A popular PDF app could have installed malware on your Android phone

Phone malware
(Image credit: Shutterstock)

Popular PDF app CamScanner, available to download from the Google Play Store, has been inadvertently allowing crooks to install malware on victims' phones.

As The Register reports, researchers from Kaspersky discovered that the app contained a trojan that allowed malicious software to be run silently in the background. Igor Golovin and Anton Kivva say the trojan, known as Necro.n, was probably disguised as a legitimate advertising package, and CamScanner's developers were likely unaware what was happening.

Necro.n doesn't actually contain any malicious software itself, but it provides a gateway for crooks to install whatever they like – whether that's software that shows ads for disreputable businesses, or apps that charge you money through illicit premium subscriptions.

Be on your guard

This discovery serves as a reminder that although Google strives to check apps in the Play Store for malicious code, it's not infallible.

In fact, it's been found that some Android phones even come with malware pre-installed. Phones can be sold with hundreds of apps installed, and only one needs to be compromised for attackers to gain access to your device.

"It looks like app developers got rid of the malicious code with the latest update of CamScanner," says Kaspersky. "Keep in mind, though, that versions of the app vary for different devices, and some of them may still contain malicious code."

Cat Ellis
Homes Editor

Cat is TechRadar's Homes Editor specializing in kitchen appliances and smart home technology. She's been a tech journalist for 15 years, and is here to help you choose the right devices for your home and do more with them. When not working she's a keen home baker, and makes a pretty mean macaron.

Latest in Security
A graphic showing someone on a tablet working through a supply chain.
Security issue in open source software leaves businesses concerned for systems
ransomware avast
One of the most powerful ransomware hacks around has been cracked using some serious GPU power
person at a computer
Infamous ransomware hackers reveal new tool to brute-force VPNs
person at a computer
Many workers are overconfident at spotting phishing attacks
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft 365 accounts are under attack from new malware spoofing popular work apps
Data Breach
Thousands of healthcare records exposed online, including private patient information
Latest in News
Metroid Prime 4
I reckon the Nintendo Switch 2 could launch with Metroid Prime 4 – here’s why
Samsung Galaxy Z Fold 6
New rumors predict a foldable iPhone will launch next year – and cost almost twice as much as the iPhone 16 Pro Max
Pebble smartwatch countdown
Pebble confirms its smartwatch announcement is just hours away
Logo of YouTube Shorts
Is YouTube auto-playing Shorts when you open the app? Well, you’re not alone - here’s how to fix it
Google DeepMind panel discussion
“More sovereignty and protection” - Google goes all-in on UK AI with data residency, upskilling projects, and startup investments
Nintendo Switch 2
Nintendo Switch 2 expected to have AI upscaling and I can't wait to finally play Tears of the Kingdom with upgraded graphics