Is it time to subscribe to a printer service from HP?

Ever since my dad brought home an...

What’s the best way of buying a phone today?

How did you buy your latest phone?...

MWC: What device highlights did you miss?

So, early last week I predicted that...

The most powerful espionage app for Android has been discovered

Back in August, Pegasus for iOS made headlines as one of the most sophisticated espionage apps on mobile. The app was believed to have been in circulation for quite a while before being discovered. Furthermore, it was suggested that a few hundred more iterations of the app were still around, targeting specific individuals like a political dissident from the UAE.

Now, Google has detailed Pegasus for Android, a clone of the app for Google’s platform. Mobile security firm Lookout sent Google a list of suspicious package names while it was conducting its own analysis. Google found that a few dozen Android devices had installed an application that bore a remarkable resemblance to Pegasus, which the company dubbed Chrysaor.

It took months for the two companies to identify Pegasus for Android. The espionage app is thought to be developed by NSO Group Technologies, who specialize “in the creation and sale of software and infrastructure for targeted attacks”.

On their own independent analysis, Lookout mentioned that the espionage app represents “the common feature-set that we see from nation states and nation state-like groups”. According to the security firm, such threats are meant to track a target both in the physical and virtual worlds.

To put that into perspective, Pegasus is capable of extraordinary functions. These include keylogging, capturing of live audio, video, and screenshots, exfiltration of data from various applications, text messages, browser history, email, and even remote control of the spyware via SMS commands.

An even more impressive fact is that Pegasus for Android can self-destruct when compromised through a variety of checks. That includes checking whether the mobile country code associated with the SIM card is invalid or not, and if the app has been unable to connect to its server for 60 days.

Unlike its iOS counterpart, which used three previously unknown security vulnerabilities to install itself on targeted devices, Pegasus for Android uses Framaroot instead, a well-known rooting technique which can bypass security.

Such sophisticated spyware and espionage tools are created after requests by specific agencies and are unfortunately often used against citizens of countries with questionable democratic values. Pegasus for Android, as an espionage app of its own, was likely used for similar purposes.

While the average user has nothing to fear against attacks of this magnitude, the fact that they exist and can live on in a mobile OS for months before being discovered is certainly troubling. With an IoT explosion in the horizon, the importance of security in the cyberspace cannot be overstated.

1 COMMENT

  1. The Pegasus app for Android incorporated with several features related to keylogging, capture of live audio and the such has made a bang that it is here to stay !!.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Recently Published

Is it time to subscribe to a printer service from HP?

Ever since my dad brought home an HP LaserJet printer (version 3, if memory serves), I have been printing with an HP. Over the...

What’s the best way of buying a phone today?

How did you buy your latest phone? I'm asking because I'm thinking about what I should be doing. When I was living in Oman, I...

MWC: What device highlights did you miss?

So, early last week I predicted that next to nothing from Mobile World Congress would break through into the mainstream media. I was right,...

How Wireless Will Pave the Path to Neobank Profitability

I'm delighted to bring you an opinion piece from Rafa Plantier at Gigs.com. I think it's particularly relevant given the recent eSIM news from...

An end of an era: Vodafone UK turns off 3G services

I thought it was worthwhile highlighting this one from the Vodafone UK team. For so long - for what feels like years, seeing the...

Mobile World Congress: Did the mainstream media notice?

I resolved this year to make sure I wrote something - anything - about Mobile World Congress, the huge mobile industry trade show taking...