Scary Android spyware can steal your messages: What to do

Spyware affecting an Android mobile user
(Image credit: Shutterstock)

Trend Micro researchers have found a new strain of Android spyware being used in a broader campaign against Chinese Uyghurs and the Chinese region of Tibet as well as Taiwan and Turkey. 

The researchers, Ecular Xu and Joseph C. Chen, believe the Android spyware, which they named ActionSpy, has been active since 2017 and steals contacts, call logs, location, SMS text logs and instant-messaging chat logs. 

It also takes screenshots and photos and records video. The spyware seems to be related to iPhone spyware deployed against Uyghurs that Google disclosed in 2019.

Xu and Chen warned that the spyware abuses Android Accessibility, the mobile OS's framework for users with hearing, vision or mobility impairments, so that the attackers can gain access to instant messages and chat logs from QQ, Viber, WeChat and Whatsapp

“While tracking Earth Empusa, also known as POISON CARP/Evil Eye," Xu and Chen wrote, "we noticed a phishing page disguised as a download page of an Android video application that is popular in Tibet.” 

As with the Uyghurs, the Tibetan minority in China has an active independence movement both in China and in exile. The Trend Micro researchers noted that Earth Empusa's use of phishing pages was similar to that of a different campaign discovered in March that was putting spyware on iPhones in Hong Kong.

"The phishing page, which appears to have been copied from a third-party web store, may have been created by Earth Empusa," they added. "Upon checking the Android application downloaded from the page, we found ActionSpy."

The attackers are presumably state-sponsored hackers working for the Chinese government, though Trend Micro is careful not to say so directly as attribution can never be certain.

Dangerous form of Android spyware

Through this phishing page, written in Uyghur using Arabic script, recipients are encouraged to download a video app well known in Tibet. But in reality, it’s a dangerous form of Android spyware.

The researchers said: “The download link was modified to an archive file that contains an Android application. Analysis then revealed that the application is an undocumented Android spyware we named ActionSpy.

“This malware impersonates a legitimate Uyghur video app called Ekran. The malicious app has the same appearance and features as the original app.”

Xu and Chen explained that the Android spyware collects basic device information like IMEI, phone number, manufacturer and battery status every 30 seconds, before sending it to a C&C server. 

They warn: “ActionSpy, in turn, adopts an indirect approach: it prompts users to turn on its Accessibility service and claims that it is a memory garbage cleaning service.

“Once the user enables the Accessibility service, ActionSpy will monitor Accessibility events on the device.”

To avoid being infected by this or any form of Android spyware, make sure you're running one of the best Android antivirus apps. Another safety measure is to download apps only from the Google Play Store, but that's only partly accessible from the Chinese mainland.

TOPICS

Nicholas Fearn is a freelance technology journalist and copywriter from the Welsh valleys. His work has appeared in publications such as the FT, the Independent, the Daily Telegraph, The Next Web, T3, Android Central, Computer Weekly, and many others. He also happens to be a diehard Mariah Carey fan!

Latest in Android Phones
Samsung Galaxy S25 Edge next to Galaxy S25 Plus
Samsung Galaxy S25 Edge vs. Galaxy S25 Plus: Everything we know so far
Samsung Galaxy S25 Ultra vs S25 Plus vs S25
Satellite messaging on Google Pixel 9 and Samsung Galaxy S25 just landed on 3 more carriers
back of Iris Pixel 9a
The Google Pixel 9a is lacking one of the Pixel 9’s best safety features — here’s what we know
vivo x200 ultra camera array
Vivo’s next premium phone could have a camera unlike anything we’ve seen before — here’s how
Google Pixel 9a with thumbs up and thumbs down icons
Google Pixel 9a — 5 reasons to buy and 3 reasons to skip
Pixel 9 Pro XL held in the hand with price drop badge.
Not a typo! This epic deal makes the flagship Pixel 9 Pro XL the same price as the budget Pixel 9a
Latest in News
Rendered images of rumored foldable iPhone.
Foldable iPhone report just revealed key details — here's what we know
NYTimes Connections
NYT Connections today hints and answers — Saturday, March 23 (#651)
NYT Strands on a cellphone
NYT Strands today — hints, spangram and answers for game #385 (Sunday, March 23 2025)
Nintendo Switch 2
Nintendo Switch 2 rumored specs — here’s what we know so far
iPhone 17 Pro render
iPhone 17 Pro — 7 biggest rumored upgrades
CAD renderings of the Google Pixel 10 Pro XL
Pixel 10 leak could be good news for all Android phones