Skip to main content

Google shuts down new Android spyware tied to cyberarms company

Android spyware
Image used with permission by copyright holder
Google on Wednesday discovered a new Android spyware named Lipizzan that can watch over and capture all activity on your phone — from phone calls to apps. Google took to its Android Developers blog to let users know the spyware has since been blocked, and that references to a cyberarms company called Equus Technologies were found in the spyware.

In April, Google found a similar spyware called Chrysaor that was believed to be written by another cyberarms company — NSO Group. Once installed, it would allow hackers to spy on the same information as Lipizzan — text messages, emails, and voice calls —  as well as the keys you typed on your device. Google was calling it “one of the most sophisticated and targeted mobile attacks” seen yet.

Recommended Videos

While researchers noted that no apps with Chrysaor were discovered on the Google Play store, Lipizzan had different results. On the blog post, Google explained the latest spyware was distributed through the Play Store in the form of what looked like a harmless “backup” app. Once installed, Lipizzan would download and enter a second stage called “license verification” to scan the infected device. If given permission to proceed, the spyware roots the device with known Android exploits and begins to send data from the device to a command and control server.

Using techniques similar to those used to find and block Chrysaor, Google managed to block the first set of apps on Google Play, but new apps were subsequently uploaded using a similar format. Instead of being marked as backup apps, they were labeled as cleaner alarm manager or sound recorder apps instead and uploaded within a week of the first set being taken down. Thecompany was still able to spot the new set of apps not too long after they were uploaded.

There were less than 100 devices that checked into Google Play Protect, created by the company that scans your device to keep it safe along with your data and apps. This means the spyware only affected an extremely small number of Android devices — 0.000007 percent to be exact. Since finding Lipizzan, Google Play Protect has removed it from any affected devices and is blocking the installs on new ones.

To make sure your own device is protected from Lipizzan, Google urges users to make sure they have opted into Google Play Protect. They should also download exclusively from the Google Play store and keep “unknown sources” disabled while not using it. Lastly, keep your phone up to date with the latest Android security update.

Brenda Stolyar
Former Digital Trends Contributor
Brenda became obsessed with technology after receiving her first Dell computer from her grandpa in the second grade. While…
Google Gemini is about to get a big upgrade for iPhone users
Person holding a phone with Google Gemini Live being shown.

Google Gemini, launched earlier this year for Android and iOS devices, has up until now only been available as a standalone app for Android users. In contrast, Apple users have had to access Google Gemini through the Google app. However, this situation is about to change.

As noted by 9to5Mac, at least one Apple user in the Philippines has been able to download the Google Gemini app from the App Store. However, it hasn’t appeared in other App Stores worldwide, including in the U.S.

Read more
Google may make it easier to share files between Android and iPhone
Android 14 logo on the Moto G Stylus 5G (2024).

Wish it was easier to share files between Android and iPhone? Android Authority says a file-sharing service designed for Android devices may eventually become available on Apple products.

During the Consumer Electronics Show (CES) in January, Google announced its collaboration with Samsung to introduce a new feature called Quick Share, which aims to simplify file sharing. This feature offers a unified solution for sharing files across Android devices, Chromebooks, and Windows systems, making the process seamless within these ecosystems. Think of it like AirDrop but for Android.

Read more
AI may soon make it easier to find the right Android app
Samsung Galaxy S24 in Marble Gray showing the Play Store.

Google may be planning to use its AI smarts to make it easier and faster to discover and learn more about apps in the Google Play Store. The first hints about a so-called Ask a Question feature have appeared inside the code of the Play Store app, and while details are thin at the moment, they do match Google’s AI efforts in its other apps.

The code discovered indicates the search and individual app pages in the Play Store may get a search bar powered by AI that will possibly display text saying “Ask a question about this app,” according to a report published by Android Authority that focused on a version of the Play Store app was torn down and examined. Code inside apps can often reveal features being tested internally before any public release.

Read more