Russian hackers tracked Ukrainian artillery units using Android implant (2016)
reuters.com
reuters.com
Jeffrey Carr, cybersecurity researcher points out his own concerns about the crowdstrike allegations here:
https://www.linkedin.com/pulse/crowdstrike-needs-address-har...
1. don't need GPS permissions for location data (IP address is still valuable intelligence especially if I'm spear phishing my target(s))
2. the claim that the app is outdated and doesn't use the internet misses the point (I would add emphasis if I could)
re 2: what crowdstrike describes is an effort to get people to download a fake version of the same app, which has added features/tracking.
note the disparity in quotes:
Linked Quote (link is broken, but from Crowdstrike CEO): Russian hackers … tricked Ukrainian servicemen into downloading a contaminated version of the software - https://www.telegraph.co.uk/news/2016/12/22/russia-linked-dn...
Poster: Crowdstrike claimed that the GRU identified a targeting app, wrote malware for it, and used the compromised apps to geolocate and bomb their artillery.
See - this is not what's being said, we're mincing words. The attack, as I understand it, is they found an app they knew their target used. Made a fake version, and spear phished people (let's say, all new recruits) into downloading their malware version. What happens after that is wide open. GPS, location, network connection, anything, we can't say (probably Crowdstrike can) so the Ukranian soldier who made the app saying his version wasn't compromised is totally besides the point.
> The implant leveraged a legitimate Android application developed by a Ukrainian artillery officer to process targeting data more quickly, CrowdStrike said.
Ouch.
[0] https://www.crowdstrike.com/blog/danger-close-fancy-bear-tra...
https://medium.com/@stranahan/timeline-of-crowdstrikes-russi...
Hey, a man can dream can't he?
Yup.
> And you can absolutely download and allow similar apps with an iPhone.
The article referenced malware, is there malware that can run on an up-to-date iPhone?
Also, Isn't there a consensus that open-source is always safer because it is being inspected by all?
With Android, unless you have a Pixel or Samsung is feeling very, very magnanimous, forget any patches coming to your device any time soon. And that too only 3 years for Pixel.