
An Android chat app that claims to be a secure messaging platform is spying on users and storing data their in an unsecured location that is publicly available. The Welcome Chat app appears to target users from a specific region and relies on open source code to record calls, steal messages, and track users.
Normal permissions for a chat app
The developers of Welcome Chat promoted it as a secure communication solution available from the Google Play store. The chat app is intended for Arabic-speaking users. It should be noted that some countries in the Middle East ban this type of app.
ESET researchers found that the Android chat app does many things that it doesn't officially mention or advertise. They also saw that the app was never part of the official Android store.
Apps outside the Play Store require users to allow installation from unknown sources, which is the case with Welcome Chat.
If users follow this process, the chat app asks for permission to send and view SMS messages, access files, record audio, and access contacts and device location. These permissions are normal for a chat app.

The app uses open source code to spy on users
Once the user gives permission, Welcome Chat begins sending information about the device and communicating with its command and control (C2) server every five minutes.
Researchers say that monitoring communication with other Welcome Chat users is at the core of this malicious app. Other functions include the following:
- theft of sent and received messages
- call history theft
- theft of the victim's contact list
- photo theft
- theft of recorded phone calls
- sending location data and other system information
Researchers discovered that much of the code used for espionage comes from public sources (e.g. open-source projects, etc.).
Whoever created Welcome Chat didn't waste much time. They probably searched the internet for the desired spying feature and used the first code they found.
This conclusion is drawn from the “age” of the code, which in some cases has been publicly available for at least five years. The call logging and location tracking features, for example, “are eight years old.”.

User data is accessible
“The data is not encrypted and therefore, not only is it available to the attacker, but also to anyone on the same network,” says ESET researcher Lukas Stefanko.
The chat application's database includes everything except the user account password: names, email, phone numbers, device tokens, profile pictures, messages, and friends list.
Initially, researchers believed that Welcome Chat was a legitimate chat app that had been infected by criminals. So they tried to warn the developers. However, they found a clean variant on VirusTotal and realized that the app was created from the ground up to spy on users.
Although there is no strong evidence, the chat app may be the work of the same group that was behind BadPatch, a spying campaign detected in 2017 that targeted users in the Middle East.
