Malware can be downloaded outside of Google Play (third-party Android app stores) Malware tricks and infects the users by launching a notification that pretends to be a system update. Malware sends various data to its Firebase C&C server just after getting installed on the device. This malware collects data directly if it has root access or uses the Accessibility Services function on the compromised device. And the data that it sends includes storage stats, ISP details, and installed apps.”]
Source: https://gbhackers.com/newly-discovered-system-update-android-malware-steals-photos-videos/

