Technology
What you need to know about VajraSpy RAT, the cyber espionage tool that infiltrated Google Play
You might think that downloading an app from the app store is safe and easy, right? Well, not always. Sometimes, you might actually end up with a nasty surprise: an app that is actually spyware hiding behind a fake name and icon.
That’s what the VajraSpy RAT does. It’s a Trojan that targets Android devices and steals your data without you knowing. This is a real threat that has affected many Android users.
Although VajraSpy has been removed from the Google Play Store, it’s still lurking out there on third-party app stores. Also, VajraSpy and the Patchwork APT group behind it are still active. They may attempt to infiltrate other platforms or modify their tactics to evade Google’s detection in the future.
To protect yourself, here’s what you need to know about VajraSpy RAT, the cyber espionage tool that’s infiltrated Google Play on Android.
CLICK TO GET KURT’S FREE CYBERGUY NEWSLETTER WITH SECURITY ALERTS, QUICK VIDEO TIPS, TECH REVIEWS AND EASY HOW-TO’S TO MAKE YOU SMARTER
Illustration of a hacker (Kurt “CyberGuy” Knutsson)
What is cyber espionage tool VajraSpy RAT?
VajraSpy is a remote access Trojan (RAT), which is a type of malware that’s designed to allow an attacker to control an infected device remotely. To get the RAT on your devices, scammers need you to download it to your system. Once the RAT is running on a compromised system — in this case, your Android — the attacker can send commands to it and receive data back in response.
MORE: HOW TO CHANGE YOUR PRIVACY SETTINGS ON YOUR ANDROID DEVICES
What are some of cyber espionage tool VajraSpy’s capabilities?
Some of VajraSpy’s capabilities are accessing and taking your contacts, photos and messages. This even includes encrypted messages like those on WhatsApp. Also, searching and exfiltrating documents, images, audio and other types of files.
In addition, it can listen in on and record your phone calls (if granted the appropriate permissions) and activate your device’s camera to take pictures, turning it into a surveillance tool.
A person on social media on their Android (Kurt “CyberGuy” Knutsson)
MORE: BEWARE OF NEW ANDROID MALWARE HIDING IN POPULAR APPS
How does cyber espionage tool VajraSpy RAT get onto your Android device?
VajraSpy gets onto an unsuspecting victim’s device via a malicious app. When the RAT was first discovered, it was on apps that were found on Google Play sometime between April 1, 2021, through Sept. 10, 2023.
ESET researchers uncovered the campaign report in 2022 when Patchwork APT — a hacking group primarily targeting people in Pakistan that’s been around since 2015 — exposed their campaign after unintentionally infecting their own infrastructure with another RAT they were experimenting with.
When this was leaked and VajraSpy was discovered, the infected apps on Google Play were taken down. But they can still be found in third-party apps, with some still getting through to Google Play anyway.
What are the third-party apps?
VajraSpy has been disguising itself primarily in news and messaging apps on Android. Some of the apps that researchers know about include:
- Rafaqat رفاقت
- Privee Talk
- Chit Chat
- Hello Chat
- YohooTalk
- MeetMe
- Let’s Chat
- Quick Chat
- TikTalk
- Nidus
- GlowChat
- Wave Chat
Google Play Protect protects users by automatically removing apps known to contain this malware on Android devices with Google Play Services. However, it is important to note that Google Play Protect may not be enough. Historically, it isn’t 100% foolproof at removing all known malware from Android devices. If, for some reason, you still see these apps on your phone, be sure to manually uninstall them.
How to uninstall apps on Android
Settings may vary depending on your Android phone’s manufacturer.
- Open the Settings app
- Scroll down and select Apps
- Tap on the app you want to delete and select Uninstall
- Confirm your choice by tapping OK or Uninstall again
Have good antivirus software on all your devices
We also recommend going beyond Google Play Protect to keep yourself from having your data breached. As we all know, free is not always the way to go, especially when we are talking about antivirus protection. Keeping hackers out of your devices can be prevented if you have good antivirus software installed. Find my review of Best Antivirus Protection here.
How to keep yourself safe from cyber espionage tool VajraSpy RAT and other Trojans
Remember, the bad guys behind VajraSpy and similar malware perpetrators are pretty quick. They keep infecting new apps with this Trojan, so always keep an eye out by using the following tips:
Tip #1 – To avoid getting your Android infiltrated by VajraSpy RAT, don’t download any apps that are recommended by someone you don’t know or don’t know well. And if the message does come from someone you know, always be a little skeptical, especially if you have never heard of the app.
Tip #2 – Make sure to only download apps from reputable app stores you’re familiar with, too. Keep in mind, though, that these bad actors are able to get new apps to slip through the cracks of Google Play time and time again. Therefore, it’s important to employ a mix of different strategies to keep yourself safe.
Tip #3 – One way to know whether or not an app is safe is by looking at how many downloads it has. If it has a small number of downloads, chances are it could be a scam. Also, look at how many reviews it has and what those reviews are and do a quick check to see if someone mentioned it as a scam or not. A good rule of thumb is if you don’t need it, and you’re not sure, don’t download it.
The good news is that compared to other spyware apps, VajraSpy hasn’t been that successful. We know this by looking at the amount of downloads/installations of the apps it disguises itself as. That being said, those third-party app stores where you can still find a lot of these malicious apps don’t track downloads well, so it’s hard to know how many victims fell for VajraSpy there.
A man on his Android phone (Kurt “CyberGuy” Knutsson)
MORE: BEWARE OF THIS MCAFEE GOOGLE CHROME AD SCAM
Kurt’s key takeaways
Though there are much bigger scams to be concerned with, letting your guard down could make you more vulnerable to attacks like this cyber espionage tool called VajraSpy RAT. To protect your Android and your data, just remember to be cautious if you see an invitation to download a messaging app from someone you don’t know well. Also, invest in antivirus software to protect your Android.
Have you ever received a strange message that asked you to download an app? What happened? Let us know by writing us at Cyberguy.com/Contact.
For more of my tech tips & security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter.
Ask Kurt a question or let us know what stories you’d like us to cover.
Answers to the most asked CyberGuy questions:
Copyright 2024 CyberGuy.com. All rights reserved.
Technology
Microsoft is disabling Office 2019 for Mac next month
Microsoft’s Office 2019 apps for Mac will stop working next month, because the company isn’t renewing a certificate that validates Office licenses. Owners of Office 2019 for Mac are being warned they’ll have to purchase Office 2024 or a Microsoft 365 subscription if they want to continue editing documents.
Microsoft previously promised that “all your Office 2019 apps will continue to function,” when it announced end of support in 2023. The company then quietly updated that support note last month to remove the mention of apps continuing to function, replacing it with “Rest assured that all your Office 2019 apps won’t lose any data.”
Starting on July 13th, Office 2019 for Mac and Office 2021 for Mac will both run in “reduced functionality mode,” allowing people to open files but not edit, save, or create new documents. The reduced functionality will impact Word, Excel, PowerPoint, Outlook, and OneNote.
While Microsoft is providing a certificate update for Office 2021 as it’s still supported until October 13th, 2026, the company is leaving Office 2019 for Mac users out in the cold as support for these apps ended a few years ago. “Office 2019 for Mac reached end of support on October 10, 2023, and no longer receives updates,” says Microsoft. “Because Office 2019 cannot be updated to the required version, this issue cannot be resolved by updating or reinstalling Office 2019 for Mac.”
JimmyTech points out that old versions of Microsoft 365 apps on Mac and iOS will also be affected by this certificate issue, but a simple update will fix it for those users.
Microsoft regularly ends support of software and there’s always the risk you could run into issues running older apps or versions of Windows. It’s still surprising to not see Microsoft make an exception here though, particularly because this certificate issue breaks the main functionality of an app you’ve paid a one-time license fee for.
Technology
Android fake call detection warns you about scams
NEWYou can now listen to Fox News articles!
You know that little moment when your phone rings and the name on the screen makes you drop everything?
Maybe it says your spouse, your daughter, your boss or your best friend. You answer because you trust the name. Then the voice sounds familiar too.
That is exactly what makes the latest phone scams so dangerous.
Android’s fake call detection can warn you when a caller may be pretending to be someone saved in your contacts. (Silas Stein/Picture Alliance)
Scammers no longer have to call from a strange number. They can spoof a trusted contact’s phone number. Then they can use AI voice tools to sound like someone you know. Android is now rolling out a new feature called fake call detection to help warn you when that familiar call may be a fake.
FAKE AGENT PHONE SCAMS ARE SPREADING FAST ACROSS THE US
Join CyberGuy Live: Lock Down Your Phone in 30 Minutes (Saturday, June 13, 10 am ET)
- Your phone holds your email, passwords, photos, banking apps and personal data. In this free, live online class, Kurt the CyberGuy will walk you step by step through simple phone security fixes you can do in real time. You’ll learn how to improve your privacy settings, spot the latest phone scams, use trusted security tools and walk away with a simple checklist to stay protected. Register here: CyberGuyLive.com
What is Android fake call detection?
Android fake call detection is a new protection built into Phone by Google. It is designed to spot suspected spoofed calls when both people on the call use Phone by Google.
Think of it as your phone quietly asking, “Is this call really coming from that person’s device?” If the answer looks suspicious, your phone can show a warning and advise you to hang up. That small alert could stop a scam before fear, panic or confusion takes over.
ANDROID SECURITY UPGRADES OUTSMART SCAMS AND PROTECT YOUR PRIVACY
How Android fake call detection works
The feature works automatically in the background. You do not need to answer a quiz, scan a code or press a button during the call. When a trusted contact calls you, their phone sends a silent confirmation signal to your phone. That signal helps prove the call really came from their device.
If a scammer spoofs your contact’s number, that confirmation signal may be missing. Your phone then checks with your contact’s actual device. If the real device says it is not placing a call, your screen can warn you that the call may be fake.
The system uses end-to-end encrypted RCS technology, so the check happens privately. You can also turn the feature off in Phone by Google settings.
AI DEEPFAKE ROMANCE SCAM STEALS WOMAN’S HOME AND LIFE SAVINGS
Why fake calls are getting harder to spot
For years, caller ID gave people a sense of control. If the name looked familiar, most of us felt safer picking up. That old habit now works in the scammer’s favor.
Scammers can use internet-based calling tools to spoof numbers. That means your phone may display the name of someone you trust, even though the call comes from somewhere else.
Then comes the AI voice trick. With today’s audio tools, scammers can make a fake voice sound shockingly real. They may pretend to be a family member in trouble, a bank employee warning about fraud or a manager asking for urgent help.
SCAMMERS EXPLOITED MOM’S FEARS TO STEAL HER ENTIRE LIFE’S SAVINGS
That combination makes the call feel personal and immediate. It also makes you more likely to act before you think.
Why Android is adding this protection now
Impersonation scams have become a major global problem. INTERPOL’s March 2026 Global Financial Fraud Threat Assessment cited impersonation fraud as one of the leading contributors to more than $400 billion in global losses.
In the U.S., impersonation scams remain one of the top fraud categories reported to the FTC. Losses reached $2.95 billion in 2024.
GLOBAL SCAM CRACKDOWN LEADS TO 276 ARRESTS
Those numbers tell you why this feature deserves attention. Scammers go where the money is. Right now, they know trusted voices and trusted names can open the door.
Which Android phones get fake call detection?
Google says fake call detection is rolling out globally in Phone by Google this month, starting with Pixel devices.
The feature is available on Android 12 and newer devices with Phone by Google, Contacts and Google Messages installed. It also requires RCS capability in Google Messages.
SAMSUNG MESSAGES ENDING? WHAT ANDROID OWNERS MUST KNOW
There is one key limitation. Both you and the person calling you must use Phone by Google for fake call detection to work.
Phone by Google already comes as the default phone app on many Android devices. If your phone uses a different calling app, you can install Phone by Google from the Play Store and set it as your default phone app.
How Android fake call detection protects you
This feature gives you an extra warning at the exact moment you need it most. That timing is important. Scam calls often rely on emotion. The caller may say someone got arrested, a loved one had an accident or a bank account faces an urgent threat.
SSA IMPERSONATION SCAMS ARE GETTING MORE PERSONAL
When the voice sounds familiar, your guard drops. A warning on your screen can interrupt that emotional rush. It gives you a reason to stop, hang up and verify the story another way.
What Android fake call detection cannot do
This new tool helps, but it cannot protect you from every scam. It may not work if the other person does not use Phone by Google. It also may not cover calls from businesses, unknown numbers or contacts using unsupported devices. So you still need basic scam rules.
If someone asks for money, gift cards, crypto, account codes or remote access to your device, hang up. Then call the person or company back using a number you already trust.
Also, never stay on the line just because the caller tells you to. That is one of the oldest pressure tactics in the scammer playbook.
A spoofed call can look familiar on your screen, even when it is really coming from a scammer. (Kurt CyberGuy Knutsson)
How to protect yourself from AI voice scams
AI voice scams work because they sound personal, urgent and believable, so your best defense is to slow the conversation down before you act.
1) Create a family safe word
Pick a simple word or phrase that only your close family knows. It should be easy to remember but hard for a scammer to guess. Then, if someone calls with an emergency and asks for money, ask for the safe word. If they cannot give it, hang up and verify the story another way.
9 WAYS SCAMMERS CAN USE YOUR PHONE NUMBER TO TRY TO TRICK YOU
2) Pause when the call feels urgent
Scammers want you scared because fear makes people act fast. That is why fake emergency calls often sound intense, emotional and rushed. Take a breath before you do anything. A real loved one, bank or employer will let you verify what is happening.
3) Call back using a trusted number
If a call feels suspicious, hang up. Then call the person back using a number saved in your contacts or one you know is real. Do not use a number, link or instruction the caller gives you. That could send you right back to the scammer.
4) Never send money or codes during the call
Do not send gift cards, crypto, wire transfers or payment app transfers because a caller sounds convincing. Also, never share a one-time passcode, PIN or account login code over the phone. Once scammers get that information, they can move fast.
5) Turn on scam protections on your phone
Use the built-in protections already available on your device. Pixel and Samsung users can enable Scam Detection in the Phone by Google app to help flag suspicious calls. Also, consider using strong antivirus software that includes AI-powered scam protection to help detect scams in texts, online content and deepfake videos. Keep an eye on call warnings too. If your phone tells you something looks risky, treat that alert seriously. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com
6) Keep your phone apps updated
Update Phone by Google, Google Contacts and Google Messages when updates are available. These tools work best when your apps and phone software stay current. Updates often include security improvements, bug fixes and new scam protections.
Here’s how to check for updates on Android:
- Open the Google Play Store app.
- Tap your profile icon in the top right corner.
- Tap Manage apps & device.
- Under Updates available, tap See details.
- Look for Phone by Google, Google Contacts and Google Messages.
- Tap Update next to each app, or tap Update all.
You can also turn on automatic app updates by opening the Google Play Store app, tapping your profile icon, then going to Settings > Network preferences > Auto-update apps. From there, choose whether to update apps over Wi-Fi, over Wi-Fi or mobile data, with limited mobile data or not at all.
Kurt’s key takeaways
If a call feels urgent or suspicious, pause before you respond and verify it another way. (Tristan Spinski/The Washington Post via Getty Images)
Android’s fake call detection is a smart step in the fight against AI-powered phone scams. It recognizes something many people already know: the name on your caller ID no longer proves the person calling you is real. This feature gives Android users another layer of protection when scammers try to hijack trust. Still, the safest move remains simple. Slow down, verify the call and never let panic make the decision for you.
Should the government do more to stop scammers from using AI voices to impersonate the people you trust? Let us know by writing to us at CyberGuy.com
Sign up for my FREE CyberGuy Report
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
- Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
- For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com – trusted by millions who watch CyberGuy on TV daily.
- Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.
Copyright 2026 CyberGuy.com. All rights reserved.
Technology
Congress just gave DHS another $70 billion
Congress narrowly voted to fund President Donald Trump’s mass deportation agenda, giving the Department of Homeland Security $70 billion over the next three years.
The house voted 214 to 212 in favor of the reconciliation bill Tuesday, following the Senate’s 52-47 vote last Friday morning. The vote fell largely along party lines. Sen. Lisa Murkowski (R-AK) was the only Senate Republican to vote against it. Rep. Tim Walberg (R-MI), initially voted against the bill — meaning it would have failed — but changed his vote after huddling with House Majority Leader Steve Scalise (R-LA) and Appropriations Chair Tom Cole (R-OK), according to The Hill. No Democrats voted in favor of the funding bill, which was done through a budget reconciliation process to avoid a Democratic filibuster.
In a speech on the House floor ahead of the Tuesday vote, Rep. Mary Gay Scanlon (D-PA) criticized Republicans for using the budget reconciliation process to avoid negotiating with Democrats, and emphasized ICE’s lack of popularity with the American people.
“At its core, this Republican reconciliation budget bill is a statement about priorities, and the priorities represented in this budget bill could not be more out of step with the needs and values of the American people,” Scanlon said.
Scanlon noted that DHS has yet to spend $100 billion of the nearly $200 billion it received under Trump’s One Big Beautiful Bill Act. She added that Trump has not only expanded ICE’s reach by increasingly going after legal immigrants but also weaponized DHS against its critics. The bill, she said, will “supercharge” Trump’s abuses.
After the House markup last Friday, Rep. Rosa DeLauro (D-CT), ranking member of the House Appropriations Committee, noted that the bill not only lacks sufficient reforms but also cuts funding for cybersecurity and TSA, whose workers went weeks without pay during the DHS shutdown.
The funding bill comes at a time of deep unpopularity for ICE. One recent poll found that just 33 percent of voters approve of how the agency is doing its job.
And it comes amid yet another threat from border czar Tom Homan to flood New York City with ICE agents. In an interview with Fox News on Monday, Homan said he would send “more ICE agents than you’ve ever seen” to New York City if the state government passed a bill limiting cooperation with DHS.
“Providing a quarter trillion dollars to an administration promising that the public ‘ain’t seen shit yet’ when it comes to mass deportation is a historic mistake,” Todd Schulte, president of the immigration reform group FWD.us, said in a statement. “Supercharging the funding for these already out of control systems will come with terrible human consequences and continue to be met with increasing opposition from voters.”
Correction, June 9th: A previous version of this story said Rep. Tim Walberg voted against the funding bill. He initially voted against it but then changed his vote to support it.
Update, June 9th: This story has been updated to include comment from FWD.us president Todd Schulte.
-
Milwaukee, WI2 minutes ago50 electric school buses to transport MPS kids starting this fall
-
Atlanta, GA7 minutes agoAtlanta Dream hold off Chicago Sky 82-75, Rhyne Howard becomes youngest player to hit rare WNBA milestone
-
Minneapolis, MN14 minutes agoOperation Metro Surge cost Minneapolis $700 million, city leaders say
-
Indianapolis, IN17 minutes agoPerson fatally shot on north side of Indianapolis
-
Pittsburg, PA22 minutes ago12+ things to do this weekend, from Pogopalooza and PizzaFest to the Beers of the Burgh Festival
-
Augusta, GA29 minutes ago
World Cup: Where to find a crowd to catch all the action
-
Washington, D.C32 minutes agoPermanent jewelry and pop-ups: Forever Adorned brings custom pieces to your stack
-
Cleveland, OH37 minutes agoOhio House passes Amanda Dean’s Law