This malicious fake YouTube app could hijack your phone and record all your secrets
Avid mobile YouTube users, especially those engaged in diplomacy work in Pakistan and India, should be very careful when downloading the famed video app, as experts have uncovered at least three fake YouTube apps that are, in fact, remote access trojans (RAT), going after their data.
Cybersecurity researchers from SentinelLabs recently observed a threat actor known as Transparent Tribe (APT36), likely using social channels and fake landing pages to distribute apps that look like YouTube but are instead malware known as CapraRAT. The apps aren’t found in the official Google Play Store, Google confirmed to the media.
This remote access trojan can steal all sorts of sensitive data from the endpoint (SMS messages, call logs, GPS data, etc.), but also record audio and video and send it to its operators. It can also grab screenshots, override system settings and modify files on the device’s filesystem. All of that is enough, among other things, to run successful identity theft campaigns, phishing attacks, and social engineering attacks, not to mention outright data theft.
Active for years
Two of the apps are simply named YouTube, while the third one is called Piya Sharma – after an Indian anchor and influencer, and most likely used in romance-based fraud. All apps request extensive permissions at installation, which should be enough of a red flag for most people. If that wasn’t enough, the apps look more like a web browser than a native app and miss some of the features present in the legitimate YouTube app.
SentinelLabs says APT36 is most likely aligned with the Pakistani government and targets Indian defense and government entities, human rights activists, diplomats engaged in the Kashmir region, and similar.
The group has been active since at least 2018, and was observed earlier this year distributing CapraRAT apps disguised as dating services. To make sure you don’t fall for the trick, make sure to always download apps from official repositories only (for example, Google Play Store, or the Galaxy Store), and be wary of any permissions the apps request at installation.
More from TechRadar Pro
Avid mobile YouTube users, especially those engaged in diplomacy work in Pakistan and India, should be very careful when downloading the famed video app, as experts have uncovered at least three fake YouTube apps that are, in fact, remote access trojans (RAT), going after their data. Cybersecurity researchers from SentinelLabs…
Recent Posts
- Apple begins requiring age verification for App Store use in Texas
- Apple is bringing age verification to Texas this week
- How to watch NBA Finals 2026: Free streams, schedule, TV channels for New York Knicks vs San Antonio Spurs
- WiiM expands its whole-home ecosystem with a new soundbar
- You can make the hyper-violence in Marvel’s Wolverine more PG-13, if you want to
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023