Recently, security researchers discovered two file management apps on Google Play that had a combined install count of more than 1.5 million times and collected far more user data than was necessary for the functionality provided by the apps. Both apps are from the same publisher and can be launched without user interaction, stealing sensitive data and sending it to servers in China.

Two file management apps with a combined installed base of over 1.5 million steal sensitive user data and send them to China
according to Report by Bleeping Computer, security researchers have reported the issue to Google, and both apps have been removed from the Google Play Store. The “File Recovery & Data Recovery” app is labeled “com.spot.music.filed” on the device and has more than 1 million installations in total; the “File Manager” app is labeled “com.file.box.master.gkd” and has more than 500,000 installations.

Both apps are developed by Mobile Security Solutions Inc. Pradeo’s Behavioral Analytics Engine Discovery, they write in the Google Play Store’s About Data section that they do not collect any user information from the device.

But Pradeo found that this was not the case at all, and two mobile applications leaked the following data from the device:
- User contact lists from device memory, connected email accounts, and social networks.
- Pictures, audio and videos managed or restored from the application.
- User’s real-time location
- Phone country code
- Internet provider name
- SIM card provider’s network code
- Operating system version number
- Device make and model
While applications may have legitimate reasons to collect the data mentioned above to ensure good performance and compatibility, much of this data is not necessary for file management or data recovery functions, and what’s even worse is that this data is secretly collected without the user’s consent. Pradeo added that both apps hide their home screen icons, making it harder for you to find and delete them. They can also abuse authorizations approved by the user during installation to reboot the device and run in the background.

Pradeo speculates that publishers are likely using emulators or install farms to increase install numbers to increase popularity and make their products appear more trustworthy. This theory is supported by the fact that the number of user reviews on the Play Store is too small compared to the installed user base. We recommend reading user reviews before installing an app, paying attention to what permissions the app asks you to grant during the app installation process, and only trusting software from reputable developers and publishers.
Source: KOCPC Chinese