New 'unremovable' xHelper malware has infected 45,000 Android devices
zdnet.com
zdnet.com
https://www.youtube.com/watch?v=31D94QOo2gY
There are only so many places it can be hiding if it's surviving a factory reset.
--Guy who is undoubtedly vastly underestimating the problem given that it's resisted AV vendors for a while
Also, an anti virus company saying they can't understand how a virus remains infected after removal is interesting.
How uselessly cynical.
I've followed the VX scene for years (it died long ago) and there has never been shortage of new malware.
Even if we wanted to give some credit to the theory, which type of virus would the AV companies develop? Something trivial, that requires a variation of a signature to detect? Or something extremely complex, that requires month of work, and that slows down the AV engine because it's algorithmically complex to detect?
None of this makes any sense. The truth is very simple - malware has always been an interesting subject, and writing viruses always had a subversive appeal to young rebels.
Darn kids.
This analogy is not helping your case at all. It's not unheard of for police to plant evidence for such purposes. It's also been proven that law enforcement has been willfully using technology having high rates of false positives for things like drug testing to bring real charges against otherwise innocent people.
https://www.washingtonpost.com/nation/2019/07/11/florida-cop...
So very realistic then?
Or have you not encountered the numerous incidents where cops plant and manufacture evidence to frame people for various reasons such as increasing their numbers for a promotion or bad culture leading to quotas for arrests/tickets/etc.?
https://www.newyorker.com/humor/daily-shouts/l-p-d-libertari...
More like saying private 'protection companies' commit crimes so they can get you to pay for their 'protection'.
I didn't say they created malware, no, but they certainly wave that flag when someone finds some. And it's certainly in their interest to pursue all of these alternatives, or even have a bad third party violate THEM to do so. The money is on the table. Do they take it? They'd be foolish not to.
1. http://www.techradar.com/us/news/software/security-software/...
2. https://news.ycombinator.com/item?id=13079569
3. https://www.wsj.com/articles/russian-hackers-scanned-network...
4. https://wiki.mozilla.org/CA:Symantec_Issues
5. https://www.howtogeek.com/199829/avast-antivirus-was-spying-...
etc...
Based on the reddit thread at least one of the devices is from a no-name manufacturer.
https://www.reddit.com/r/antivirus/comments/bj6isa/xhelper_k...
Writing to /system requires it to be mounted read/write and permissions to do so, so they'd need a root exploit in order to pull it off, but there's quite a few to choose from especially as devices age and given that they're doing this outside Play Store where Google won't pick them up.
I'm just crossing my fingers advanced users don't lose the ability to side-load apps over bad publicity like this, maybe they should make it harder to enable though.
It seems like every time I hope for a reasonable solution like this I get let down substantially though.
IMO There is a slight flaw to how this question is worded. It's not that they block you from running code that you need to be root to run (you'll just get insufficient perms errors) it's just that you're not root. You could write the code to write to /system, and it will run it just will not work. Thus, you need to utilize some sort of local privilege escalation. That is it's own equally semi-sticky wicket.
And recovery is already a stretch IMO.
Software publishers which have been proven to be paying out commission money from "bait and install" app links, for things published in the Play Store, should have their entire app and developer profile removed with extreme prejudice.
Also from bulk analysis tools running against known-malware hosting http daemons out on the Internet. Anybody who's used an android phone for a sufficiently long time and visited a few weird places has seen the javascript redirects for scary-looking pages with "CLEAN 581 VIRUSES FROM YOUR PHONE NOW" pages, designed to mimic android or ios system GUI elements. Inevitably accompanied by a link to a play store page.
Play store should offer a screen to the users to allow them to report aggressive ads.
Some other comments are questioning weather this is happeneing to 'budget' devices sold by sketchy manufacturers. Would that explain something like this.
I sure as hell hope thats not the case on a phone from reputable manufacturer. If I can't wipe everything, including malware from my android device by doing a factory reset, I'm going to throw it in the garbage tomorrow & buy an iPhone.
I would imagine this malware modifies one of the partitions that is not customarily wiped. And I would expect that doing a proper full reflash from a computer (eg starting from `fastboot flash bootloader ...`) would remove it, assuming it wasn't already baked into that image at the manufacturer.
Clearly unpublished exploits are also bad, meaning this essentially applies to every phone. That's a pitfall of the closed security paradigm - even if you are willing to trust the manufacturer, you still can't be sure that their control has not actually been usurped by some unknown third party.
So you either need to double down and choose the closed system that receives the highest scrutiny (Apple), or opt for a device that has been opened by the community for long enough that any stateful hiding places are known.
A simple proof that this isn't the case is the fact that factory resets do not revert your phone back to the same OS version as it came with out of the box and it does not download an OS image to install. The only device I know that does this is macbooks have a built in recovery which can be used to download a fresh OSX image and install that.
On an unrooted/unexploited phone a factory reset should remove every bit of data bad app has access to. On a rooted phone you can wipe everything by downloading the vendor image (Google supplies these but not all OEMs do) and then you can flash that over the entire phone which replaces everything on the storage.
Maybe my memory is incorrect, but I'd be surprised if it did not revert back. I'm thinking of reseting soon, so if I do I'll report back :)
Ok, maybe don't do that?
In other words, the conclusion is right, but this incident is NOT the selling point. Ad blockers and manifest V3 is a much better research study into their stupidity.
Just noting that 45,000 users affected IS NOT the PlayStore failure reference story. It's bigger than that.
10 million uBlock Origin Chrome users are soon to be abandoned due to Google's policies. That's way more interesting, and ties the PlayStore issues to the same Chrome Extension issues.
Apple is credibly watching out for their customers. Google is credibly watching out for Google. Pretty much unapologetically with little pushback.
Personally frustrating for me as I've been a loyal Android user for a long time. Almost ready to switch to an iPhone, despite my unfamiliarity and the much higher price point. Google should pay attention.
There is a permission on android called "Draw over other apps" which is disabled by default now when you install the app but the app can open a popup asking you to enable it which android warns you against accepting.
The valid use cases for this permission is you could have PIP for videos.
Yes its pretty bad but its not like any app can just draw adverts over the screen.
https://mashable.com/2017/06/12/apple-app-store-subcription-...
https://9to5mac.com/2019/10/25/malware-iphone-apps/
https://www.techtimes.com/articles/235985/20181204/apple-rem...
https://www.wired.com/2015/09/apple-removes-300-infected-app...
They get so much wrong, so often, you have to wonder if they really look at the apps at all or just have some checklist, screenshots and a quota to hit. They explicitly approved all the garbage practices that Apple Arcade's billing protects users from.
From my own app review experience, this is all they do.
A shady developer tricking people and a shady website tricking people result in bad things.
To get this trojan I'd need to go into settings and tick this box:
https://q3fb03rfy3f4ahuzu2uy6e11-wpengine.netdna-ssl.com/wp-...
Then go to the dodgy website, then download the apk, then install it then pikachu face when I get a trojan.
And you can talk about how great Apple's security is but to fix this issue all Google has to do is remove that tick box in settings so no more sideloading apps.
But that also comes back with drawbacks that I assume an Apple user like yourself wouldn't know about, because all you know is a walled garden. Sort of like how Chinese people love the fact their internet is censored. So safe, so secure.
Yes, truly... because there's no way that someone who uses an iPhone might know about the existence of Android/Windows/Linux/macOS or any other system that allows for sideloading and/or installing un-certed apps.
The point is, even if Apple allowed sideloading, there's no way that the iOS sandbox model would allow for what's being described here. The comparison wasn't accurate.
Your condescension and ignorance doesn't help that argument at all.
And yet, they don’t.
> But that also comes back with drawbacks that I assume an Apple user like yourself wouldn't know about, because all you know is a walled garden.
Funny how Android users keep saying that. I’m an Android developer by profession, which is why I use an iPhone as my personal phone and would never recommend an Android device even to my worst enemy. I’ve seen how the sausage is made and it isn’t pretty. The best thing you can say about Android is that it’s free, which correctly reflects what it’s worth.
Apple's capricious app store review policy aside, iOS is so locked down that even a completely malicious sideloaded* iOS app can't dig itself into the system like this. Without a local privilege escalation exploit there's just no way to set up a persistent background service and no way to escape the sandboxing to allow an app to leave a mark on the system after your app is uninstalled.
(*a developer can basically sideload any app on their iOS device with an Apple developer license)
> According to Malwarebytes, the source of these infections is "web redirects" that send users to web pages hosting Android apps. These sites instruct users on how to side-load unofficial Android apps from outside the Play Store. Code hidden in these apps downloads the xHelper trojan.
https://www.digitaltrends.com/mobile/google-play-store-malwa...
While they were live, they didn’t steal data or gain control of a victim’s device, ....And while the worst effects you’d feel as a victim in this case would be a quicker battery drain and a higher data bill, this latest wave of iOS malware is most notable not for what it does but for how it got there.
Which is a far cry from an unremovable app. It didn’t even get outside of the sandbox and wasn’t an escalation of privilege attack.
There are already many legitimate apps distributed outside of Google Play for various reasons, such as weird Google policies or simply being booted out with no or spurious reason & the developer not being able to ever reach a human to fix this.
So be careful what you wish for.
I think Apple's desktop solution to unverified developers is a good way to split the difference. Deny by default but allow whitelisting. They go even further under the privacy tab and only allow certain applications permission to access accessibility features or full disk access, etc.
Maybe it's a good idea to hide the "Allow sideloaded apps" under the developer menu in Android or something, or generally to display a scarier message.
This and it's ability to survive factory reset may indicate, that xhelper can gain complete control over device (probably via improperly built firmware or unpatched root exploits). No amount of sandbox enhancements can stop this kind of priviledge escalation.
In general really wonder why people still defend Apple these days. Even if you overlook a combination of stuff like infinite attempts for icloud logins that led to the Fappening, their role in HK protests, and of course their pretty terrible labor practices that go so far as even to supposedly break the Chinese labor laws (which is a feat in itself), there is still issues with stuff they produce. Their hardware and software quality has been on a hard decline, especially if you compare it to alternatives rather than on its own merit. They don't really innovate despite opposite marketing claims, and they still participate in this "technology as a jewelry" thing with their $1000 monitor stands.
Do you also suggest defragging and do you have any tips for editing my himem.sys and config.sys files so I can play Doom?
It's basically how linux systems work, most stuff comes from the package manager which has been pretty good at keeping out malware and users can install whatever they want from elsewhere.
That's not to say in any way ANDROID BAD or anything like that, it's just a broader attack vector that you're up against with Android unless you're a very careful experienced customer. Most people aren't. :/
It's incredibly frustrating to read these pro-walled-garden-arguments. By the same argument you could say that the people in Hong Kong or elsewhere should just shut up and accept that their leaders will know what's best for them.
I worry about a future where these locked-down devices will be the norm for all of us. Don't defend Apple for locking you in. That's ridiculous.
My objection is that it's not that useful to only look at whether a party wants to restrict freedom. Personally, I don't think that's a very useful dimension at all -- I don't consider the existence of a road limiting to my freedom to drive wherever I feel like it.
Of course, you can always use another road or go completly off track. Like living in the woods?
Fundamentally, the problem exposed by this particular piece of malware was the ability for it to persist across removals and device resets, not that it was "sideload-able" by the user. Malware persistence should not be possible on a well-designed system, especially one where applications are generally untrusted and sandboxed. Had this been malware that requires sideloading but could be removed when noticed, it wouldn't even have made the headlines at all.
The problem with making the walled-garden argument here is like saying nobody will get sick if we just put everyone in isolation all the time. Like, sure, it is _a_ solution, and assuming the isolation is perfect, it _does_ achieve the goal... But this merely sidesteps the problem, and anything that slips through the wall (which as pointed out by other commenters, does happen on iOS too) will be just as dangerous as before.
The real solution is to "buff up everyone's immune system" and make it easy to restrict and treat malware apps when they inevitably end up on a device, walled garden or not.
That's what, 0.0018% of devices infected?