By Sabeeh Zanair :
Security analysts have identified a sophisticated Android malware operation that allows attackers to secretly monitor phone calls, access private messages and extract sensitive personal data, highlighting the growing threat posed by modern mobile spyware.
The malware, known as Arsink, functions as an advanced Android Remote Access Trojan (RAT) that provides cybercriminals with deep control over infected devices. Once installed, it can quietly collect private information while remaining largely invisible to users.
Researchers discovered multiple variants of the malware that rely on popular cloud platforms for data theft and remote control. Some versions use Google Apps Script to transfer large files and media to Google Drive, while others exploit Firebase services and Telegram for command-and-control operations and data exfiltration.
According to security firm Zimperium, the campaign has reached a massive scale. Investigators identified more than 1,200 unique malicious app samples, with hundreds using Google-based services to upload stolen content. Over 300 Firebase databases were found to be linked to the operation, and analysis revealed around 45,000 unique infected IP addresses worldwide.
Unlike basic adware or typical financial malware, Arsink behaves more like professional surveillance software. It is built for stealth and long-term monitoring, allowing attackers to spy on communications, steal credentials and remotely manipulate devices without alerting victims.
The malware primarily spreads through deceptive download links shared on messaging platforms and social networks rather than official app stores. Cybercriminals disguise malicious files as modified or “premium” versions of popular apps such as WhatsApp, Instagram, YouTube, Spotify and TikTok, tricking users into installing them from unofficial sources.
The campaign has a global reach, with infections reported across more than 140 countries. The highest numbers were recorded in Egypt and Indonesia, followed by Iraq, Yemen, Türkiye, Pakistan, India and Bangladesh — regions where third-party app downloads and Telegram sharing are common.
Once active, Arsink abuses Android’s permission system to gain extensive access. It can record phone calls, capture audio through the microphone, steal messages and contacts, take screenshots, read one-time passwords and execute remote commands via encrypted servers.
Google has confirmed that the malware is not distributed through the Play Store and stated that devices with Google Play Protect enabled receive automatic warnings. The company has also worked with researchers to dismantle parts of the malware’s infrastructure by shutting down several malicious cloud services used in the campaign.






