Categories: Security

Malware Poses As Fake Netflix App To Spy On Users And Steal Data

Cloud security provider Zscaler has uncovered a fake Netflix app which, once downloaded, enables cyber criminals to take control over the device.

The app, which was available through a third party app store, was actually a “well crafted” piece of spyware called SpyNote RAT (remote access Trojan), capable of performing functions such as executing commands on the device and activating the microphone to listen to conversations.

It could also take screen captures, view contacts, read SMS messages and copy files from the device to a Command & Control (C&C) centre.

Netflix spyware

Once installed, the fake app displays the same logo as the legitimate Netflix app from the Google Play Store. However, when it is clicked for the first time the icon actually disappears from the home screen, tricking the user into thinking that it has been deleted.

Using the Services, Broadcast Receivers, and Activities components of the Android platform, SpyNote RAT keeps itself up and running, enabling it to continuously spy on its unsuspecting victims.

“Command execution can create havoc for the victim if the malware developer decides to execute commands in the victim’s device,” writes Shivang Desai on the Zscaler blog. “Leveraging this feature, the malware developer can root the device using a range of vulnerabilities, well-known or zero-day.”

“Uninstalling apps is another function favoured by developers of Android spyware and malware. They tend to target any antivirus protections on the device and uninstall them, which increases the possibility of their malware persisting on the device.”

Desai notes that this particular malware targeting the hugely popular video-streaming app appeared to be “more robust” than most, as it was designed to only function over Wi-Fi.

He also warns that SpyNote RAT is “gaining popularity in the hacking community” and has been found targeting several other popular apps including WhatsApp, YouTube Video Downloader, Instagram and Facebook.

This is not the first time Netflix has been targeted by cyber criminals, as a phishing scam was recently discovered to be targeting credit card details and other personal information of users.

Quiz: Everything you should know about cyber security in 2016

Sam Pudwell

Sam Pudwell joined Silicon UK as a reporter in December 2016. As well as being the resident Cloud aficionado, he covers areas such as cyber security, government IT and sports technology, with the aim of going to as many events as possible.

Recent Posts

Is the Digital Transformation of Businesses Complete?

Digital transformation is an ongoing journey, requiring continuous adaptation, strong leadership, and skilled talent to…

18 hours ago

Craig Wright Faces Contempt Claim Over Bitcoin Lawsuit

Australian computer scientist faces contempt-of-court claim after suing Jack Dorsey's Block and Bitcoin Core developers…

19 hours ago

OpenAI Adds ChatGPT Search Features

OpenAI's ChatGPT gets search features, putting it in direct competition with Microsoft and Google, amidst…

19 hours ago

Google Maps Steers Into Local Information With AI Chat

New Google Maps allows users to ask for detailed information on local spots, adds AI-summarised…

20 hours ago

Huawei Sees Sales Surge, But Profits Fall

US-sanctioned Huawei sees sales surge in first three quarters of 2024 on domestic smartphone popularity,…

20 hours ago

Apple Posts China Sales Decline, Ramping Pressure On AI Strategy

Apple posts slight decline in China sales for fourth quarter, as Tim Cook negotiates to…

21 hours ago