A new Android malware called RedDrop can perform a massive range of malicious actions, including recording audio and uploading it to cloud-storage accounts on Google Drive and Dropbox. 
Malicious software was first detected by the British company Wandera mainly on employees' devices who worked as business consultants. Despite its impressive features that could easily classify it as spyware, ReDrop is not considered an electronic espionage product because it was primarily used to register users to premium SMS numbers and earn money from them.
The malicious software operates primarily in China. Because there is no official Google Play Store there, users usually rely on various search engines to find apps. The steps to infect a device with RedDrop are as follows:
- The user searches (usually on Baidu) for an Android app.
- A malicious search result redirects users through various sites until it ends up in a third-party app store.
- The user installs an application that has been infected by RedDrop which asks for administrator rights.
- The malicious software obtains boot persistence and then gathers the device's core data and sends it to a remote C&C server.
- RedDrop downloads and installs seven other applications that provide the malicious software with additional functionalities
- The user launches the application.
- The primary goal of RedDrop is for the user to subscribe to Premium SMS services and delete any incoming verification texts that might alert the user.
- The malware steals phone data, such as photos, files, and contact lists. As an additional feature it records audio via the microphone. RedDrop sends all these files to remote Dropbox and Google Drive accounts.
Researchers believe that the malicious software steals users' personal files and records audio only in cases where someone wants to extort infected users. Wandera says it discovered RedDrop in at least 53 applications offered for download in various app stores and advises users to watch out for the third-party stores they use.
