Skip to main content

Google takes down Android app that let hackers control your phone through SMS

android spyware works through text smartphone cellphone hacking frustration
Image used with permission by copyright holder
An internet security company has published its findings on an Android app that contained spyware controlled via text messages. Researchers at Zscaler have determined an app suspiciously titled “System Update” gave attackers the ability to execute commands on a remote device and receive its location data. The app — which was just deleted on Google Play Store — had been available for the last three years, and was listed as having been downloaded anywhere from 1 million to 5 million times.

The reviews all indicate users had been installing System Update believing, unsurprisingly, that it would update the version of Android on their device. Instead, when opened for the first time, the app would display the standard system error message — “Unfortunately, System Update has stopped” — and remove itself from the app drawer.

This would activate the spyware, named SMSVova, and set things into motion. SMSVova fetches the user’s location data and begins reading text messages, looking for an SMS message that reads “get faq.” If another device texts “get faq” to the infected party, the latter will automatically respond with a list of commands. By texting these commands to the affected device, the attacker could remotely lock the phone with a password or even issue fake low-battery warnings.

At this point, the attacker is given total access to the coordinates of the infected phone. Although the app is no longer available to download from Google’s marketplace, Zscaler reports it found the code living in another remote access program, called DroidJack.

There is of course no shortage of ways in which an unscrupulous hacker could gain access into your phone, especially with the help of user-installed software. But this is certainly one of the more interesting methods. It’s also quite frightening, considering it gives the attacker so much power through the seemingly harmless and unsophisticated medium of text messages. Then again, in light of the deadly string of emojis that can incapacitate an iPhone, perhaps we shouldn’t be so surprised.

Editors' Recommendations

Adam Ismail
Former Digital Trends Contributor
Adam’s obsession with tech began at a young age, with a Sega Dreamcast – and he’s been hooked ever since. Previously…
Your next Samsung phone might ditch Google Search for Bing
The screens on the Galaxy A54 and Galaxy S23 Ultra.

When you buy an Android phone, you expect Google Search to be installed out of the box as the default search engine. But that may not be the case when you buy your next Samsung phone. According to a report over the weekend, Samsung might abandon Google Search in favor of Bing as the default search engine for future Samsung Galaxy phones.

The possibility that Samsung is considering replacing Google Search with Bing on its smartphones sent Google into a "panic," according to the New York Times, Why? As the report explains, "An estimated $3 billion in annual revenue is at stake with the Samsung contract." If Samsung doesn't want to keep using Google for the default search engine on its phones, that's $3 billion per year Google will no longer get. And if Samsung decides it wants Bing instead of Google, who knows how many other companies will follow suit and do the same.
Why Samsung wants Bing over Google

Read more
Your Google One plan just got 2 big security updates to keep you safe online
Two Google Pixel 7 Pro smartphones.

Google just added some major new security features to keep its Google One subscribers safe while on the web. After all, the internet is where you spend a lot of your time, whether that's looking things up, paying bills, shopping, booking appointments, or sharing photos with family and friends. That’s a lot of information, and Google wants to keep subscribers safe from the darker side of the web.

Regardless of whether you use an iPhone or an Android smartphone, all Google One subscribers are getting the following two security features.
VPN by Google One for everyone

Read more
Our 5 favorite iPhone and Android apps by Black developers
An iPhone with apps from Black developers downloaded on it.

As we wrap up the celebration of 2023's Black History Month, it remains important to recognize and appreciate the contributions that Black people have made in various fields, including technology and the smartphone apps we use every day. From social media platforms to productivity tools, Black developers and other people of color have worked hard to create innovative, useful, and just plain fun apps.

Here, we're focusing on five helpful apps developed by Black people that you should check out. These iPhone and Android apps range from ones that help you discover and support Black-owned businesses to ones that provide legal assistance in case of an emergency to ones that curate and highlight sources of news and entertainment by Black creators.
We Read Too

Read more