Categories: Security

Malware Poses As Fake Netflix App To Spy On Users And Steal Data

Cloud security provider Zscaler has uncovered a fake Netflix app which, once downloaded, enables cyber criminals to take control over the device.

The app, which was available through a third party app store, was actually a “well crafted” piece of spyware called SpyNote RAT (remote access Trojan), capable of performing functions such as executing commands on the device and activating the microphone to listen to conversations.

It could also take screen captures, view contacts, read SMS messages and copy files from the device to a Command & Control (C&C) centre.

Netflix spyware

Once installed, the fake app displays the same logo as the legitimate Netflix app from the Google Play Store. However, when it is clicked for the first time the icon actually disappears from the home screen, tricking the user into thinking that it has been deleted.

Using the Services, Broadcast Receivers, and Activities components of the Android platform, SpyNote RAT keeps itself up and running, enabling it to continuously spy on its unsuspecting victims.

“Command execution can create havoc for the victim if the malware developer decides to execute commands in the victim’s device,” writes Shivang Desai on the Zscaler blog. “Leveraging this feature, the malware developer can root the device using a range of vulnerabilities, well-known or zero-day.”

“Uninstalling apps is another function favoured by developers of Android spyware and malware. They tend to target any antivirus protections on the device and uninstall them, which increases the possibility of their malware persisting on the device.”

Desai notes that this particular malware targeting the hugely popular video-streaming app appeared to be “more robust” than most, as it was designed to only function over Wi-Fi.

He also warns that SpyNote RAT is “gaining popularity in the hacking community” and has been found targeting several other popular apps including WhatsApp, YouTube Video Downloader, Instagram and Facebook.

This is not the first time Netflix has been targeted by cyber criminals, as a phishing scam was recently discovered to be targeting credit card details and other personal information of users.

Quiz: Everything you should know about cyber security in 2016

Sam Pudwell

Sam Pudwell joined Silicon UK as a reporter in December 2016. As well as being the resident Cloud aficionado, he covers areas such as cyber security, government IT and sports technology, with the aim of going to as many events as possible.

Recent Posts

Tesla To Ask Shareholders To Reinstate Elon Musk’s $56 Billion Package

Tesla shareholders to be asked to reinstate Elon Musk's $56 billion pay package, days after…

8 hours ago

Telegram To Reach One Billion Users Within Year

Catching WhatsApp? Billionaire founder of Telegram claims encrypted platform will reach one billion users within…

9 hours ago

Judge Dismisses Some Harm Claims Against Meta, Zuckerberg

Good news for Mark Zuckerberg as judge dismisses some claims in dozens of lawsuits alleging…

10 hours ago

Google Begins Removal Of California News Ahead Of Proposed Law

Consequences of Assembly Bill 886. Google begins removing California news websites from some search results

11 hours ago

Tim Cook Says Apple Considering Factory In Indonesia

CEO Tim Cook during visit to Jakarta says Apple will look into building a manufacturing…

12 hours ago

Canada To Implement Digital Services Tax This Year

Introduction of digital services tax on tech firms will begin in 2024 Canadian government confirms,…

16 hours ago