
Renowned mobile security company Pradeo has identified two file management apps available on the Google Play Store as spyware, endangering the privacy and security of up to 1.5 million Android users. These deceptive apps secretly transmit sensitive user data to malicious servers in China, raising serious concerns about the safety of personal information.
According to Pradeo’s investigation, both spyware apps, named File Recovery and Data Recovery (com.spot.music.filedate), with over 1 million installations, and File Manager (com.file.box.master.gkd), with over 500,000 installations, originate from the same source. Although these Android apps appear harmless, they employ similar malicious tactics and automatically launch upon device reboot without requiring user input.
Contrary to the claims made on the Google Play Store, where both apps assure users that no data is collected, Pradeo’s analytics engine has discovered that various personal information is being collected without users’ knowledge. The stolen data includes contact lists, media files (images, audio files, and videos), real-time location, mobile country code, network provider details, SIM provider network code, operating system version, device brand, and model.
What’s particularly alarming is the substantial amount of data these spyware apps transfer. Each app conducts over a hundred transmissions, a significant volume indicating malicious intent. Once the data is gathered, it is sent to multiple servers in China, which security experts have identified as malicious.
To make matters worse, the developers of these spyware apps have employed sly techniques to enhance their legitimacy and hinder uninstallation attempts. Hackers artificially inflated the number of app downloads using install Farms or mobile device emulators, creating a false sense of trustworthiness. Additionally, both apps possess advanced permissions that enable them to conceal their icons on the home screen, making it arduous for unsuspecting users to remove them.
Pradeo has provided security recommendations for individuals and businesses in light of this alarming discovery. Individuals are urged to exercise caution when downloading apps, especially those lacking ratings but claiming a significant user base. It is crucial to carefully read and comprehend app permissions before accepting them to prevent breaches.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543