The presence of malicious apps in the Google Play Store is not a new problem, and even more so in APKs downloaded in the wild. Recently, the security unit Lab52 discovered that a seemingly innocent-looking Android application APK contained the latest threat. According to the unit’s report, this malicious application may be related to the Russian hacker group Turla and has all-encompassing capabilities.

Security agencies have discovered spyware that can almost completely take over Android phones, beware!
The new malware was first discovered in a seemingly unrelated app called “Roz Dhan: Earn Wallet cash”. Lab52 ResearchAccording to the article, once you download this harmless surface-level app, a second app containing malicious spyware will appear on your Android phone under the name “Process Manager” and use a gear icon to make it look like the official Settings app.


Malicious applications can control the camera, microphone, lock screen, storage encryption, etc. of an Android device. As long as the user’s permission is obtained, the application icon related to the spyware may disappear from the foreground and continue to run in the background. At the same time, it can control or otherwise monitor the functions of the victim device from the inside out, without even using any backdoor or opportunistic means.

According to Lab52, this malicious application can be said to have complete control over the Android device. Because the list of processes it affects is very extensive, the malicious application can secretly record your every move through the camera or microphone, send messages by itself, read text messages, monitor phone calls, and even read information from external devices connected to the victim device. Here are the permissions this malware requires, 18 of them:
| license | use |
| ACCESS_COARSE_LOCATION | Access your phone’s location |
| ACCESS_FINE_LOCATION | Access location with GPS |
| ACCESS_NETWORK_STATE | View all network status |
| ACCESS_WIFI_STATE | View wireless network information |
| CAMERA | Take photos and videos from your camera |
| FOREGROUND_SERVICE | Allowed to appear in foreground |
| INTERNET | Allow creation of network sockets |
| MODIFY_AUDIO_SETTINGS | Allow modification of audio settings |
| REAL_CALL_LOG | Allow reading of call logs |
| READ_CONTACTS | Allow reading contact information |
| READ_EXTERNAL_STORAGE | Allow reading of external storage devices |
| WRITE_EXTERNAL_STORAGE | Allow writing to memory card |
| READ_PHONE_STATE | Allow reading phone status and ID |
| READ_SMS | Allows reading text messages stored on the SIM card |
| RECEIVE_BOOT_COMPLETED | Allow applications to launch when the device is turned on |
| RECORD_AUDIO | access recorder |
| SEND_SMS | Allow text messages |
| WAKE_LOG | Prevent device from locking/sleeping |
The best way to combat this particular form of spyware is to not grant it any permissions in the first place. In fact, it is the most basic precaution to be extra vigilant about any application downloaded from unfamiliar and unreliable sources, and to always pay close attention to the authorization requests issued by each application at any time. But if you have installed malware similar to “Process Manager” and have given it permission, although it will not be displayed in regular mode, deleting it is a top priority. For example, the “Process Manager” mentioned above is displayed as an active process in the notification bar of the phone, which then provides you with the opportunity to stop its operation and delete it.

Your other option is to open your Android phone’s permission settings and revoke anything that looks suspicious (path: Settings >> Privacy >> Permission Manager). In this particular case, it may not all show up under the “Process Manager” heading. This method won’t remove the spyware, but it will cut it off and render it essentially useless, which is a more cautious short-term approach if you’re worried about accidentally deleting any important programs.

Source: KOCPC Chinese