Android malware found on Amazon Appstore disguised as health app

Share:

A malicious Android spyware application named ‘BMI CalculationVsn’ was discovered on the Amazon Appstore, masquerading as a simple health tool but stealing data from infected devices in the background.

The application was discovered by McAfee Labs researchers, who notified Amazon, leading to the application being removed from the store.

However, those who installed the app must manually remove it and perform a full scan to eliminate any leftover traces.

Android spyware on the Amazon store

The Amazon Appstore is a third-party app store for Android devices that comes pre-installed on Amazon Fire tablets and Fire TV devices.

It is also an alternative to Google Play for Android device owners who can’t or don’t want to use Google’s platform, even offering exclusive Amazon Prime games and content.

The BMI CalculationVsn spyware app, published by ‘PT Visionet Data Internasional,’ is promoted as a simple body mass index (BMI) calculator tool.

Spyware app
Spyware app on the Amazon Appstore
Source: McAfee

Opening the malicious app welcomes the user to a simple interface that provides the promised functionality, such as calculating their BMI. However, additional malicious actions are happening in the background.

First, the app starts a screen recording service that requests the appropriate permission when the user clicks the ‘Calculate’ button, which can be deceptive and trick people into reflex approvals.

Requesting permission to record the screen
Requesting permission to record the screen
Source: McAfee

McAfee says the recording is stored locally in an MP4 file but was not uploaded onto the command and control (C2) server, likely due to the app still being in an early testing development phase.

Code to record the device screen
Code to record the device screen
Source: McAfee

A little more digging into its release history by the researchers showed that the app first appeared in the wild on October 8. By the end of the month, it had changed its icon, added more malicious functions, and changed the certificate information.

The second malicious action performed by the app is scanning the device to retrieve all installed applications, allowing the attackers to plan their next steps.

Finally, the spyware intercepts and collects SMS messages sent and stored on the device, including one-time passwords (OTPs) and verification codes.

Stealing sensitive user data
Stealing sensitive user data
Source: McAfee

Given that dangerous apps can still slip through code review cracks in legitimate and otherwise trustworthy stores like the Amazon Appstore, it is important for Android users to only install apps from well-known publishers.

It is also recommended to scrutinize requested permissions and revoke risky ones even after installation.

Google Play Protect can detect and block known malware discovered by App Security Alliance partners, including McAfee, so keeping it active on Android devices is crucial.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
10:59 pm, Jun 17, 2025
weather icon 21°C
L: 19° | H: 22°
scattered clouds
Humidity: 60 %
Pressure: 1024 mb
Wind: 6 mph W
Wind Gust: 15 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 30%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:42 am
Sunset: 9:20 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 10:00 pm
weather icon
19° | 22°°C 0 mm 0% 8 mph 76 % 1025 mb 0 mm/h
Thu Jun 19 10:00 pm
weather icon
17° | 28°°C 0 mm 0% 11 mph 76 % 1026 mb 0 mm/h
Fri Jun 20 10:00 pm
weather icon
17° | 28°°C 0 mm 0% 12 mph 66 % 1026 mb 0 mm/h
Sat Jun 21 10:00 pm
weather icon
17° | 32°°C 0 mm 0% 10 mph 70 % 1022 mb 0 mm/h
Sun Jun 22 10:00 pm
weather icon
21° | 31°°C 0.2 mm 20% 15 mph 56 % 1016 mb 0 mm/h
Tomorrow 1:00 am
weather icon
17° | 19°°C 0 mm 0% 5 mph 63 % 1024 mb 0 mm/h
Tomorrow 4:00 am
weather icon
14° | 16°°C 0 mm 0% 4 mph 72 % 1025 mb 0 mm/h
Tomorrow 7:00 am
weather icon
16° | 16°°C 0 mm 0% 4 mph 76 % 1025 mb 0 mm/h
Tomorrow 10:00 am
weather icon
22° | 22°°C 0 mm 0% 4 mph 53 % 1025 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
25° | 25°°C 0 mm 0% 5 mph 40 % 1025 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
27° | 27°°C 0 mm 0% 8 mph 35 % 1024 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
26° | 26°°C 0 mm 0% 7 mph 40 % 1024 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
22° | 22°°C 0 mm 0% 5 mph 56 % 1025 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€90,372.64
-3.71%
Ethereum(ETH)
€2,177.19
-4.98%
Tether(USDT)
€0.86
-0.01%
XRP(XRP)
€1.87
-5.90%
Solana(SOL)
€127.94
-5.76%
USDC(USDC)
€0.86
-0.01%
Dogecoin(DOGE)
€0.146937
-5.29%
Shiba Inu(SHIB)
€0.000010
-5.19%
Pepe(PEPE)
€0.000009
-9.57%
Scroll to Top