This top Android screen recorder app is actually spyware, so delete now

Google Android figure standing on laptop keyboard with code in background
(Image credit: Shutterstock / quietbits)

After almost a year of working properly and being cleanly distributed through the Play Store, a popular Android screen recording app has turned on its users, recording their calls, stealing files, and even listening in to the sounds of the device’s environment.

Cybersecurity researchers from ESET found the app, named iRecorder - Screen Recorder, which was added to the Play Store in September 2021, turned sour in August 2022. 

In the year before malicious code was apparently added, more than 50,000 people had downloaded the app, the report said. 

Unknown motives

The malware that was subsequently added is based on the open-source AhMyth Android Remote Access Trojan (RAT), but was heavily modified. ESET says whoever modified the code took their time to understand the code of both the app and the back end. ESET’s researchers dubbed the malware AhRat.

The threat actors behind the compromise are unknown, and so are their motives. But given the functionalities of AhRat, all things point to an espionage campaign, the researchers said. After all, besides the screen recording feature (which isn’t malicious), the app can record ambient audio picked up by the endpoint’s microphone, and exfiltrate files such as saved web pages, images, audio, video, document files, and more.

“The AhRat research case serves as a good example of how an initially legitimate application can transform into a malicious one, even after many months, spying on its users and compromising their privacy. While it is possible that the app developer had intended to build up a user base before compromising their Android devices through an update or that a malicious actor introduced this change in the app; so far, we have no evidence for either of these hypotheses,” ESET researcher Lukáš Štefanko said. 

In other words, there’s a slight chance the app was taken over by malicious actors and used in a supply chain attack.

The iRecorder app versions 1.3.8 and older are not malicious, it was said, but if you updated it in the meantime, chances are - you’ve been compromised. The worst part is that the victims didn’t even need to grant the app any further permissions. The app has since been removed from the Play Store.

For safer alternatives, we tested out the best screen recorders and the best free screen recorders for capture your display without security concerns. 

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
 In this photo illustration a Google Play logo seen displayed on a smartphone.
Why is there so much spyware hidden in the Play Store?
Spyware
Government-linked Italian spyware maker caught distributing malicious Android apps
An Android phone being held in the hand
These malicious Android apps were installed over 60 million times - here's how to stay safe
mobile phone
Popular Android financial help app is actually dangerous malware
Kaspersky Report on Stalkerware
Security flaw in popular stalkerware apps is exposing phone data of millions
Android phone malware
Screen reading malware found in iOS app stores for first time - and it might steal your cryptocurrency
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras