Lipizzan Spyware Detected by Google Had the Potential to Control Your Android Device

Advertisement
By Sanket Vijayasarathy | Updated: 28 July 2017 13:56 IST
Highlights
  • New spyware could control your Android device
  • Spyware was found hiding inside harmless apps like ‘Backup’ or ‘Cleaner’
  • Google Play Protect has managed to remove the malware

Back in April, researchers at Google discovered an Android malware, called Chrysaor, that could give an attacker remote control of the infected device. Android Security was able to find and block potentially harmful apps (PHAs) with that family of spyware, but in the process of doing so discovered a new spyware family called Lipizzan.

Researchers believe that the new spyware is unrelated to Chrysaor, and has the ability to monitor and exfiltrate a user's email, SMS messages, location, voice calls, and media. The code behind the spyware has been traced to a cyber arms company, Equus Technologies.

On the Android Developers blog, researchers say that the newly discovered spyware works in two stages. It is firstly distributed through several channels, including Google Play, and hides behind a harmless app like "Backup" or "Cleaner". After installing such an app, Lipizzan would load a second "licence verification" stage, which check out the infected device and validates certain abort criteria. Once the all-clear is given, the spyware proceeds to root the device with known exploits to take control of the device and exfiltrate data to a Command & Control server.

Advertisement

Once Lipizzan gains full control of the infected device, it has the ability to record call, track the user's location, take screenshots and photos with the device's camera, fetch information and files stored in the device and other user information such as contact, call logs and more. Researchers say that the PHA had specific routines to retrieve data from apps like Gmail, LinkedIn, Skype, Snapchat, and WhatsApp.

Advertisement

The most notable thing about the new spyware is how easily the authors can change the branding of the implanted apps. Soon after Google detected and blocked the first set of apps on Google Play, new apps began cropping up with the same spyware. These apps changed from 'backup' apps to apps like "cleaner", "notepad", "sound recorder", to name a few. Google says that it has so far detected the spyware in fewer than 100 devices that checked into Google Play Protect. Now that Lipizzan is detected, Google Play Protect has managed to remove the family from affected devices and will block installs on new devices.

Google says that Android users can protect themselves by making sure they opt into Google Play Protect, and making sure apps are downloaded exclusively from Google Play. The company also urges users to keep their phones patched to the latest Android security update.

Advertisement

There have been a bunch of Android malware-related reports such as SpyDealer, LeakerLocker, and CopyCat in recent months that have raised an alarming concern over the safety of the platform and the potential risks of storing personal information over the digital space.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Motorola Edge 70 Launched With Snapdragon 7 Gen 4 SoC, Slim 5.99mm Profile
  2. Apple's Low-Cost MacBook Launch Timeline, Price Leaked Ahead of Debut
  3. Lava Agni 4 Price Range, Features Leaked; Will Launch in These Colourways
  4. Realme UI 7.0 Launched With Light Glass Design, AI Features
  5. Samsung Galaxy S26 Ultra Spotted in Leaked Renders With Rounder Corners
  6. Moto G Play (2026), Moto G (2026) With Dimensity 6300 SoC Launched
  7. Moto G67 Power 5G Launched in India With 7,000mAh Battery: See Price
  8. WhatsApp's Apple Watch App Is Finally Out: Check Features, Compatibility
  9. Amazon Demands Perplexity Stop AI Tool From Making Purchases
  10. NASA Confirms Plans to Retire and Deorbit the ISS Over Point Nemo
  1. Moto G57 Power With 7,000mAh Battery Launched Alongside Moto G57: Price, Specifications
  2. Steam Deck Gets a Display-Off Low-Power Mode for Downloads Three Years After Launch
  3. Snapdragon 8 Elite Gen 6 Leak Hints at Two Variants Including 'Pro' Model
  4. Realme Will Try to Absorb Increased Cost of Components Ahead of Upcoming Product Launches, Executive Says
  5. Motorola Edge 70 Launched With Snapdragon 7 Gen 4 Chipset, Slim 5.99mm Profile: Price, Specifications
  6. Researchers Unveil How Atomic Entanglement Enhances Light Bursts
  7. Lava Agni 4 Confirmed to Launch in Two Colourways; Tipster Leaks Price Range, Key Features
  8. Google Proposes Play Store Reforms in Settlement With Fortnite Maker Epic Games
  9. Scientists Recreate Cosmic ‘Fireballs’ in Lab to Solve Mystery of Missing Gamma Rays
  10. Realme UI 7.0 Launched With Light Glass Design, AI Notify Brief and AI Gaming Coach: See Eligible Phones, Beta Release Schedule
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.