Skip to main content

Google shuts down new Android spyware tied to cyberarms company

Android spyware
Image used with permission by copyright holder
Google on Wednesday discovered a new Android spyware named Lipizzan that can watch over and capture all activity on your phone — from phone calls to apps. Google took to its Android Developers blog to let users know the spyware has since been blocked, and that references to a cyberarms company called Equus Technologies were found in the spyware.

In April, Google found a similar spyware called Chrysaor that was believed to be written by another cyberarms company — NSO Group. Once installed, it would allow hackers to spy on the same information as Lipizzan — text messages, emails, and voice calls —  as well as the keys you typed on your device. Google was calling it “one of the most sophisticated and targeted mobile attacks” seen yet.

Recommended Videos

While researchers noted that no apps with Chrysaor were discovered on the Google Play store, Lipizzan had different results. On the blog post, Google explained the latest spyware was distributed through the Play Store in the form of what looked like a harmless “backup” app. Once installed, Lipizzan would download and enter a second stage called “license verification” to scan the infected device. If given permission to proceed, the spyware roots the device with known Android exploits and begins to send data from the device to a command and control server.

Please enable Javascript to view this content

Using techniques similar to those used to find and block Chrysaor, Google managed to block the first set of apps on Google Play, but new apps were subsequently uploaded using a similar format. Instead of being marked as backup apps, they were labeled as cleaner alarm manager or sound recorder apps instead and uploaded within a week of the first set being taken down. Thecompany was still able to spot the new set of apps not too long after they were uploaded.

There were less than 100 devices that checked into Google Play Protect, created by the company that scans your device to keep it safe along with your data and apps. This means the spyware only affected an extremely small number of Android devices — 0.000007 percent to be exact. Since finding Lipizzan, Google Play Protect has removed it from any affected devices and is blocking the installs on new ones.

To make sure your own device is protected from Lipizzan, Google urges users to make sure they have opted into Google Play Protect. They should also download exclusively from the Google Play store and keep “unknown sources” disabled while not using it. Lastly, keep your phone up to date with the latest Android security update.

Brenda Stolyar
Former Digital Trends Contributor
Brenda became obsessed with technology after receiving her first Dell computer from her grandpa in the second grade. While…
Your Google Maps app is about to look different. Here’s what’s changing
Screenshot of the new teal color in the Google Maps app.

If you own an Android device such as a Samsung Galaxy S24 or Google Pixel 9 Pro, there is a small design update coming to the Google Maps app that aims to enhance its visual appearance and user experience. The app will be adopting a new interface color scheme, which could make navigation and interaction feel fresher.

As first reported by 9to5Google, Google Maps is set to change its signature blue accent for buttons and other user interface elements to a dark shade of teal.

Read more
Here’s another hands-on look at the Google Pixel 9a’s radical new design
A person holding the Google Pixel 8a.

The Google Pixel 9a is months away from launch, but many leaks have already revealed what the phone might look like. New real-life images of the Pixel 9a fortify earlier leaks, making us believe the purported design changes, including a more condensed camera module.

Prominent leaker OnLeaks shared a set of images on X allegedly showing a prototype unit of the Pixel 9a. The images show the front and the back of the Pixel 9a and align with the previous leaks of the phone, including hands-on images and digital renders.

Read more
Google quietly announced a huge change for the Pixel 6, Pixel 7, and Pixel Fold
The back of the Pixel 7 Pro and Pixel 6 Pro.

If you have a Google Pixel 6, Pixel 7, or original Pixel Fold, then we have some good news. Those devices will now last longer, as Google has extended update support for them by an additional two years, according to a change on its support page.

When the Pixel 6 launched, Google also announced that it would be extending software support for future devices from three years to five years. Previously, Google only gave its hardware three years of security and Android OS updates, but at that time, security updates were extended to five years. Android OS upgrades stayed at three.

Read more