Skip to main content

Android System Update App On Play Store Contained Spyware

By May 20, 2017May 25th, 2021Technology News

If you’ve recently downloaded an app called SMAVova, you’re not alone. Between one and five million users have done the same. Unfortunately, that’s a problem, and to be safe, you’ll want to reset your device to factory defaults to be sure you’re rid of it. It’s actually malware, and once you download it, it will send your exact location to the hackers controlling it in real time.

The discovery was formally made by researchers from Zscaler ThreatLabz, but a close look at the app’s download screen would have revealed that something was amiss.

For starters, there’s no screenshot. By itself, that’s not necessarily a dead giveaway, but the app sells itself as being an Android System Update, and Google is not in the business of releasing such updates without the requisite screen shots.

Secondly, and perhaps even more compelling is the fact that as increasing numbers of people downloaded the app, legions of them left negative reviews, stating that it didn’t make any new Android updates available and generally did not work as advertised.

Generally, people tend to rely on peer reviews like this as a barometer for whether they want to download the app for themselves, so it’s unclear why that wasn’t the case in this particular instance. It is possible that users, seeing a mention of Android updates, simply went ahead with the download in spite of the red flags that the negative reviews represented.

Whatever the case, the app has now been removed and is no longer available. That’s small consolation for the millions of users who have already been impacted, but at least it keeps the problem from getting any worse.

The moral of the story here is simple. Despite Google’s best efforts, malicious apps do occasionally wind up on the App Store. Due diligence is in order to be sure you actually want or need the app in question before diving in and grabbing it, and peer reviews should be an important part of that process.

Jason Manteiga

Jason J. Manteiga, Vice President of Olmec Systems, has been part of the company for over the past 20 years. He believes that having a great work environment and supportive team, is the ultimate key to success. Since being in the IT realm for over 25 years, Jason, along with Olmec Systems, has been on the Inc. 5000 “List of America’s Fastest Growing Private Companies” and Channel Futures MSP 501 “Top Managed Service Providers in North America,” along with other awards and nominations. Jason earned his Bachelor Degree in Information Systems from the New Jersey Institute of Technology. He also holds certifications in Microsoft MCSE, VMWare VCP, and Cisco CCNA. In his spare time, Jason is a contributor for The Center for Social & Legal Research (Privacy Exchange) and a member of the Morris County Chamber of Commerce. His hobbies include cycling and kayaking. He currently lives in New Jersey with his wife, two daughters and son.