ESET researchers have found a new RAT malware on the Google Play Store , hidden in the Android screen recording app “ iRecorder – Screen Recorder ” . The app had tens of thousands of installations . The researchers named the malware “ AhRat ”.

The “ iRecorder – Screen Recorder ” app was first introduced to the store in September 2021, but it likely became malicious through an update released almost a year later, in August 2022.
The name and purpose of the app made it easy for malicious developers to ask users for permission to record audio and access files.
See also: New Fleckpe Android malware detected on Google Play
The app had amassed over 50,000 installs on the Google Play Store, but after the researchers reported it, it was removed from the app.
“After we were notified about iRecorder’s malicious behavior, the Google Play security team removed it from the store,” said ESET malware researcher Lukas Stefanko.
According to BleepingComputer, a Google spokesperson said: “When we find apps that violate our policies, we take appropriate action. Users are also protected by Google Play Protect, which can warn about detected malicious apps on Android devices.
However, researchers say that the malicious iRecorder – Screen Recorder app can also be found on alternative and unofficial Android marketplaces.
“The iRecorder developer also provides other apps on Google Play, but they do not contain malicious code,” Stefanko said.
See also: XWorm malware exploits Follina vulnerability in new attacks
The AhRat malware is based on an open-source Android RAT known as AhMyth. It has a wide range of capabilities, including tracking the location of infected devices, stealing call logs, contacts, and text messages, sending SMS, taking photos, and recording audio in the background.

Upon closer examination, ESET found that the malicious iRecorder – Screen Recorder application itself only utilized a subset of the RAT’s capabilities, as it was only used to create and recordings audio and steal files with specific extensions.
This isn't the first time that Android malware based on AhMyth has infiltrated the Google Play store. In 2019, ESET reported on another app that tricked Google's app review process twice and made it onto the store.
“Previously, the open-source AhMyth was used by Transparent Tribe, also known as APT36, a cyberespionage group known for its extensive use of social engineering techniques targeting government and military organizations in South Asia,” Stefanko said. “However, we cannot attribute the current samples to any specific group and there is no indication that they are produced by a known advanced threat group (APT).”
See also: Cloned CapCut websites spread information-stealing malware
Regardless, Android malware is a serious threat that can cause significant damage to your smartphone. It is important to be careful when downloading and installing apps on phone to protect your device. If you suspect that your device has been infected with malware, take immediate action by running an antivirus scan or seeking professional help.
Source: www.bleepingcomputer.com
