A malicious Android spyware application, named 'BMI CalculationVsn,' was recently discovered on the Amazon Appstore. The app masqueraded as a simple BMI calculator but was secretly stealing user data. The app, published by ‘PT Visionet Data Internasional,’ appeared to offer a basic body mass index calculation, but it also initiated a screen recording service and scanned devices for installed applications. The app also had the ability to intercept incoming SMS messages, which included one-time passwords and verification codes, and stored this information.
McAfee Labs researchers identified the malicious activity and promptly notified Amazon, leading to the app's removal from the store. However, users who installed 'BMI CalculationVsn' need to manually uninstall it and conduct a full scan of their devices to ensure the spyware is completely removed. The app's activity was traced back to October 2024, with the spyware initially recording screens before it added the BMI calculator interface and SMS interception capabilities. This incident serves as a reminder to exercise caution when downloading apps, even those that appear innocuous.