Hackers could use Google Home or Amazon Echo to listen in to your conversations

Smart speaker
(Image credit: Shutterstuck)

At least eight eavesdropping apps have slipped past Google and Amazon's app verification process and made their way into their respective app stores, ready to be downloaded onto the smart speakers of unsuspecting victims.

As Ars Technica reports, researchers at hacking collective Security Research Labs (SRLabs) built four Google Home actions and four Alexa skills, which looked like innocuous tools for checking horoscopes and generating random numbers, but were also capable of phishing for passwords and monitoring users' conversations.

All of these apps passed through Google and Amazon's security checks, and were published for others to download.

When a user asked to know their horoscope, the eavesdropping apps provided the information as expected. They then seemed to stop running, but actually remained active and listening in the background. Conversations were logged and sent to a remote server.

When a victim attempted to use one of the phishing apps, they would receive an error message informing them that the app was unavailable in their country. The app would again remain running, and after a short break would use a voice similar to that used by Alexa or Google Home to inform the user that an update was available, and ask for their password.

Researchers at Sophos recently identified several apps in the Google Play Store that used a similar trick – throwing up up fake error messages while continuing to run in the background and perform malicious operations – but users are even less likely to expect such malware on their smart speakers.

Play it safe

SRLabs reported its findings to Amazon and Google, both of which removed the apps from their respective stores and promised they would tighten their appraisal processes in the future to make sure genuinely malicious software isn't able to slip through the same way.

For the time being, you're well advised to follow the Sophos team's advice on installing new apps: always read reviews, and sort them so you see the most recent ones first (the malicious element might have been added with a recent update). Filter out any five-star reviews with no written text, as these are likely to be fake, and look closely at the remainder.

If several reviewers complain about the app causing problems or not behaving as expected, you'd be better off avoiding it.

TOPICS
Cat Ellis
Homes Editor

Cat is TechRadar's Homes Editor specializing in kitchen appliances and smart home technology. She's been a tech journalist for 15 years and is an SCA-certified barista, so whether you want to invest in some smart lights or pick up a new espresso machine, she's the right person to help.

Latest in Smart Home Hubs
google nest
Google is slowly phasing out its Assistant helper to make room for Gemini's reign in smartphones - here’s how it’s doing the same for smart home devices
Various SwitchBot smart home automation devices
Switchbot has totally redesigned its smart home hub – and it's great news for renters
Amazon Echo Show on a counter displaying
The Echo Show 15 (2024) can't decide if it's a Fire TV or a smart home hub, and it fails to excel at either
Amazon Echo Show 21 running Spotify app
The Amazon Echo Show 21 is big and beautiful, and it's changed how I control my smart home
The Samsung Bespoke line of kitchen appliances
What is Samsung's ambient sensing? Unpacking the new SmartThings AI features
HomePod 2 on shelf in a home
New leak may have revealed more details about Apple's first smart display
Latest in News
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Philips Hue
Philips Hue might be working on a video doorbell, and according to a new report, we just got our first look at it
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
A fresh Samsung Galaxy S25 Edge leak hints at a 2K display and a titanium frame
Hatch Restore 3 in Putty
You can finally start your day with The Office theme song, and I couldn't be more excited