---
title: "Android App Busted Secretly Recording Users’ Lives"
description: "An Android app that was supposed to be used to do screen recordings has been caught secretly recording audio and sending it somewhere shady."
date: "2023-05-25"
modified: "2023-05-25"
authors:
  - name: "Noor Al-Sibai"
    job_title: "Senior Staff Writer"
    link: "https://futurism.com/authors/nooralsibai"
url: "https://futurism.com/the-byte/android-app-recording-users-malware"
categories:
  - "Future Society"
tags:
  - "android"
  - "hacking"
  - "malware"
  - "the digest"
---

# Android App Busted Secretly Recording Users’ Lives

![An Android app that was supposed to be used to do screen recordings has been caught secretly recording audio and sending it somewhere shady.](<https://futurism.com/wp-content/uploads/2023/05/android-app-recording-users-malware-1.jpg>)
*\<em\>Image: Getty / Futurism\</em\>*

## Secret Surveillance

An Android app that was supposed to be used to do screen recordings has been caught secretly recording *audio* and sending it somewhere shady — but the story behind the debacle goes even deeper.

As the [*WeLiveSecurity* blog reports](<https://www.welivesecurity.com/2023/05/23/android-app-breaking-bad-legitimate-screen-recording-file-exfiltration/>), the app named "iRecorder – Screen Recorder" had more than 50,000 installs from the Google Play store after its fall 2021 launch and, by all indications, was a normal, benign app.

At some point, however, the app was "trojanized" with malicious software during a subsequent update, according to the security software firm ESET, which owns *WeLiveSecurity*.

"Initially, the iRecorder app did not have any harmful features," the blog post reads. "What is quite uncommon is that the application received an update containing malicious code quite a few months after its launch."

And reader, it gets weirder: "The application’s specific malicious behavior, which involves extracting microphone recordings and stealing files with specific extensions, potentially indicates its involvement in an espionage campaign."

## Ah, Rats!

This strange debacle, ESET notes, involves a type of "remote access trojan" — or RAT, evocatively — [malware](<https://futurism.com/the-byte/android-malware-google-play-apps>) known as AhMyth, which has previously [plagued the Google Play store](<https://securitynews.sonicwall.com/xmlpost/trojanized-android-ahmyth-rat-spreads-via-legitimate-apps/>) on [more than one occasion](<https://www.welivesecurity.com/2019/08/22/first-spyware-android-ahmyth-google-play/>). As the RAT moniker suggests, this kind of malware is used to remotely access victims' phone data and send it to outside developers to do whatever nefarious things they want with the data or to the infected devices.

*WeLiveSecurity* has named the latest AhMyth version "AhRat," and said that besides the iRecorder app — which has now been pulled from Google Play — its researchers haven't detected the malware "anywhere else in the wild."

While it's unclear who or what was controlling this latest version of AhMyth, the blog did note that past generations had been used for some pretty freaky stuff.

"Previously, the open-source AhMyth was employed by Transparent Tribe, also known as APT36, a cyberespionage group known for its extensive use of social engineering techniques and targeting government and military organizations in South Asia," *WeLiveSecurity* explains, though the blog admits that it doesn't know who is behind this attack and has no evidence that it's connected with any "known advanced persistent threat."

As [common as malware has become](<https://dataprot.net/statistics/malware-statistics/>), the history of AhMyth and the possibility that this version could have been used for clandestine ends provides a stark reminder of how dangerous this sort of thing really is — and, if nothing else, should encourage everyone to exercise caution even on official app stores.

**More on bad actors:** [*Scammer Tricks Man With Face and Voice Swap of His Friend, Cops Say*](<https://futurism.com/the-byte/scammer-tricks-man-face-voice-swap>)

## Author
At Futurism, I've often been drawn to unpacking the narratives that underlie technological, scientific and medical progress, with a special interest in areas of conflict and ambiguity that end up setting agendas and steering the fates of both elites and the hoi polloi. I'm a committed generalist, but I often find myself returning to work involving NASA and the private space sector, the effects of AI on media and society, and the mechanics of the pharmaceutical industry, with a specific focus on the spread of GLP-1 drugs like Ozempic and Wegovy. Prior to Futurism, I worked for publications ranging from Media Matters and Truthdig to Raw Story and Bustle. I'm also the author of "Myspace Scene Queens," a 2024 title in Instar Books' acclaimed "Remember the Internet" series. My work at Futurism has been cited by outlets including the New Yorker, Slate, Nieman Lab, the Verge, the MIT Technology Review, the Sunday Times, and the Daily Beast. I grew up in North Carolina, attended the University of North Carolina at Asheville, and now live in Brooklyn, New York. In my free time, I'm an avid reader and music fan; you can probably find me at a local poetry reading, concert, underground rave, or DJ set. I'm the proud parent of an ineffable orange cat named Mee-Mow.

### Author social links  
[Bluesky](<https://bsky.app/profile/noorfromfuturism.bsky.social>)