Android Malware Linked to Russian Attackers Discovered, Can Record Audio and Track Your Location

Named Process Manager, the malware runs in the background once installed.

Advertisement
By Jagmeet Singh | Updated: 4 April 2022 18:42 IST
Highlights
  • Android malware uses the same infrastructure that is linked to Turla
  • It is installed as an app but works in the background
  • The malware converts user data into JSON for sharing with hackers

Android users should be careful while installing any new apps on their devices

Photo Credit: Unsplash/ Pathum Danthanarayana

A new Android malware has been detected and detailed by a team of security researchers that records audio and tracks location once planted in the device. The malware uses the same shared-hosting infrastructure that was previously found to be used by a team of Russian hackers known as Turla. However, it is unclear whether the Russian state-supported group has a direct relation with the newly discovered malware. It reaches through a malicious APK file that works as an Android spyware and performs actions in the background, without giving any clear references to users.

Researchers at threat intelligence firm Lab52 have identified the Android malware that is named Process Manager. Once installed, it appeared on the device's app drawer as a gear-shaped icon — disguised as a preloaded system service.

The researchers found that the app asks for a total of 18 permission when run for the first time on the device. These permissions include access to the phone location, Wi-Fi information, take pictures and videos from the inbuilt camera sensors, and voice recorder to record audio.

Advertisement

It is not clear whether the app receives permissions by abusing the Android Accessibility service or by tricking users to grant their access.

Advertisement

However, after the malicious app runs for the first time, its icon is removed from the app drawer. The app, though, still runs in the background, with its active status available in the notification bar.

The researchers noticed that the app configures the device on the basis of the permissions it receives to start executing a list of tasks. These include the details about the phone on which it has been installed as well as the ability to record audio and collect information including Wi-Fi settings and contacts.

Advertisement

Particularly on the audio recording part, the researchers discovered that the app records audio from the device and extracts it in the MP3 format in the cache directory.

The malware collects all the data and sends it in JSON format to a server that is located in Russia.

Advertisement

Although the exact source from which the malware reaches the devices is unknown, the researchers found that its creators have abused the referral system of an app called Roz Dhan: Earn Wallet Cash that is available for download on Google Play and has over 10 million downloads. The malware is said to download the legitimate app that eventually helps attackers install it on the device and makes profit out of its referral system.

It seems relatively uncommon for spyware since the attackers seem to be focused on cyber espionage. As Bleeping Computer notes, the strange behaviour of downloading an app to earn commissions from its referral system suggests that malware could be a part of a larger system that is yet to be discovered.

That said, Android users are recommended to avoid installing any unknown or suspicious apps on their devices. Users should also review the app permissions they grant to limit access of third parties to their hardware.


Can OnePlus 10 Pro beat iPhone 13 Pro and Galaxy S22 Ultra? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. Motorola Unveils Signature Phone With Four 50-Megapixel Cameras
  2. Redmi Pad 2 Pro 5G With 12,000mAh Battery Arrives in India: See Price
  3. Motorola Unveils Razr Fold as its First Book-Style Foldable at CES
  4. Realme 16 Pro Series With 7,000mAh Battery Debuts in India: See Price
  5. Redmi Note 15 5G First Impressions
  6. CES 2026: Motorola Enters the Wearable AI Race With Project Maxwell
  7. iQOO Z11 Key Specifications Confirmed Ahead of Imminent Launch in China
  8. Vivo Y50s 5G, Vivo Y50e 5G Launched With 6,000mAh Battery: Price, Features
  9. Vivo X200T Said to Launch in India With 'Aggressive' Pricing
  10. Realme 16 Pro+, Realme 16 Pro Review: A New Dawn for Realme
  1. Lenovo Legion Go 2 SteamOS Version Revealed at CES 2026, Will Be Available From June 2026
  2. Motorola Unveils Unified AI Platform and AI Pin-Styled Wearable Device Prototype at CES 2026
  3. iQOO Z11 Turbo Battery, Charging Details Confirmed; Tipster Leaks Camera Specifications
  4. CES 2026: Eureka Z50, E10 Evo Plus Robot Vacuum Cleaners Launched, FloorShine 890 Tags Along
  5. Motorola Unveils Signature Phone With Snapdragon 8 Gen 5 Chip and 50-Megapixel Sony LYTIA Cameras: Price, Specifications
  6. CES 2026: Motorola Razr Fold Announced With 2K LTPO Inner Display, 50-Megapixel Triple Cameras
  7. Self-Driving Cars Could Prevent Over 1 Million Road Injuries Across the U.S. by 2035
  8. Astronomers Measure Mass and Distance of a Rogue Planet for the First Time in History
  9. The Rip OTT Release Date: When and Where to Watch it Online?
  10. Netflix’s One Last Adventure Takes Fans Inside the Making of Stranger Things 5
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.