Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
  • AI
  • Tech
  • Cybersecurity
  • Finance
  • DeFi & Blockchain
  • Startups
  • Gaming
Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
Dataconomy
No Result
View All Result

Fake BMI calculator app on Amazon Appstore steals your data

Upon activation of the app, it initiates a screen recording service, requesting permission when the user clicks the 'Calculate' button

byKerem Gülen
December 20, 2024
in News, Cybersecurity
Home News

A malicious Android spyware application, dubbed ‘BMI CalculationVsn,’ has been discovered on the Amazon Appstore, posing as a health tool while stealthily stealing data from users. This application was identified by McAfee Labs researchers, who promptly notified Amazon, resulting in its removal from the store. However, users who previously installed the app must manually delete it and conduct a full scan to ensure complete eradication of the spyware.

Malicious spyware app discovered on Amazon Appstore

The BMI CalculationVsn application, published by ‘PT Visionet Data Internasional,’ attempts to present itself as a straightforward body mass index (BMI) calculator. Users encounter a seemingly simple interface that allows them to input their weight and height to calculate their BMI; however, additional malevolent functions are executed in the background.

Upon activation of the app, it initiates a screen recording service, requesting permission when the user clicks the ‘Calculate’ button. This tactic may deceive users into granting reflex approvals. While McAfee’s investigation revealed that the recorded video is stored locally as an MP4 file, it was not uploaded to the command and control (C2) server. This avoidance is likely due to the app still being in a developmental stage.

Stay Ahead of the Curve!

Don't miss out on the latest insights, trends, and analysis in the world of data, technology, and startups. Subscribe to our newsletter and get exclusive content delivered straight to your inbox.

Further scrutiny into the app’s history indicated its initial appearance on October 8, with changes to its icon, the addition of further malicious functionalities, and updates to its certificate information by month’s end.

Fake BMI calculator app on Amazon Appstore steals your data
(Image: McAfee)

Functionalities and data theft measures

The Mickey CalculationVsn app engages in various harmful activities designed to compromise user security. In addition to recording the screen, it scans the device for other installed applications, which may allow attackers to strategize their next steps based on the information retrieved. This capability enables them to identify target users more effectively.

Moreover, the spyware intercepts and collects SMS messages stored on the device, potentially capturing one-time passwords (OTPs) and verification codes. The intercepted SMS data is subsequently uploaded to a Firebase storage bucket, clearly indicating a coordinated effort to extract sensitive user information.


BADBOX botnet infects over 192,000 Android devices worldwide


The app remains a work in progress, as research into its previous samples suggests that it is still in the testing phase. The code inspection revealed that the initial version launched as a screen recording app, which was later transformed in functionality when the icon was changed to that of a BMI calculator.

Fake BMI calculator app on Amazon Appstore steals your data
(Image: McAfee)

The developer of BMI CalculationVsn operates under the name ‘PT Visionet Data Internasional,’ which appears to misuse the reputation of a legitimate enterprise IT management service provider in Indonesia. This suggests that the creator of the malware has a technical background and may possess an understanding of software development principles.

In light of this discovery, users are advised to remain vigilant when downloading apps from the Amazon Appstore, which, being an alternative to Google Play, may host apps that bypass traditional security measures. Precautions to consider include installing trusted antivirus software, meticulously reviewing requested app permissions, and being alert to unusual device behavior that could indicate malicious activity.

Despite the removal of the app from the Appstore, the risks to users who installed it remain.


Featured image credit: Kerem Gülen/Midjourney

Tags: amazonCybersecurity

Related Posts

Zoom announces AI Companion 3.0 at Zoomtopia

Zoom announces AI Companion 3.0 at Zoomtopia

September 19, 2025
Google Cloud adds Lovable and Windsurf as AI coding customers

Google Cloud adds Lovable and Windsurf as AI coding customers

September 19, 2025
Radware tricks ChatGPT’s Deep Research into Gmail data leak

Radware tricks ChatGPT’s Deep Research into Gmail data leak

September 19, 2025
Elon Musk’s xAI chatbot Grok exposed hundreds of thousands of private user conversations

Elon Musk’s xAI chatbot Grok exposed hundreds of thousands of private user conversations

September 19, 2025
Roblox game Steal a Brainrot removes AI-generated character, sparking fan backlash and a debate over copyright

Roblox game Steal a Brainrot removes AI-generated character, sparking fan backlash and a debate over copyright

September 19, 2025
DeepSeek releases R1 model trained for 4,000 on 512 H800 GPUs

DeepSeek releases R1 model trained for $294,000 on 512 H800 GPUs

September 19, 2025

LATEST NEWS

Zoom announces AI Companion 3.0 at Zoomtopia

Google Cloud adds Lovable and Windsurf as AI coding customers

Radware tricks ChatGPT’s Deep Research into Gmail data leak

Elon Musk’s xAI chatbot Grok exposed hundreds of thousands of private user conversations

Roblox game Steal a Brainrot removes AI-generated character, sparking fan backlash and a debate over copyright

DeepSeek releases R1 model trained for $294,000 on 512 H800 GPUs

Dataconomy

COPYRIGHT © DATACONOMY MEDIA GMBH, ALL RIGHTS RESERVED.

  • About
  • Imprint
  • Contact
  • Legal & Privacy

Follow Us

  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
No Result
View All Result
Subscribe

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Policy.