Android malware found on Amazon Appstore disguised as health app

Share:

A malicious Android spyware application named ‘BMI CalculationVsn’ was discovered on the Amazon Appstore, masquerading as a simple health tool but stealing data from infected devices in the background.

The application was discovered by McAfee Labs researchers, who notified Amazon, leading to the application being removed from the store.

However, those who installed the app must manually remove it and perform a full scan to eliminate any leftover traces.

Android spyware on the Amazon store

The Amazon Appstore is a third-party app store for Android devices that comes pre-installed on Amazon Fire tablets and Fire TV devices.

It is also an alternative to Google Play for Android device owners who can’t or don’t want to use Google’s platform, even offering exclusive Amazon Prime games and content.

The BMI CalculationVsn spyware app, published by ‘PT Visionet Data Internasional,’ is promoted as a simple body mass index (BMI) calculator tool.

Spyware app
Spyware app on the Amazon Appstore
Source: McAfee

Opening the malicious app welcomes the user to a simple interface that provides the promised functionality, such as calculating their BMI. However, additional malicious actions are happening in the background.

First, the app starts a screen recording service that requests the appropriate permission when the user clicks the ‘Calculate’ button, which can be deceptive and trick people into reflex approvals.

Requesting permission to record the screen
Requesting permission to record the screen
Source: McAfee

McAfee says the recording is stored locally in an MP4 file but was not uploaded onto the command and control (C2) server, likely due to the app still being in an early testing development phase.

Code to record the device screen
Code to record the device screen
Source: McAfee

A little more digging into its release history by the researchers showed that the app first appeared in the wild on October 8. By the end of the month, it had changed its icon, added more malicious functions, and changed the certificate information.

The second malicious action performed by the app is scanning the device to retrieve all installed applications, allowing the attackers to plan their next steps.

Finally, the spyware intercepts and collects SMS messages sent and stored on the device, including one-time passwords (OTPs) and verification codes.

Stealing sensitive user data
Stealing sensitive user data
Source: McAfee

Given that dangerous apps can still slip through code review cracks in legitimate and otherwise trustworthy stores like the Amazon Appstore, it is important for Android users to only install apps from well-known publishers.

It is also recommended to scrutinize requested permissions and revoke risky ones even after installation.

Google Play Protect can detect and block known malware discovered by App Security Alliance partners, including McAfee, so keeping it active on Android devices is crucial.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
3:45 am, Apr 3, 2025
weather icon 9°C
L: 8° | H: 10°
scattered clouds
Humidity: 79 %
Pressure: 1019 mb
Wind: 6 mph E
Wind Gust: 12 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 35%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 6:30 am
Sunset: 7:36 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
8° | 10°°C 0 mm 0% 12 mph 80 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
10° | 18°°C 0 mm 0% 14 mph 86 % 1021 mb 0 mm/h
Sat Apr 05 10:00 pm
weather icon
7° | 17°°C 0 mm 0% 12 mph 73 % 1022 mb 0 mm/h
Sun Apr 06 10:00 pm
weather icon
7° | 14°°C 0 mm 0% 12 mph 81 % 1025 mb 0 mm/h
Mon Apr 07 10:00 pm
weather icon
6° | 14°°C 0 mm 0% 9 mph 77 % 1028 mb 0 mm/h
Today 4:00 am
weather icon
8° | 9°°C 0 mm 0% 9 mph 79 % 1019 mb 0 mm/h
Today 7:00 am
weather icon
8° | 9°°C 0 mm 0% 10 mph 80 % 1019 mb 0 mm/h
Today 10:00 am
weather icon
12° | 14°°C 0 mm 0% 11 mph 69 % 1020 mb 0 mm/h
Today 1:00 pm
weather icon
18° | 18°°C 0 mm 0% 12 mph 48 % 1020 mb 0 mm/h
Today 4:00 pm
weather icon
18° | 18°°C 0 mm 0% 11 mph 55 % 1019 mb 0 mm/h
Today 7:00 pm
weather icon
14° | 14°°C 0 mm 0% 8 mph 64 % 1020 mb 0 mm/h
Today 10:00 pm
weather icon
13° | 13°°C 0 mm 0% 7 mph 71 % 1021 mb 0 mm/h
Tomorrow 1:00 am
weather icon
11° | 11°°C 0 mm 0% 5 mph 80 % 1021 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€77,045.70
-1.39%
Ethereum(ETH)
€1,683.66
-2.87%
Tether(USDT)
€0.92
-0.01%
XRP(XRP)
€1.89
-1.81%
Solana(SOL)
€110.76
-3.47%
USDC(USDC)
€0.92
0.01%
Dogecoin(DOGE)
€0.152964
-2.74%
Shiba Inu(SHIB)
€0.000011
0.02%
Pepe(PEPE)
€0.000006
-4.06%
Scroll to Top