The Overseer malware was found in four apps live on the Google Play store. One of the apps was an Embassy search tool intended to help travelers find embassies abroad. The malware was also injected as a trojan in Russian and European News applications for Android. Google promptly removed the four affected apps after Lookout notified the company. The spyware is capable of exfiltrating a significant amount of information from an infected device. Its command and control (CNC) uses Facebooks Parse Server, hosted on Amazon Web Services.”]
Source: https://blog.lookout.com/embassy-spyware-google-play

