Spyware-laden 'privacy' extensions and apps affect over 11 million users

Spyware

Researchers have discovered a collection of privacy-related apps and browser extensions that track users' activity and send it to a remote server. The suspicious software has over 11 million users in total, and include extensions for Chrome and Firefox, as well as mobile apps for iOS and Android.

According to Andrey Meshkov of AdGuard, the extensions all appear to belong to one company: Big Star Labs. This isn't immediately obvious because many of the apps are published under different names, and their privacy policies are only available as image files, which means the text can't be indexed by Google. AdGuard was only able to find the connections by trawling through the policies manually.

Meshkov found issues with the following tools (some of which have now been removed from the respective app stores):

  • Block Site
  • AdblockPrime
  • Mobile Health Club apps
  • Poper Blocker
  • CrxMouse

Read the fine print

The mobile apps are particularly concerning. All of the Android apps request access to the operating system's Accessibility Services, which allows apps to perform tasks that would usually require user interaction, such as tapping and swiping (something Google tried to crack down on last year).

Meanwhile, one iOS app offers to install a Mobile Device Management profile, which allows it to see all the apps installed on your phone, see your browser history, and potentially even install new apps.

"It is no 'new' news that our personal data is valuable," Meshkov concludes. "Those who want to profit from acquiring it will always surround us. With this in mind, I will never tire of repeating two simple rules one needs to follow if they care about preserving their privacy and security: Read the privacy policy before installing anything [and] never install anything made by a developer you don't trust."

Cat Ellis
Homes Editor

Cat is TechRadar's Homes Editor specializing in kitchen appliances and smart home technology. She's been a tech journalist for 15 years, and is here to help you choose the right devices for your home and do more with them. When not working she's a keen home baker, and makes a pretty mean macaron.

Latest in Computing Security
ensure data security for your business
The complete data protection system for your business
ignal messaging application President Meredith Whittaker poses for a photograph before an interview at the Europe's largest tech conference, the Web Summit, in Lisbon on November 4, 2022.
"We will not walk back" – Signal would rather leave the UK and Sweden than remove encryption protections
Man uses a laptop in a hotel room
4 ways to avoid misinformation on social media and retain control of your newsfeed
Apple
"We will never build a backdoor" – Apple kills its iCloud's end-to-end encryption feature in the UK
DeepSeek
DeepSeek accused of sharing users' data with TikTok's ByteDance in another blow around privacy concerns
This photograph shows wordmark of Siri, a digital assistant developed by Apple Inc., displayed on a smartphone
Did Siri break the law? Apple's latest privacy complaint in France doesn't bode well
Latest in News
Apple iPhone 16 Review
Three iPhone 17 model dummy units appear in a hands-on video leak
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
New Samsung Galaxy S25 Edge may have revealed some key details – including its price
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 9 (game #1140)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 9 (game #371)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 9 (game #637)
WhatsApp
WhatsApp just made its AI impossible to avoid – but at least you can turn it off