A friend of mine asked me help him to examine his Android 5.0 smartphone. He did not say "s wrong with his phone," and he just wonder why he wife know everything he chats on the phone, and wher E He has been.
I ' d like-to-help him-to-figure out if anything wrong on his phone. When I start to monitor his phone, I find a very interesting stuff running on his phone. Obviously it try to pretend it's Google Play App, actually it's not ... Also I could see the destination IP and port ...
I start to Analye and figure out where it is. Yes that ' s it: A very suspicious package-"Com.example.downloader"
Look at the Manifest and it ' s really scaring. It can read/write SMS, storage, contacts, calendar,locactions, process outgoing calls, even recording audio.
Guess what? It also could record chat messages including Naver line, Facebook, what ' s App, Skype, and WeChat. No wonder his wife knows everything he chats on the phone. You could see the Naver line chat messages recording in its own Database as below.
I told him what I found on his phone, and he is very angry. He swore to the figure out what the his wife have done to his phone and when she does this. I told Hime that maybe she bought the "this App" on the internet or her friend taught hers to do so. I think the reason why she does it maybe she's afraid that she husband does isn't love her anymore. If her husband have affair with other girls and she'll know immediately. Still it ' s illeagl and it's not a right thing to do to the one of your love.
Android Malware Analysis