Explorer

Amazon Takes Down BMI CalculationVsn App From Its Appstore After Spotting Android Malware In It

Marketed as a basic body mass index (BMI) calculator, the BMI CalculationVsn app concealed dangerous malware.

Researchers at McAfee Labs recently uncovered a malicious Android spyware app on the Amazon Appstore called BMI CalculationVsn. Disguised as a straightforward health tool, the app secretly harvested sensitive data from devices it infected. Upon being alerted by the researchers, Amazon promptly removed the app from the store.

However, users who downloaded it need to uninstall the app manually and run a comprehensive scan to ensure all remnants are completely removed.

Android Spyware On Amazon Store: What Do We Know?

The Amazon Appstore, a third-party marketplace for Android apps, comes pre-installed on Amazon Fire tablets and Fire TV devices. Among the apps available on the store was the malicious BMI CalculationVsn, published by "PT Visionet Data Internasional." Marketed as a basic body mass index (BMI) calculator, the app concealed a dangerous spyware operation.

When opened, the app presents a straightforward interface that performs BMI calculations as advertised. However, behind the scenes, it engages in covert activities. For instance, it activates a screen recording service, requesting the necessary permissions when users click the "Calculate" button. This action could easily deceive users into granting access without realising its implications.

ALSO READ | Samsung Galaxy S25 Ultra Leaks: Standard & Plus Model To Feature Colour Variants, Ultra To Come In 7 Titanium Shades

According to McAfee researchers, the recorded screen captures were saved locally as MP4 files but were not uploaded to a command-and-control (C2) server. This behaviour suggests the app might still have been in its early testing phase. Further investigation revealed that the app was first introduced on October 8. By the end of the same month, it had undergone significant changes, including a new icon, additional malicious features, and updated certificate information.

The app’s second malicious activity involves scanning the device to compile a list of all installed applications, enabling attackers to strategise their next moves. Additionally, the spyware intercepts and collects SMS messages stored or sent from the device, including sensitive data such as one-time passwords (OTPs) and verification codes.

Read more
Sponsored Links by Taboola

Top Headlines

'Biggest Mess...': Indian Techies Stranded After US Reschedules Visa Interviews Amid New Vetting Rules
'Biggest Mess...': Indian Techies Stranded After US Reschedules Visa Interviews Amid New Vetting Rules
'Desh Me Do Namoone...': Yogi Adityanath Attacks Oppn, Akhilesh Hits Back With Delhi-Lucknow 'Rift' Jibe
'Desh Me Do Namoone...': Yogi Adityanath Attacks Oppn, Akhilesh Hits Back With 'Rift' Jibe
Bangladesh Freezes Visa Services In Three Indian Cities Amid Unrest Back Home
Bangladesh Freezes Visa Services In Three Indian Cities Amid Unrest Back Home
8th Pay Commission Delay Could Quietly Cost Govt Employees Up To Rs 3.8 Lakh In HRA
8th Pay Commission Alert: Delay Could Cost Govt Employees Up To Rs 3.8 Lakh In HRA

Videos

West Bengal Politics: Humayun Kabir Launches ‘Janta Unnayan Party’ in Murshidabad, Targets TMC and BJP Ahead of 2026 Polls
Delhi NCR: Battles Toxic Air as AQI Stays Above 400 Amid Cold Wave and Dense Fog
Aviation Breaking: Air India Flight AI-887 Returns to Delhi After Engine Oil Pressure Drops to Zero
SP Stages Protest Outside UP Assembly Over Codeine Syrup Case Ahead of Key Legislative Agenda
Breaking: 18-Year-Old Girl Pushed from Moving Local Train in Navi Mumbai, Accused Arrested

Photo Gallery

25°C
New Delhi
Rain: 100mm
Humidity: 97%
Wind: WNW 47km/h
See Today's Weather
powered by
Accu Weather
Embed widget