An Android app that is designed as a backup tool to protect device data is actually stealing information about the user's phone and activity.
It's called SocialPath and a version of the malware managed to pass inspection and be offered on the official Android store Google Play.
Google removed it from its list as soon as it was notified by security researchers about its dangers, but until it was identified and removed, it received several clicks to download it.
Security researchers who monitor the occasional malware distribution campaigns noticed that one of them recorded almost 6,000 clicks, most of which came from Lebanon (1,715).
The next two places were users from Sudan (1,117) and Oman (666). Users in European Union countries were defrauded in 7% of all clicks.

According to Lookout's Jeremy Linden, SocialPath promises to create secure copies of your contact list and says the service will soon expand to photos, videos and other types of files, and also claims to offer users access to their data if their device is lost or stolen. If the recipient of the message decides to sign up for the service, they are asked to provide their full name, email address, phone number, country of residence and a personal photo.
These are not the only elements sent to their server as the application has functions to leak the contact list, messages, the complete call log which includes phone numbers, the exact time of calls and their duration.
Linden says the malware also has the ability to make calls to numbers sent from the scammers' server and then delete the call logs, so as to hide its activities.
As for the identity of the scammers in this case, and based on the evidence found in the app's code, Linden believes that Arabic-speaking individuals are hiding. Considering the countries involved, SocialPath could be a spying tool with political purposes, but it could also be part of a more advanced phishing scheme with financial motives.
Regardless of its scope, Android should only download apps for their devices from trusted sources, avoid third-party stores where the content is not vetted, and finally read user comments for any negative reports.
