DU Antivirus Security??? You installed it on your phone?

You should check some apps on your phone.

Google removed from the Play Store - then restored to its original state - one of the most popular mobile antivirus apps, after Check Point security company discovered the application secretly collected Compile user data.

The application is called DU Antivirus Security and is a product of DU Group, a company of Baidu Group. According to the app's Play Store page, between 10 and 50 million people downloaded and installed the app.

Researchers at Check Point say in their report that they have detected suspicious behavior in the operation of this application. When users run DU Antivirus Security for the first time, it will collect information such as:

  • Identity.
  • Contacts.
  • Call history.
  • Location information, if possible.

DU Antivirus will then encrypt the data and send it to the remote server at address 47.88.174.218. Initially, the researchers said that the server was under the control of the malware author, but through the DNS records investigation and related subdomains showed that the host domain host was registered under the name of an employee of the malware. Baidu is Zhan Liang Liu.

The information will then be used by another DU Group application called Caller ID & Call BLock - DU Caller, intended to provide users with information about incoming calls.

Below is the name of the application containing the data collection code Check Point found on the Play Store:

So you should be careful about this and should remove them on your phone.

H2
H3
H4
3 columns
2 columns
1 column
Join the conversation now
Logo
Center