A popular PDF app could have installed malware on your Android phone

Phone malware
(Image credit: Shutterstock)

Popular PDF app CamScanner, available to download from the Google Play Store, has been inadvertently allowing crooks to install malware on victims' phones.

As The Register reports, researchers from Kaspersky discovered that the app contained a trojan that allowed malicious software to be run silently in the background. Igor Golovin and Anton Kivva say the trojan, known as Necro.n, was probably disguised as a legitimate advertising package, and CamScanner's developers were likely unaware what was happening.

Necro.n doesn't actually contain any malicious software itself, but it provides a gateway for crooks to install whatever they like – whether that's software that shows ads for disreputable businesses, or apps that charge you money through illicit premium subscriptions.

Be on your guard

This discovery serves as a reminder that although Google strives to check apps in the Play Store for malicious code, it's not infallible.

In fact, it's been found that some Android phones even come with malware pre-installed. Phones can be sold with hundreds of apps installed, and only one needs to be compromised for attackers to gain access to your device.

"It looks like app developers got rid of the malicious code with the latest update of CamScanner," says Kaspersky. "Keep in mind, though, that versions of the app vary for different devices, and some of them may still contain malicious code."

Cat Ellis
Homes Editor

Cat is TechRadar's Homes Editor specializing in kitchen appliances and smart home technology. She's been a tech journalist for 15 years, and is here to help you choose the right devices for your home and do more with them. When not working she's a keen home baker, and makes a pretty mean macaron.

Latest in Security
healthcare
Software bug meant NHS information was potentially “vulnerable to hackers”
A hacker wearing a hoodie sitting at a computer, his face hidden.
Experts warn this critical PHP vulnerability could be set to become a global problem
botnet
YouTubers targeted by blackmail campaign to promote malware on their channels
A close-up of a phone screen showing the Telegram, Signal and WhatsApp apps
Agentic AI has “profound” issues with security and privacy, Signal President says
botnet
Another top security camera maker is seeing devices hijacked into botnet
Bluetooth
Top Bluetooth chip security flaw could put a billion devices at risk worldwide
Latest in News
Apple's Craig Federighi demonstrates the iPhone Mirroring feature of macOS Sequoia at the Worldwide Developers Conference (WWDC) 2024.
Report: iOS 19 and macOS 16 could mark their biggest design overhaul in years – and we have one request
Google Gemini Calendar
Gemini is coming to Google Calendar, here’s how it will work and how to try it now
Lego Mario Kart – Mario & Standard Kart set on a shelf.
Lego just celebrated Mario Day in the best way possible, with an incredible Mario Kart set that's up for preorder now
TCL QM7K TV on orange background
TCL’s big, bright new mid-range mini-LED TVs have built-in Bang & Olufsen sound
Apple iPhone 16e
Which affordable phone wins the mid-range race: the iPhone 16e, Nothing 3a, or Samsung Galaxy A56? Our latest podcast tells all
Homepage of Manus, a new Chinese artificial intelligence agent capable of handling complex, real-world tasks, is seen on the screen of an iPhone.
Manus AI may be the new DeepSeek, but initial users report problems