Botnets are large illegal networks of infected machines – usually desktop or laptop computers – typically used to send out masses of spam email.
Researcher Terry Zink said there was evidence of spam being sent from Yahoo mail servers by Android devices.
Microsoft’s own platform, Windows Phone, is a key competitor to Android.
The Google platform has suffered from several high-profile issues with malware affected apps in recent months.
The official store – Google Play – has had issues with fake apps, often pirated free versions of popular paid products like Angry Birds or Fruit Ninja.
This latest discovery has been seen as a change of direction for attackers.
“We’ve all heard the rumors,” Terry Zink wrote in a blog post.
“But this is the first time I have seen it – a spammer has control of a botnet that lives on Android devices.
“These devices login to the user’s Yahoo Mail account and send spam.”
He said analysis of the IP addresses used to send the email revealed the spam had originated from Android devices being used in Chile, Indonesia, Lebanon, Oman, Philippines, Russia, Saudi Arabia, Thailand, Ukraine, and Venezuela.
As is typical, the spam email looks to tempt people into buying products like prescription drugs.
Security expert Graham Cluley, from anti-virus firm Sophos, said it was highly likely the attacks originated from Android devices, given all available information, but this could not be proven.
This was the first time smartphones had been exploited in this way, he said.
“We’ve seen it done experimentally to prove that it’s possible by researchers, but not done by the bad guys,” he said.
“We are seeing a lot of activity from cybercriminals on the Android platform.
“The best thing you can do right now is upgrade your operating system, if that’s possible.
“And before you install apps onto your device, look at the reviews, because there are many bogus apps out there.”
Google said it did not respond to queries about specific apps but was working to improve security on the Android platform.
“We are committed to providing a secure experience for consumers in Google Play, and in fact our data shows between the first and second halves of 2011, we saw a 40% decrease in the number of potentially malicious downloads from Google Play,” a spokesman said.
“Last year we also introduced a new service into Google Play that provides automated scanning for potentially malicious software without disrupting the user experience or requiring developers to go through an application approval process.”
The US House Ethics Committee has voted to release its report on former Republican Representative…
ABC News has agreed to pay $15 million to President-elect Donald Trump to settle a…
South Korea’s parliament has voted to impeach President Yoon Suk Yeol over his failed attempt…
Israeli war planes have carried out more than 100 air strikes in Syria on December…
President-elect Donald Trump has threatened to impose 100% tariffs on the BRICS countries if they…
Syrian troops have withdrawn from the city of Aleppo following an offensive by rebels opposed…