Google Assistant May Support Malware That Steal Users' Passwords

Aadhya Khatri - Oct 22, 2019


Google Assistant May Support Malware That Steal Users' Passwords

In an experiment, a research lab succeeded developing apps for Alexa and Google Assistant with the main purpose is to phish for users’ information

Now we have more Google Assistant apps than anyone can ever use, so slipping some malware to the mix is not that hard to execute.

In an experiment, a research lab succeeded developing apps for Alexa, and Google Assistant with the primary purpose is to phish for users’ information. The lab in question is Germany’s Security Research Labs and they have created a total of eight apps, all of which have passed the security screening of Google and Alexa.

Google Home Mutemic 1500x1000
In an experiment, a research lab succeeded developing apps for Alexa and Google Assistant with the main purpose is to phish for users’ information

The apps are horoscope checkers. While they may work a bit different from the other, all of them have the same underlying principle. What they really do is to listen and steal users’ passwords.

So here is how they work. The user may ask for something like:

“OK Google, ask My Lucky Horoscope to give me the horoscope for Taurus.”

After giving the user what he or she wants, the app will play the sound that Google uses when a third-party app has been closed to give the impression that the app is no longer running. After the sound is played, the app will record for the next 30 seconds and send all the recordings to a server.

The video down below shows another example of an app mimicking the voice of Google Assistant to fool users that it has been closed. It will wait for a minute and then mimic the voice again to steal users’ passwords for their Google accounts.

The second way of attack is easier to detect than the first one. The apps the researchers in this experiment have been removed but they show that Google and Amazon need to be more careful not letting malicious apps slipping through their defense like that.

Comments

Sort by Newest | Popular

Next Story

Read more

X Platform Implements Strict Measures Against Fake AI-Generated Videos Amid Iran Conflict

ICT News- Mar 05, 2026

X Platform Implements Strict Measures Against Fake AI-Generated Videos Amid Iran Conflict

In the meantime, users are advised to scrutinize sources, check for AI indicators, and rely on verified news outlets.

Samsung Galaxy S26 Series Sets New Pre-Order Records: Ultra Model Captures 70 Percent of Sales

Mobile- Mar 06, 2026

Samsung Galaxy S26 Series Sets New Pre-Order Records: Ultra Model Captures 70 Percent of Sales

With such robust initial demand, the Galaxy S26 series is poised to outperform its predecessors in total sales, solidifying Samsung's dominance in the premium smartphone market.

Xiaomi Unveils Cutting-Edge 17 Series Smartphones and Teases Vision GT Hypercar

Mobile- Mar 07, 2026

Xiaomi Unveils Cutting-Edge 17 Series Smartphones and Teases Vision GT Hypercar

Xiaomi's MWC 2026 presentation highlights its ambition to dominate not just smartphones but also connected ecosystems and electric vehicles.