Explorer

Beware: Google detects spy app stealing info from Facebook, WhatsApp and phones

Google has detected an app which has been stealing information from call records and also from social media apps like Facebook, WhatsApp, and also takes pictures from mobile phones without even displaying them on screen of the device.

NEW DELHI: Google has detected an app which has been stealing information from call records and also from social media apps like Facebook, WhatsApp, and also take pictures from mobile phones without even displaying them on screen of the device. The company has removed the app from Play Store, notified all known affected devices and suspended account of the app developer, the post dated November 27 said. "Tizi is a fully featured backdoor that installs spyware to steal sensitive data from popular social media applications. The Google Play Protect security team discovered this family in September 2017 when device scans found an app with rooting capabilities that exploited old vulnerabilities," a post on Google security blog said. The post said that earlier variant of Tizi did not had rooting capabilities but it developed later on and thereafter started stealing sensitive information from devices. "The rooting capabilities give an app full control of the device. It can bypass all restriction posed on it by Android security system. An app with rooting is like a user using the device. Presence of such app on Google Play Store raises concerns around secure apps on the app store," cyber security expert Jiten Jain said. The post said that after gaining rooting capability, Tizi steals sensitive data "from popular social media apps like Facebook, Twitter, WhatsApp, Viber, Skype, LinkedIn, and Telegram." The backdoor capability of Tizi were common to commercial spyware, such as recording calls from WhatsApp, Viber, and Skype, sending and receiving SMS messages, and accessing calendar events, call log, contacts, photos, Wi-Fi encryption keys, and a list of all installed apps "Tizi apps can also record ambient audio and take pictures without displaying the image on the device's screen," the post said. The post said that in and after April 2016 vulnerabilities in devices which could have been affected by Tizi were fixed with new software codes. "If a Tizi app is unable to take control of a device because the vulnerabilities it tries to use are are all patched, it will still attempt to perform some actions through the high level of permissions it asks the user to grant to it, mainly around reading and sending SMS messages and monitoring, redirecting, and preventing outgoing phone calls," the post said.
View More
Advertisement
Advertisement
25°C
New Delhi
Rain: 100mm
Humidity: 97%
Wind: WNW 47km/h
See Today's Weather
powered by
Accu Weather
Advertisement

Top Headline

LS Elections: Almost No Votes Cast In 6 Nagaland Districts Amid Shutdown Call Over Statehood Demand
Almost No Votes Cast In 6 Nagaland Districts Amid Shutdown Call Over Statehood Demand
Arvind Kejriwal Vs ED: Delhi CM Slams Charge Over Jail Diet, Asks 'Am I Going To Risk Paralysis To Get Bail?'
Kejriwal Slams ED's Charge Over Jail Diet, Asks 'Am I Going To Risk Paralysis To Get Bail?'
'Fought Against Hindus In Court, But..': PM Modi Lauds Ex-Babri Litigant Iqbal Ansari As He Slams Congress, I.N.D.I.A
'Fought Against Hindus In Court, But..': PM Modi Lauds Ex-Babri Litigant As He Slams Congress
Lok Sabha Polls: Violence Mars Voting In Manipur As Armed Miscreants 'Intimidate' Booth Agents, Voters
Violence Mars Lok Sabha Voting In Manipur As Armed Miscreants 'Intimidate' Booth Agents, Voters
Advertisement
for smartphones
and tablets

Videos

Shah Rukh Khan & Daughter Suhana Khan To Work Together In 'King', SRK To Dive Into Action | KFHLS Polls Voting Phase 1: 'Please Do Not Test My Patience' Chirag Paswan's Scathing Attack | ABP NewsLS Polls Voting Phase 1: BJP candidate Anil Baluni claims victory on 5 seats of Uttarakhand | ABP NewsUP Polls Voting Phase 1: SP candidate from Kairana, Fiercely targets NDA ahead of voting | ABP News

Photogallery

Embed widget