Skip to main content

Google takes down Android app that let hackers control your phone through SMS

android spyware works through text smartphone cellphone hacking frustration
Image used with permission by copyright holder
An internet security company has published its findings on an Android app that contained spyware controlled via text messages. Researchers at Zscaler have determined an app suspiciously titled “System Update” gave attackers the ability to execute commands on a remote device and receive its location data. The app — which was just deleted on Google Play Store — had been available for the last three years, and was listed as having been downloaded anywhere from 1 million to 5 million times.

The reviews all indicate users had been installing System Update believing, unsurprisingly, that it would update the version of Android on their device. Instead, when opened for the first time, the app would display the standard system error message — “Unfortunately, System Update has stopped” — and remove itself from the app drawer.

Recommended Videos

This would activate the spyware, named SMSVova, and set things into motion. SMSVova fetches the user’s location data and begins reading text messages, looking for an SMS message that reads “get faq.” If another device texts “get faq” to the infected party, the latter will automatically respond with a list of commands. By texting these commands to the affected device, the attacker could remotely lock the phone with a password or even issue fake low-battery warnings.

Please enable Javascript to view this content

At this point, the attacker is given total access to the coordinates of the infected phone. Although the app is no longer available to download from Google’s marketplace, Zscaler reports it found the code living in another remote access program, called DroidJack.

There is of course no shortage of ways in which an unscrupulous hacker could gain access into your phone, especially with the help of user-installed software. But this is certainly one of the more interesting methods. It’s also quite frightening, considering it gives the attacker so much power through the seemingly harmless and unsophisticated medium of text messages. Then again, in light of the deadly string of emojis that can incapacitate an iPhone, perhaps we shouldn’t be so surprised.

Adam Ismail
Former Digital Trends Contributor
Adam’s obsession with tech began at a young age, with a Sega Dreamcast – and he’s been hooked ever since. Previously…
It just got easier to protect your Android phone from thieves
Android 15 theft protection.

With the release of Android 15 on Pixel devices, Google has introduced several new privacy and security enhancements. Among the notable additions are the improved theft protection features that are designed to make it harder for thieves to access your data. Initially, it was a bit difficult to find these settings. However, as Android Authority first noted, that's about to change.

When Android 15 launched, to find the theft protection menu on devices running Android 15, you had to follow these steps:

Read more
This Google app will make your Pixel look more like an iPhone
A person holding the Google Pixel 9.

As Google's Pixel line of phones has grown over the years, some fans have pointed out the increasing resemblance to the iPhone. The rounded edges, sleek design, and raised camera bump are all reminiscent of Apple's iconic device — especially with the newest Google Pixel 9.

Now, it looks like even the incoming call screen of the Google Phone app will be taking on an iPhone-like appearance. This is according to an APK breakdown by Android Authority.

Read more
RCS messages are about to look a little different on your Android phone
Google Messages app on a Pixel 8 Pro, showing an RCS Chat message thread.

You might soon see a change in how your messages look on your Android phone. Google Messages is rolling out a change to how the type of message is displayed. At present, it says either "Text message" or "RCS message" at the bottom, but the new change will shorten these to either (Text) or (RCS).

9to5Google's Abner Li reports the change and points out that the phrasing could be reduced to either Text or RCS to streamline the appearance and make it look less technical. That said, only a limited number of people have reported the change so far. Google has a tendency to roll updates out slowly, however, so that's not surprising.

Read more