Google Assistant May Support Malware That Steal Users' Passwords
Aadhya Khatri
In an experiment, a research lab succeeded developing apps for Alexa and Google Assistant with the main purpose is to phish for users’ information
- Google Assistant Now Makes It Irresistible To Wear Face A Mask
- Here's How To Get A Makeshift Podcast From Any Text-Based Story
- How To Curb Your Roommate's Laziness: Google Assistant's 'Sticky Notes'
Now we have more Google Assistant apps than anyone can ever use, so slipping some malware to the mix is not that hard to execute.
In an experiment, a research lab succeeded developing apps for Alexa, and Google Assistant with the primary purpose is to phish for users’ information. The lab in question is Germany’s Security Research Labs and they have created a total of eight apps, all of which have passed the security screening of Google and Alexa.
The apps are horoscope checkers. While they may work a bit different from the other, all of them have the same underlying principle. What they really do is to listen and steal users’ passwords.
So here is how they work. The user may ask for something like:
“OK Google, ask My Lucky Horoscope to give me the horoscope for Taurus.”
After giving the user what he or she wants, the app will play the sound that Google uses when a third-party app has been closed to give the impression that the app is no longer running. After the sound is played, the app will record for the next 30 seconds and send all the recordings to a server.
The video down below shows another example of an app mimicking the voice of Google Assistant to fool users that it has been closed. It will wait for a minute and then mimic the voice again to steal users’ passwords for their Google accounts.
The second way of attack is easier to detect than the first one. The apps the researchers in this experiment have been removed but they show that Google and Amazon need to be more careful not letting malicious apps slipping through their defense like that.
Featured Stories
ICT News - Mar 29, 2026
FTC Takes Action Against Debanking Practices by Major Financial Firms
ICT News - Mar 27, 2026
Palantir CTO Identifies Iran Conflict as First Large-Scale AI-Driven War
ICT News - Mar 24, 2026
OpenAI on the Brink: Major Setbacks Signal the Bursting of the AI Bubble
ICT News - Mar 20, 2026
Top 10 Most Popular Social Media Sites Based on User Count in 2026
ICT News - Mar 19, 2026
Billion Dollar Blunder: Meta Shuts Down Metaverse After Wasting $80,000,000,000.00
ICT News - Mar 18, 2026
X to Introduce Regional Controls for Posts and Replies
ICT News - Mar 17, 2026
Is DLSS 5 Helping Games or Hurting Developers' Creative Style?
ICT News - Mar 16, 2026
AI's Role in Warfare: US Strikes on Iran Unveiled
ICT News - Mar 15, 2026
Elon Musk's Bold Chip Venture: Tesla's Massive Fab Initiative Sparks AI Hardware...
ICT News - Mar 14, 2026
Elon Musk's High-Stakes $109 Billion Lawsuit Against OpenAI and Microsoft
Read More
ICT News- Mar 29, 2026
FTC Takes Action Against Debanking Practices by Major Financial Firms
The Federal Trade Commission has sent warning letters to PayPal, Stripe, Visa, and Mastercard over concerns about debanking lawful businesses and consumers.