Android malware found on Amazon Appstore disguised as health app

Share:

A malicious Android spyware application named ‘BMI CalculationVsn’ was discovered on the Amazon Appstore, masquerading as a simple health tool but stealing data from infected devices in the background.

The application was discovered by McAfee Labs researchers, who notified Amazon, leading to the application being removed from the store.

However, those who installed the app must manually remove it and perform a full scan to eliminate any leftover traces.

Android spyware on the Amazon store

The Amazon Appstore is a third-party app store for Android devices that comes pre-installed on Amazon Fire tablets and Fire TV devices.

It is also an alternative to Google Play for Android device owners who can’t or don’t want to use Google’s platform, even offering exclusive Amazon Prime games and content.

The BMI CalculationVsn spyware app, published by ‘PT Visionet Data Internasional,’ is promoted as a simple body mass index (BMI) calculator tool.

Spyware app
Spyware app on the Amazon Appstore
Source: McAfee

Opening the malicious app welcomes the user to a simple interface that provides the promised functionality, such as calculating their BMI. However, additional malicious actions are happening in the background.

First, the app starts a screen recording service that requests the appropriate permission when the user clicks the ‘Calculate’ button, which can be deceptive and trick people into reflex approvals.

Requesting permission to record the screen
Requesting permission to record the screen
Source: McAfee

McAfee says the recording is stored locally in an MP4 file but was not uploaded onto the command and control (C2) server, likely due to the app still being in an early testing development phase.

Code to record the device screen
Code to record the device screen
Source: McAfee

A little more digging into its release history by the researchers showed that the app first appeared in the wild on October 8. By the end of the month, it had changed its icon, added more malicious functions, and changed the certificate information.

The second malicious action performed by the app is scanning the device to retrieve all installed applications, allowing the attackers to plan their next steps.

Finally, the spyware intercepts and collects SMS messages sent and stored on the device, including one-time passwords (OTPs) and verification codes.

Stealing sensitive user data
Stealing sensitive user data
Source: McAfee

Given that dangerous apps can still slip through code review cracks in legitimate and otherwise trustworthy stores like the Amazon Appstore, it is important for Android users to only install apps from well-known publishers.

It is also recommended to scrutinize requested permissions and revoke risky ones even after installation.

Google Play Protect can detect and block known malware discovered by App Security Alliance partners, including McAfee, so keeping it active on Android devices is crucial.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
3:08 am, Mar 7, 2025
weather icon 10°C
L: 9° | H: 11°
overcast clouds
Humidity: 78 %
Pressure: 1011 mb
Wind: 3 mph SE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 6:32 am
Sunset: 5:50 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
9° | 11°°C 0 mm 0% 11 mph 84 % 1012 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
9° | 14°°C 0 mm 0% 10 mph 78 % 1011 mb 0 mm/h
Sun Mar 09 9:00 pm
weather icon
9° | 16°°C 0 mm 0% 9 mph 80 % 1005 mb 0 mm/h
Mon Mar 10 9:00 pm
weather icon
7° | 13°°C 0 mm 0% 12 mph 87 % 1005 mb 0 mm/h
Tue Mar 11 9:00 pm
weather icon
4° | 7°°C 1 mm 100% 14 mph 91 % 1008 mb 0.13 mm/h
Today 6:00 am
weather icon
9° | 10°°C 0 mm 0% 7 mph 84 % 1011 mb 0 mm/h
Today 9:00 am
weather icon
11° | 11°°C 0 mm 0% 9 mph 80 % 1012 mb 0 mm/h
Today 12:00 pm
weather icon
15° | 15°°C 0 mm 0% 11 mph 63 % 1012 mb 0 mm/h
Today 3:00 pm
weather icon
14° | 14°°C 0 mm 0% 10 mph 64 % 1012 mb 0 mm/h
Today 6:00 pm
weather icon
13° | 13°°C 0 mm 0% 7 mph 71 % 1012 mb 0 mm/h
Today 9:00 pm
weather icon
12° | 12°°C 0 mm 0% 7 mph 72 % 1012 mb 0 mm/h
Tomorrow 12:00 am
weather icon
10° | 10°°C 0 mm 0% 6 mph 73 % 1011 mb 0 mm/h
Tomorrow 3:00 am
weather icon
9° | 9°°C 0 mm 0% 6 mph 71 % 1010 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€80,969.67
-4.90%
Ethereum(ETH)
€1,998.64
-5.68%
XRP(XRP)
€2.31
-1.28%
Tether(USDT)
€0.93
0.01%
Solana(SOL)
€130.55
-5.47%
USDC(USDC)
€0.93
0.00%
Dogecoin(DOGE)
€0.182794
-4.95%
Shiba Inu(SHIB)
€0.000012
-1.68%
Pepe(PEPE)
€0.000006
-5.97%
Peanut the Squirrel(PNUT)
€0.201372
5.99%
Scroll to Top