allowed it to engage in malicious behaviour, including recording ambient sound and audio by utilising the phone's mic. These recordings could then be uploaded to the attacker's command-and-control (C&C) server. The app was also capable of extracting files with specific extensions, such as video, audio, images, web pages, documents, and compressed files.

ESET's researchers explain that the AhMyth RAT is a very powerful tool that can exfiltrate text messages, call logs, and contacts on a user's phone while recording audio, capturing images, tracking the device's location, and generating a list of all the files on the smartphone. 

The app's behaviour suggests that the AhRat trojan could be used as part of an espionage campaign, according to the researchers, who were unable to attribute it to any advanced persistent threat (APT) group. Meanwhile, ESET says that the original open-source AhMyth RAT was previously used by cyberespionage group APT36 — commonly known as Transparent Tribe — to target government and military organisations in South Asia. 

After ESET flagged the malicious code in the iRecorder app to Google, the app was removed from the Google Play store. The app has already been downloaded 50,000 times, according to the listing at the time of its removal. Users who installed or updated the application after it was infected will have to manually uninstall it in order to remove the infected app from their smartphones.


Google I/O 2023 saw the search giant repeatedly tell us that it cares about AI, alongside the launch of its first foldable phone and Pixel-branded tablet. This year, the company is going to supercharge its apps, services, and Android operating system with AI technology. We discuss this and more on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Malware, Android Malware, Trojans, RAT
 
Show Full Article
Please wait...
Advertisement

Related Stories

Popular Mobile Brands
  1. IPL 2025 Live Streaming for Free: How to Watch CSK vs RCB IPL Match Online?
  2. OTT Releases This Week: Jewel Thief, Viduthalai Part 2, and More
  3. Realme 14 Pro+ Review: Plenty of Refinements
  4. Realme 14 5G With Snapdragon 6 Gen 4 SoC, 6,000mAh Battery Launched
  5. Vivo X200 Ultra Teased to Get Dedicated Camera Control Button
  6. Vivo X200 Ultra Teased to Get Two Imaging Chips; Camera Samples Revealed
  7. OnePlus President Hints at New Compact Phone; OnePlus 13T Design Leaked
  8. Ghibli Tokens Ignite Memecoin Frenzy Amid Anime AI Art Boom
  9. OnePlus 12R, Nord 4 and Pad 2 Receiving New OxygenOS 15 Update in India
  10. iQOO Z10 Price in India, Chipset Details Teased Ahead of Launch
  1. Krafton Acquires Controlling Stake in Real Cricket Developer Nautilus Mobile for Rs. 118 Crore
  2. UAE Plans to Launch Digital Dirham CBDC, Integrated Wallet in Q4 2025
  3. CMF by Nothing Hints at New Products With Pokemon Teasers; CMF Phone 2 Could Launch Soon
  4. Google NotebookLM Upgraded With Mind Maps Feature and Output Language Selector
  5. Ghibli-Themed Tokens Spark Memecoin Frenzy Amid Surge in Anime AI Art Trend on Social Media
  6. Prince of Persia: The Lost Crown to Release on Android, iOS Platforms on April 14
  7. Apple's Foldable iPhone to Sport Display With Same Aspect Ratio as iPad Models, Tipster Claims
  8. Light Phone 3 With OLED Display, 1,800mAh Battery and Minimalist Design Launched: Price, Specifications
  9. Instagram Adopts Popular TikTok Feature, Adds 2X Playback Speed Option for Reels
  10. Anthropic Researchers Make Major Breakthrough In Understanding How an AI Model Thinks
Gadgets 360 is available in
Download Our Apps
App Store App Store
Available in Hindi
App Store
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.
Trending Products »
Latest Tech News »