Pinduoduo App Accused of Using Malware to Spy on Users
Cybersecurity researchers have identified sophisticated malware within Pinduoduo, a major Chinese shopping application used by over 750 million monthly users. The malicious code allegedly exploits vulnerabilities in Android operating systems to bypass security measures, allowing the app to monitor user activities, read private messages, check notifications, and modify device settings. Investigations involving multiple international cybersecurity firms and former employees suggest these exploits were designed to spy on users and competitors to boost sales. While Pinduoduo has denied these accusations, Google suspended the app from its Play Store in March due to similar findings. This revelation intensifies scrutiny on Chinese-developed apps regarding data security and privacy violations. Although there is no evidence that Pinduoduo shared data with the Chinese government, concerns persist among US lawmakers about potential coercion. The scandal also casts a shadow over Temu, Pinduoduo’s international sister app owned by parent company PDD, which is rapidly expanding in Western markets. Experts describe the privilege escalation tactics as highly unusual for a mainstream application, marking a significant breach of user trust and data security standards.
Wire timeline
Pinduoduo App Accused of Using Malware to Spy on Users
Cybersecurity researchers have identified sophisticated malware within Pinduoduo, a major Chinese shopping application used by over 750 million monthly users. The malicious code allegedly exploits vulnerabilities in Android operating systems to bypass security measures, allowing the app to monitor user activities, read private messages, check notifications, and modify device settings. Investigations involving multiple international cybersecurity firms and former employees suggest these exploits were designed to spy on users and competitors to boost sales. While Pinduoduo has denied these accusations, Google suspended the app from its Play Store in March due to similar findings. This revelation intensifies scrutiny on Chinese-developed apps regarding data security and privacy violations. Although there is no evidence that Pinduoduo shared data with the Chinese government, concerns persist among US lawmakers about potential coercion. The scandal also casts a shadow over Temu, Pinduoduo’s international sister app owned by parent company PDD, which is rapidly expanding in Western markets. Experts describe the privilege escalation tactics as highly unusual for a mainstream application, marking a significant breach of user trust and data security standards.
CNN.com - RSS Channel - App International Edition