Malware on My Android Phone
beust.com
beust.com
The lesson should be; even very experienced technical people fall onto the malware trap. We all have day-to-day problems, unexpected stuff happening, in short life doing its thing. We'll inevitably end up being victims of a scam that happens just the worst possible day of them all, because reasons.
Thus the problem is not if we'll also fall on the trap, but what tools we'll have at our disposal when we do, and to what extent the Operating System will be there helping to protect us (and/or help us diagnose the issue...)
1. Do not trust Google to vet the apps in the play store. They won't; they don't even try.
2. Those shiny Play Protect and whatnot postured around by Google are practically utter useless bs/bloat
3. Stick to famous, really famous apps from the Play Store - as in well known - e.g. Facebook, Netflix, Evernote etc (you will be tracked of course, you won't be hacked - you pay this price by using Googled Android anyway)
4. If you couldn't find a well known app on Play Store - head to https://www.f-droid.org
5. Do not, just do not download any other app on your phone (treat it as a no exception rule) unless you know what you are doing and possibly can look at the code - find something decent as an APK from GitHub et al.
6. Be very miserly when it comes to doling out permissions to apps. Your default should be "no".
7. Privacy (not really) and safety are just superficial polish by Google on Android OS - their core and only focus developing the OS is: making it as much of an ad platform as they can and on top of that how to get a bigger and bigger cut of the overall ad revenue with every release.
Nowadays anybody can be an Android developer, India is full of teenagers doing it.
"Saying that an author lacks the authority to write about a topic is a variant of ad hominem—and a particularly useless sort, because good ideas often come from outsiders. The question is whether the author is correct or not. If his lack of authority caused him to make mistakes, point those out. And if it didn't, it's not a problem."
But in general, Paul Graham isn't saying anything that is novel to this site's comment guidelines:
Be kind. Don't be snarky. Have curious conversation; don't cross-examine. Please don't fulminate. Please don't sneer, including at the rest of the community.
Comments should get more thoughtful and substantive, not less, as a topic gets more divisive.
I'm not taking their post completely on faith. It matches up with my previous experiences, including the article we're currently talking about and related articles I've read.
Is there a specific issue you have with their point, or did you just want to point out that they're not special for making apps?
The barcode scanner wasn't any shitty app, it was the one that was recommended a long time ago by Google authenticator. I had left it installed on my phone and it must had had the dodgy update that got it banned from the app store.
That's where I remember it from, thanks! However I think there's some confusion here: the one the blog mentions is not https://play.google.com/store/apps/details?id=com.google.zxi... (github based, relatively trustworthy looking, recommended by Google Authenticator back in the day), it's the now removed qrcodescanner app: https://webcache.googleusercontent.com/search?q=cache:38t1gW...
I think those bad reviews on https://play.google.com/store/apps/details?id=com.google.zxi... are because the malware probably used the zxing qr library, and there might be traces left in it, or these users are just confused (or the malware app deliberately pointed low star reviewers to the github competitor app in the play store). As others have stated, this github app with the bad reviews hasn't been updated for a long time.
If the malware is also in https://github.com/zxing/zxing , I really hope they do a postmortem to explain how. The fact that https://play.google.com/store/apps/details?id=com.google.zxi... still exists though, while the app mentioned in the blog has been removed by google, makes me think the zxing app is clean.
The rub? It wasn't this app. It was another one that was also called barcode scanner. It was also beginning to garner negative reviews, which the developer (had a Ukranian email address) had begun responding to saying the app was perfectly legal because it was serving ads only inside the app itself.
I'm wondering if that deluge of bad reviews is directed at the wrong app? I'll look to see if I can still find the google play page for the one I had.
Also, I had that app for a LONG time before it started displaying this kind of behavior just last month, which also corresponds to the bad reviews starting on the zxing app.
https://play.google.com/store/apps/details?id=com.google.zxi...
So it might be another completely unrelated app that triggered the issue, or it might be this one, no idea!
I've reset my phone to factory and re-installed only as and when I needed an app and so far no more ads.
That kinda blows my mind.
We even did a low-level reset (a representative guided me through it) but to his own surprise the malware was still there.
I was out of warranty and I had to pay a sum to get it fixed, which was more expensive than buying a new tablet.
I'm not that extreme, but I did replace my computer once I got back from Kiev. I'd rather not worry about it.
(my father has an android phone and now I suddenly find myself curious about save/restore and how to find malware on his phone)
No - There is no 'easy' way to store/restore the entire phone as I believe Apple does. (I had a miserable day doing this, when my old Pixel started playing up and had to migrate across to a replacement) - and this was best case when I had the two phones next to each other.
Core 'google' stuff seems fine - either all tied to your account (e.g. contacts) or google app data (texts, pictures etc) which can be backed up to cloud, or directly migrated between phones.
What doesn't work is the logins/settings for all the random apps. Some do store on cloud. Some allow manual export/import of settings. Some you're going to have to setup again from scratch.
Back in the day when I did root my phone, TWRP and similar things let you image/restore the whole phone.
That is the true "factory reset", as it's how they were first loaded with software in production. I believe the more widely-known and generic Android reset is merely restoring from an internal partition.
If you look at the storage requirements of an app, you can see it's split between "App Size" and "User Data" (along with a cache).
AFAIK there's no way to actually backup/move the user data without rooting. Now I can see why Google might not want to store all that (and why I might not want them to) - but it's somewhat silly not to have any options.
I think Android phones with the Google Services Framework installed do provide such a way. Alternatively, if you're using a custom ROM (like GrapheneOS on Pixel devices), you can use Seedvault[0] for full backups of your phone. It basically acts as a drop-in replacement of the backup service provided by Google.
This was a side-loaded app on an unlocked phone. What am I missing?
This plus the native support for CardDav and CalDav are pushing me to try iOS next time I have to change my phone.
This is the best heuristic to apply not just for QR code scanning, but for pretty much everything. To avoid malware, avoid the Play Store.
When using f-droid, also check out the project web site and git repo (at least in a cursory way, even if you can't fully audit the code, you can get a sense of who the developer is and the project's overall health from the commit log and issue tracker).
Play store should be only used for things that you can't work around with apps from f-droid.
Don't forget it is on the Google Play store too. https://play.google.com/store/apps/details?id=com.google.zxi...
There was a time when QR Code scanning was better in Android than iOS (native in iOS 11.x).
The "Google" way of scanning QR Codes is Google Lens, but it doesn't work offline :|
I believe these bad reviews might be a result of the malware app pushing bad reviews to the zxing app page on google play, using an in app 'rate this app?' -> low rating -> send to the zxing app in Google Play (instead of the malware app in google play).
https://f-droid.org/en/packages/com.secuso.privacyFriendlyCo...
What's interesting, is that despite the app not being updated since 2018, open source, and containing no ads or tracking the reviews are saying it recently became adware.
Searching for barcode scanner in the app store brings you to a horrible sea of ad supported crap ware, and it seems like that crap ware wants to ensure you don't download something that might be decent.
I scraped the latest 1000 reviews (coincidentally almost exactly 12 months worth).
The "adware" reviews are all very recent with large amounts of votes.
They seem to start on December 18, with 162 1-star reviews in the following 25 days -- more than all the 1-star reviews in the 6 months prior.
I wouldn't be surprised if these reviews are not only automated spam, but are constantly being deleted and reposted to keep them "fresh", and at the top of the "relevant reviews".
Charts: https://imgur.com/a/QUyHcHu
CSV of review data: https://pastebin.com/ZanYgd5Y
Used the simplescraper.io Chrome extension (with a little bit of DevTools fiddling) to export a CSV.
Created a pivot table in Excel and charted the results.
The last update I see available is what I have installed - 4.7.8 from September 2018. Definitely no strange behavior from it.
But I also use this app for QR-codes, since I was never able to find an alternative. The vast permissions required make me nervous every time I install it... Good to know it is on F-Droid as well, built from a source tarball, so should be OK [1]?
[1] https://f-droid.org/en/packages/com.google.zxing.client.andr...
However all the negative comments about ads are from after November 2020. Clearly a smear campaign.
Another option would be to use Google's MLKit. I think they've added support for scanning QR codes in there. It requires Google Play Services though, which is not ideal.
> No issues initially but now it will give full screen ads often that either force open your browser to a shady site...
> ...thought I should update it. That's when I started getting full page ads and browser redirects. I don't know who hijacked this app...
> Avoid!! Used to be great. Now opens adware, and pops it over the lockscreen. Goes to great lengths to cover its tracks, calling the process "partners" and removing itself from recent applications. I had to use "popup ad detector" to find it. Appalling behaviour. Very underhanded.
The zxing library is open source and different from the app. So looks like something fishy happened to the app recently. From the description of problems, this might even be the app referred to in the article.
The one thing I've noticed about the iOS store is that apps are more up-front. Many have a price tag attached to them, which I prefer. Android apps are all about giving you something for free and then in the back doing god knows what to make pennies off of you.
The whole ads-in-apps situation is from some sci-fi novel. Let's make screens bigger, so we can fill more of it with ads.
I wonder if this is a concerted effort to steer impressionable people away from a "real" FOSS QR code reader app and direct them to a malicious one instead, using scare tactics.
Ridiculously, there's no way that I can see to get an app shortcut icon to it.
Note: I work at Google but not on Android/Lens
Voice Assist is yet another privacy invasion vector imho, there are too many anecdotal first hand accounts of someone talking about fishing and suddenly getting banner adds for boat trips everywhere.
The technology and storage that would be required to parse non-device-directed speech doesn’t exist and wouldn’t be profitable since there are so many other reliable signals that are much cheaper.
Better to be screwed by google, than to be screwed by both google and samsung/whatever.
I had a QR reader in my camera app on some old Androids, around 2011 or so, but maybe it was because I then often was running custom ROMs? Or because back then QR codes were hyped and used for everything? Anyways, in 2019 or so it was included again in the native camera app on all Samsungs.
While I get the allure of "it just works", having a niche feature that's basically never used and easily installed anyway seems like a weird hill to die on.
There is also ICSx⁵ from the same developer, works against outlook.com.
I paid for both, they work great.
Apple added a builtin QR code scanner to the camera app in iOS 11 due to the ridiculously widespread use of QR codes in China.[1] I guess (Google's version of) Android doesn't have that because Google doesn't derive much value from that market, and QR codes don't have as much mindshare in other major markets.
[1] They specifically called out the Chinese market when introducing the feature in WWDC 2017 keynote:
> Of course, there's much more than we have time to talk about today, but I want to highlight some features of special interest to our customers in China, like QR codes that are integrated right into the main camera, accessible from the lock screen, super use Yes, super useful for customers in China.
I believe that its built-in app also has a QR scanner in HiVision package, but it requires to accept a scary privacy agreement.
Firefox for Android embeds a QR scanner in its address bar: https://support.mozilla.org/en-US/kb/scan-qr-codes-firefox-a...
My last few Android phones have had QR reading built in to the camera though, just not current Nokia. It might even be my biggest annoyance with it...
But, the phone I had before those two, had a Camera app which didn't read QR codes. So maybe it's a matter of expectations now: old Camera apps were just for Camera, while modern ones are now generally expected to be able to read QR codes? (I would, anyway)
I thought it was a bit 'hit or miss' at first - if you hold the camera over the code, after a bit it decides to pop up a link over the QR in preview. Then realized if you tap on the code, it instantly displays the link. Just had a fun few minutes on https://www.google.com/search?q=qr+codes&tbm=isch - as the tap allows it to handle multiple ones within the same frame.
After taking a picture of a QR code, view the image, tap 'more', wait 10s, if the image is good enough (and it really needs perfect focus and placement, it's very pinickety) then it will show "read QR code", if you choose that option it will then take you to a URL/text preview, and then you can open your browser to that URL, etc..
Worst discoverability ever!
I've had this on Samsung phones for a long time.
On the flip side there are QR apps in the top 100 App Store apps because the built-in support in camera is not really obvious unless someone tells you.
But these are all behind app, not readily accessible.
Took me ages to discover that, still not sure how long it’s been there.
I am currently looking for a new bank.
I got a workaround by switching to desktop mode, when that didnt work anymore by using Fennec (FF mobile fork with relaxed addon support) + useragent switcher
It uses LUA scripts to install apps remotely and can grant any app any permission and run as system level through reflection.
The government funded LifeLine phones that are given to the poor, disabled and veterans are all infected with this malware.
Here is an excellent technical analysis of the rootkit:
Google Play Protect could also do some behavior profiling to analyze what apps are doing in the background. A service launching recurring VIEW intents on web sites in the background should have raised a flag to the system."
Sounds good.
I sense that there so many teams involved such a feature is not on their radar. So "they already know they blocked it" and "the existing installed app should be blocked" imply that two teams know what the others are doing.
I'm guessing that the team that does the removal from the store has no communications path to those who would add a flagging mechanism for already installed apps.
I was able to find it pretty quickly by going to:
Settings > Battery > Usage Details > Battery Usage Since Full Charge
This showed me the most recent app used. As I hadn't used the QR scanner app in quite some time, it seemed a reasonable place to look first.
I unlocked my phone and two
accidental clicks led me to
agree to a dialog that my brain
immediately registered as suspicious
What type of dialog can pop up on your Android screen after unlocking and install "malware"? What is "malware" here? It looks like they mean an app from the play store? The next day, I picked up my phone and
when I launched Chrome, I immediately
noticed it was displaying a spammy URL.
How can one app alter the behavior of another?Coincidentally, I just spent my Saturday evening pouring over malicious JavaScript hosted on Cloudfront that does extensive browser fingerprinting and if a match is made to an Android device a fake Captcha pops up in Chrome which actually enables push notifications and from there a full screen pop-up appears that vibrates the devices and claims the phone is infected with (N) viruses and the “repair now” button pulls up the Play Store app to install DFNDR antivirus/cleaner.
If you look at the reviews of that app you’ll see all the angry reviews of users having their browsers hijacked.
The app itself is just an advertising server wrapped around Avast’s detection engine and is funded by the Chinese Qihoo.
It harvests users social media data and charges the users almost $10 a month after a 3 day trial period.
Novice users are unable to delete the app if “advanced protection” is enabled because it becomes a device administrator and uses deceptive language to confuse the user trying to remove the app.
If the app gets installed it will not let you clear the storage of the app from within settings even if you had never opened the app and before you agree to any terms and conditions.
The fake virus warnings that lead to DFNDR have been going on every single day since 2013.
I’m putting together a webpage that will include the JavaScript and other details as we speak.
The Google Play Store is a dumpster fire full of scam apps and Scummy developers.
Wow, this sounds like a classic clickjacking vulnerability. That’s still possible on modern[ish] Android? Definitely interested in your write up.
he received a push notification
to chrome from the malicious app
What does that mean? How does an app send a "push notification" to Chrome?In Defcon 2, author finds a log with intent:
{act=android.intent.action.VIEW
Android will handle The URI with default app. The malware sends HTTP url, so it will be opened by default browser.
I did several things after this:
- Reported the ad to Google (no followup from their side - naturally).
- Removed Chrome.
- Installed Firefox and uBlock Origin.
That would be the case if you enable sideloading, but that isn't mentioned in the article. Is it possible to install an app via popup without going through the store? This needs some clarification.
> It checks your device for potentially harmful apps from other sources. These harmful apps are sometimes called malware.
> If you choose to install apps from unknown sources outside of the Google Play Store, turning on the “Improve harmful app detection” setting will allow Google Play Protect to send unknown apps to Google to protect you from harmful apps.
[0] https://support.google.com/googleplay/answer/2812853?hl=en
It does not sound to me like the Chrome app was infected, just told to open a page.
https://play.google.com/store/apps/details?id=com.google.zxi...
A 2020 review talks about ads appearing after a recent "update", but the app hasn't pushed an update since 2018!
I've always had this app installed and never experienced adware, perhaps those reviews are left by people falling victim to the copycat scam?
I also think those reviews might be left by people who can't find the original offending app because it's been removed. https://www.apkshub.com/app/com.qrcodescanner.barcodescanner seems to show it had BILLING permission though, which is always an alarm bell.
The code is open source too: https://github.com/TimDaub/scan.lol
Am I missing something or does your repo only contain the minified version of the javascript, and not contain the `index.js` referenced in the `package.json` nor the method to build to minified artifacts? This seems like it's not open source.
thanks for pointing that out. Rest assured, the site is 100% open source as I'm simply publishing the repo using GitHub Pages. There's no build step.
Regarding package.json's main file: It's a mistake. I did not update it properly after I did `npm init`.
It just popped up annoying ads, which it doesn't need special permissions to do.
Maybe that’s the problem?
That is pretty hard to achieve, and no mobile or desktop platform really has it.
Some 5 years ago, I switched to Firefox Mobile out of annoyance because Chrome refused to block all those popups random websites would show with some prompting an app install.
Google has since made a lot of improvements including tightening up which apps can install other apps (not a blanket permission anymore), running the Potentially Harmful Applications program, narrowing down fingerprinting (still some way to go as evident by TFA). Google is even locking the code up that runs outside of Android in crosvms [1]. I'm positive, things will improve [2] even if slowly because Android, at this point, is the most widely distributed OS and they can't move as fast anymore without hurting developers and users.
Google did implement what they call AppOps (2013) which paved for tremendous amount of user control over app permissions. They removed AppOps citing that it was never meant to be used by end-users but by AOSP and app developers [3].
Fortunately, if Android is rooted, one can use AppOps [4]; but then rooting exposes one to an incredible amount.
Besides, there are LittleSnitch-esque firewalls for both root and non-root devices [5].
[0] https://arstechnica.com/information-technology/2011/11/mobil...
[1] https://youtu.be/edqJSzsDRxk
[2] https://android-developers.googleblog.com/search/label/Secur...
[3] https://www.zdnet.com/article/google-removes-awesome-but-uni...
Android security is broken.
As you can imagine, when all the covid checkins started, I couldn't find this. Everyone would say to me "just open the camera on your iPhone it's easy" as though it was a given that every visitor was using an Apple phone.
I went through three different QR apps based on what I found on the play store and all of them blasted me with inappropriate ads I kept wishing I didn't open in public. A bit if visibility in the UX would have solved this.
Would be cool too if there was a shared file space for apps... And apps had to stay within that pen. Giving them access to all your phone's files is just wreckless. But I don't have the choice.
Sometimes I phantasize about a novel computer or phone, where you can "physically" inspect the running (non-OS) applications. On a phone, you'd have a glowing edge where each light or micro display corresponds to one application. You can only ever have 6 or so apps running at the same time. If an app launches a lot in the background, you'd notice it quickly from the new color blinking. On a desktop PC or a server, maybe you'd even have a little door in the case, and behind it a bunch of little OLED displays that replace the task manager. With a click of a physical switch, you could evict an application from memory automatically.
Of course this would be unpractical for a lot of reasons, and you'd have to trust the OS/firmware. But I like both ideas of understanding what the PC is doing, and adding back a tactile element to computing.
This makes me think that it would be nice to be able too load "camera sensor scripts" in a similar way to GLSL for GPU, for filtering and analysis using hardware. (it might be possible, I am not an android developer)
Google Play Protect performs notoriously poorly compared to dedicated malware apps:
I've been a victim of that specific malware and I was wondering how on earth did it happen as I'm usually careful enough when it comes to security. I also had the barcode scanner app. I didn't go as far as the author and I did a factory reset.
As an example: try to find a non-ad-infested flashlight app on play store, then try to find a single ad-infested flashlight app on f-droid.
Reduce the attack surface as much as you can!
I also added to my mix the Nova Launcher. It makes it easier to tap&hold an app icon, gives you a quick shortcut straight to the specific app's Settings --> Apps --> specific app's properties, in which I (usually) block access to data/wifi/roaming/background (e.g. for a QR Code reader app).
90% of my apps do not need to reach out to the interweb, and I block them both on Settings as well as Block Data/Wifi on NoRoot Firewall.
Although Huawei is beeing Huawei-ing (some sneaky apps are running).. I do like the interface into "Manually" managing backround running (battery), internet access.
Managing those kinds of blocker apps, and security and such are all great when you're 'in the zone' and have it fresh at the forefront of your thoughts. For me, it only takes a week or so of not thinking about it before my standards slip and I have Just Another Application™ running.
I didn't have any probs with sofrware while using iPhones. I was jailbreaking them, installing a similar firewall and had my mind at ease. I would go to Apple in a heartbeat if they stopped lying and allowed rooted/jailbroken phones.
It is nice to see that on a comment 95% on Android people still downvote me for (justifiably) trashing Apple. They got caught cheating. Then they got caught lying. Then they were found guilty. Apple fanboys are having a party downvoting. Fun fact: "HN karma" is virtual, while the $1k that they pay Apple every year is a REAL number. Keep rocking folks. I guess when someone spits on your coffee you downvote the commenter and keep going back to the same coffee place, right? (https://bgr.com/2020/07/13/iphone-batterygate-lawsuit-settle...)
> and I have Just Another Application™ running
this is absolutely normal/logical. A friend suggested the 7min workout by Johnson & Johnson. Nice app, free, has these simple 7mins workouts, also has warm-up/cool-down if you want the extra 7-8mins.. very nice. Loving it.
It doesn't need internet connection to fully operate (workouts). I don't need it to "back up my progress in their cloud". So it stays offline (forever). It takes 1min when I install that new/extra app to bolt it down and have it behave just as I want (and does not disrupt me with notifications or leak data or kill my battery).