Google, Lookout Detail 'Chrysaor' Android Malware, Related to Pegasus iOS Malware

Advertisement
By Shekhar Thakran | Updated: 5 April 2017 14:10 IST
Highlights
  • Infected apps were never made available through Google Plays
  • Chrysaor doesn't make use of zero-day vulnerabilities
  • New malware believed to be related to Pegasus

Researchers at Google and mobile security firm Lookout have now discovered that infamous iOS spyware Pegasus, which was described as sophisticated and discovered last year, has now turned up on Android in the form of 'Chrysaor'. Notably, the advanced form of malware can potentially give remote control of the device to the exploiter and even deletes itself, remove all traces.

Before you start getting uneasy, Google has clarified that the infected apps that carried the malware were never made available through Google Play store. Further, Google said that it tried to find the scope of Chrysaor by using Verify Apps, only to find that it had low volumes of installs outside Google Play. As per search giant, Israel-based NSO Group Technologies, which was behind the Pegasus malware is believed to be behind Chrysaor as well.

"Late last year, after receiving a list of suspicious package names from Lookout, we discovered that a few dozen Android devices may have installed an application related to Pegasus, which we named Chrysaor," Google said in a post. "Among the over 1.4 billion devices protected by Verify Apps, we observed fewer than 3 dozen installs of Chrysaor on victim devices," it added.

Advertisement

As per the search giant, the Chrysaor malware has been targeted at devices running Android 4.3 Jelly Bean or earlier versions.

Advertisement

Some of the spying functionalities in the Chrysaor malware include keylogging, screenshot capture, Live audio capture, remote control of the malware via SMS, browser history exfiltration, email exfiltration from Android's native email client, contacts and text message, as per Lookout. It also enables messaging data exfiltration from common applications including WhatsApp, Skype, Facebook, Twitter, Viber, Kakao.

The Chrysaor malware self destructs itself when it finds its position in danger and meets certain conditions, Lookout points out. "It's clear that this malware was built to be stealthy, targeted, and is very sophisticated," Lookout said in its post regarding the malware.

Advertisement

The most notable difference between Chrysaor on Android and Pegasus on iOS is that the former doesn't use zero-day vulnerabilities to root the device. Chrysaor instead uses a well-known rooting technique called Framaroot.

"In the case of Pegasus for iOS, if the zero-day attack execution failed to jailbreak the device, the attack sequence failed overall. In the Android version, however, the attackers built in functionality that would allow Pegasus for Android to still ask for permissions that would then allow it to access and exfiltrate data. The failsafe jumps into action if the initial attempt to root the device fails," Lookout said.

Advertisement

As the Chrysaor malware has not been distributed at large scale, majority of Android devices are out of danger but we would like to warn our readers who are using Android not to install apps from unverified sources in order to keep their devices secure

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. Vivo X300 FE Reportedly Bags IMDA and TUV Certifications Ahead of Launch
  2. Lava Bold N2 Will Be Launched in India on This Date: See Expected Specs
  3. Xiaomi 17 Series Leak Hints at Imminent Launch Ahead of MWC at These Prices
  4. Samsung Galaxy S26+ Reportedly Listed for Sale Online Ahead of Launch
  5. Oppo K14x 5G With 6,500mAh Battery Goes on Sale in India: See Price, Offers
  6. Apple to Reportedly Launch Low-Cost MacBook in 'Playful Colors' in March
  7. Poco X8 Pro Spotted on Geekbench With This Dimensity 8000 Series Chipset
  8. Samsung's 'Wide' Galaxy Z Fold Design Spotted in Leaked One UI 9 Animations
  9. Kingdom Come: Deliverance Gets a Next-Gen Update on PS5, Xbox Series S/X
  1. Sony Could Reportedly Delay PS6 to as Late as 2029 Due to RAM Shortage
  2. iPhone 18 Series to Drop SIM Card Slot in Europe to Make Room for Slightly Larger Battery: Report
  3. Poco X8 Pro Spotted on Geekbench With MediaTek Dimensity 8500 Ultra SoC, Android 16
  4. Xiaomi 17, Xiaomi 17 Ultra Global Price Details, Launch Date and Colour Options Leaked
  5. X Building Smart 'Cashtags' to Let Users Check Cryptocurrency Prices in Real-Time
  6. Samsung Galaxy A27 5G Listing on IMEI Database Suggests a Galaxy A26 Successor Is on the Way
  7. Anthropic Inaugurates First Indian Office in Bengaluru, Starts Hiring Local Talent
  8. Apple Tipped to Adopt Samsung's Privacy Display Technology for MacBook Models by 2029
  9. Oppo Find X10 Series Tipped to Launch in H2 2026 With Built-In Magnets for Wireless Charging
  10. AMD and TCS to Co-Develop Helios AI Data Centre Architecture, Deliver 200MW Data Centre Blueprint
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.