This Simple Android App Proves Anything Can Contain Malware

How much damage can a BMI calculator app do to your phone? It turns out that it’s not what the app can do, but what it hides in its code that you should be concerned about. This is the case of an app uploaded to the Amazon Appstore that contained spyware that was discovered by McAfee.

McAfee Detects Malware Glitch in BMI App on Amazon Appstore

As McAfee discovered, the malicious app pretends to be a simple BMI calculator. Sure enough, when you download it, it does exactly that. You can enter your height and weight, and the app will tell you whether your BMI is in a healthy range or not.

However, something strange happens when you click “Calculate”. Suddenly, the app asks you to allow it to record your screen. Given the location of the permission request, it seems like cybercriminals want to take advantage of people’s impatience and accept any pop-up that appears to get their BMI results.

This Simple Android App Proves Anything Can Contain Malware
This Simple Android App Proves Anything Can Contain Malware
This Simple Android App Proves Anything Can Contain Malware

If the user accepts this request, the app will start recording the target’s screen, presumably to steal any private information the user enters into the app. The malicious app may also record SMS messages (presumably to steal 2FA codes) and get a list of target apps.

When McAfee analyzed the code, they found that the app had all the means to collect data, but it wasn’t actually sending it anywhere. It’s unclear whether the cybercriminals wanted to keep it a secret and wait for more downloads before activating the feature, or whether they simply forgot about it. Either way, the app was taken down before it could do any damage.

While we were lucky this time, not all malicious apps will be detected like this. Always be careful when downloading apps, even if they seem simple and are offered on official app stores! If an app asks for Android permissions it doesn’t need (like screen recording permission for the BMI app), deny it; who knows what the app could collect if you allow it.

Leave a Comment

How to Check Purchase History on Apple App Store

How to Check Purchase History on Apple App Store

Through your purchase history on the App Store, you will know when you downloaded that app or game, and how much you paid for the paid app.

Quick tips to check WiFi security on iPhone when connecting

Quick tips to check WiFi security on iPhone when connecting

Apple makes it easy to find out if a WiFi network is safe before you connect. You don't need any software or other tools to help, just use the built-in settings on your iPhone.

Instructions for receiving strange calls on iPhone

Instructions for receiving strange calls on iPhone

iPhone mutes iPhone from unknown callers and on iOS 26, iPhone automatically receives incoming calls from an unknown number and asks for the reason for the call. If you want to receive unknown calls on iPhone, follow the instructions below.

How to Turn Off Headphone Volume Limit Warning on iPhone

How to Turn Off Headphone Volume Limit Warning on iPhone

iPhone has a speaker volume limit setting to control the sound. However, in some situations you need to increase the volume on your iPhone to be able to hear the content.

How to Uninstall Any Android App Using ADB (Including System Apps and Bloatware)

How to Uninstall Any Android App Using ADB (Including System Apps and Bloatware)

ADB is a powerful set of tools that give you more control over your Android device. Although ADB is intended for Android developers, you don't need any programming knowledge to uninstall Android apps with it.

This setting can extend your phones battery life better than you think.

This setting can extend your phones battery life better than you think.

You might think you know how to get the most out of your phone time, but chances are you don't know how big a difference this common setting makes.

Android System Key Verifier protects you from scammers and impersonators without you even knowing it.

Android System Key Verifier protects you from scammers and impersonators without you even knowing it.

The Android System Key Verifier app comes pre-installed as a system app on Android devices running version 8.0 or later.

Simple trick to control Apple TV with any Android phone

Simple trick to control Apple TV with any Android phone

Despite Apple's tight ecosystem, some people have turned their Android phones into reliable remote controls for their Apple TV.

What to do when mobile data is not working on Android device?

What to do when mobile data is not working on Android device?

There are many reasons why your Android phone cannot connect to mobile data, such as incorrect configuration errors causing the problem. Here is a guide to fix mobile data connection errors on Android.

How to run PlayStation 3 games on Android using aPS3e

How to run PlayStation 3 games on Android using aPS3e

For years, Android gamers have dreamed of running PS3 titles on their phones – now it's a reality. aPS3e, the first PS3 emulator for Android, is now available on the Google Play Store.