Google Says It Found a 'Socially Engineered' Spyware App Family on the Play Store

Advertisement
By Press Trust of India | Updated: 29 November 2017 20:27 IST

Google on Monday said it had detected an app called Tizi on Google Play that had been stealing information from call records and also from social media apps like Facebook, WhatsApp, and also take pictures from mobile phones without even displaying them on screen of the device.

"Tizi is a fully featured backdoor that installs spyware to steal sensitive data from popular social media applications. The Google Play Protect security team discovered this family in September 2017 when device scans found an app with rooting capabilities that exploited old vulnerabilities," a post on Google security blog said.

The company has removed the app from Play Store, notified all known affected devices and suspended the account of the app developer, the post revealed.

Advertisement

The post said that an earlier variant of Tizi did not have rooting capabilities but it was developed later on and thereafter started stealing sensitive information from devices.

Advertisement

"The rooting capabilities give an app full control of the device. It can bypass all restriction posed on it by Android security system. An app with rooting is like a user using the device. Presence of such app on Google Play Store raises concerns around secure apps on the app store," cybersecurity expert Jiten Jain said.

The post said that after gaining rooting capability, Tizi steals sensitive data "from popular social media apps like Facebook, Twitter, WhatsApp, Viber, Skype, LinkedIn, and Telegram."

Advertisement

The backdoor capability of Tizi were common to commercial spyware, such as recording calls from WhatsApp, Viber, and Skype, sending and receiving SMS messages, and accessing calendar events, call log, contacts, photos, Wi-Fi encryption keys, and a list of all installed apps

"Tizi apps can also record ambient audio and take pictures without displaying the image on the device's screen," the post said.

Advertisement

The post said that in and after April 2016, vulnerabilities in devices which could have been affected by Tizi were fixed with new software code.

"If a Tizi app is unable to take control of a device because the vulnerabilities it tries to use are are all patched, it will still attempt to perform some actions through the high level of permissions it asks the user to grant to it, mainly around reading and sending SMS messages and monitoring, redirecting, and preventing outgoing phone calls," the post said.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. ACT Fibernet Launches New Broadband Plans With Free OTT Subscriptions
  2. OnePlus 15R Surfaces on Benchmarking Site Ahead of India Launch
  3. Motorola Edge 70 With Pantone's 2026 Colour, Swarovski Crystals Launched
  4. Flipkart Buy Buy 2025 Sale: Nothing Phone 3, Phone 3a Deals Revealed
  5. Flipkart Buy Buy 2025 Sale With Discounts on iPhone 16 Begins on This Date
  6. Samsung May Limit Exynos 2600 to South Korea's Galaxy S26 Units
  7. HMD 101, HMD 100 With Built-In Radio Launched in India at These Prices
  8. Apple Announces App Store Awards 2025 Winners: Check List
  9. Realme Watch 5 Launched in India With Up to 16-Day Battery Life: See Price
  1. NotebookLM App Gets an In-Built Camera, Lets Users Upload Images as a Source
  2. HMD 101 Launched in India With 1,000mAh Battery, Auto Call Recording Alongside HMD 100: Price, Features
  3. Crypto Traders Await US Fed Signals as Bitcoin Price Drops to $91,900
  4. Nothing Phone 3a Lite Goes on Sale in India: See Price, Offers, Availability
  5. Realme Narzo Phones Confirmed to Launch in India Soon via Amazon
  6. Samsung Galaxy Watch Ultra 2 Launch Timeline Leaked; Could Debut Alongside Samsung Galaxy Watch 9
  7. Samsung Galaxy S26 Series May Get Exynos 2600 Chipset Exclusively in South Korea: Report
  8. Apple’s FaceTime Reportedly Blocked in Russia Alongside Snapchat’s Video Calling Feature
  9. Anthropic Releases New Claude Tool That Interviews Users About Their AI Usage
  10. ACT Fibernet Launches Revamped Broadband Plans Starting at Rs. 499
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.