logo

Android Spyware SMSVova found on Google Play Store

ID: d7f91c53-ccbd-5783-8b10-bc8bdff31ae2

STIX ID: report--d7f91c53-ccbd-5783-8b10-bc8bdff31ae2

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabz discovered an Android app named "System Update" on Google Play (1–5M installs) that masqueraded as a system update but operated as SMS-controlled spyware: it set up a location service and SMS receiver, accepted commands like "get faq" and a default password "Vova", and could exfiltrate real-time geolocation to an attacker; Google removed the app after disclosure and code similarities to DroidJack were observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.