Malicious Android Apps Slip into Disguise
krebsonsecurity.com
krebsonsecurity.com
E.g. recently I wanted to try an App to identify insects. There were a few that seemed nice and free. After I installed them they were full of ads and nagged me for a 7-day trial signup. And even after I did, the app didn't even work particularly well.
Websites generally work on mobile so that is my chosen path these days. They're not as slick, but I can accomplish what I want.
I would love an app store that commits to much higher standards on all fronts. I think the subscription format that the likes of Setapp use could be very useful here in that it would be shared among these apps that meet high standards.
What's pushing me to discover if every time I open it it's an ad begging me to install TikTok?
Merlin Bird ID is so good in comparison, probably the best in the "ID this thing" category of apps I have ever tried. Photos do a lot, but if you don't get a good ID it will ask some questions about the bird's behavior and your circumstances to narrow down your search.
Seriously, just don't eat any mushroom that you can't personally identify with 100% confidence from your own knowledge and references, with some app saving its xyz not being considered a reference.
Even experienced mycologists have sometimes made mistaken identifications so anyone else should be so cautious as to presume poison in all cases except the most certain.
(Obviously store bought are an exception)
No, you're not alone, but I get the sense we're in a small group of users. Maybe there are more collected here on HN, but in the wild, most people will install an app without any consideration for possible reasons not to install.
Nearly all new installs are apps by indie devs that I saw someone mention in a Mastodon post or HN comment or something, because that's where the gold is. Midsize and up companies generally don't care enough about user experience to build great apps (instead, optimizing for "engagement" and leaning on A/B tests for design decisions), and obviously neither do shovelware devs of any size. The interesting stuff is almost always built by small operations run by passionate people.
The stores tend to promote the apps that generate the most revenue; often times the best app for your needs is not the one that's making the most money.
I suspect this article is about a bug in Play Protect, which is an on-device security scanner. I don't think iOS has something similar.
The attack vector was normal apps purchased by the hackers were modified to download and install malicious apps. This should have been caught by Play Protect on the device, but failed due to the bug
It has a link to the original report
Don't download Microsoft Teams if it claims an app developer with an unrecognisable name and only 500 downloadeds, don't download cracked games, be wary of the obvious free-to-play clones, and if a web page shows a flashing gif warning you that Whatsapp is outdated, don't install the APK file it's trying to push through your browser. It's also important to keep your browser up to date and to think before you grant apps permission described like "control the entire screen" and "give app access to all input and screen content".
Android malware is not that different from Windows malware. It spreads through devices infected from the factory, pirated software, fake download ads, and less commonly, through clones and abandonware on official storefronts like Google Play.
This threat actor is buying abandonware and spreading viruses through updates. Dime-in-a-dozen PDF readers and file managers (that your phone already came with anyway) are at risk, but if you stick to reputable brands you'll be fine. Pick "Google Drive PDF" over "Insomnia Media PDF Viewer - Reader & Editor" with 10k downloads.
Google Play comes with an antivirus program built in (Google Play Protect) that will warn you of known risks. You can disable it if you don't want Google to know about every app you install from other sources, but if you leave it enabled you'll minimize the risk of getting infected.
If you want to be sure you're not getting infected, use F-Droid. F-Droid compiles open-source apps on their own servers, so the source code they receive is the source code the compiled APK uses. Even if your app is open source, there's no way to upload a precompiled APK to the F-Droid website. This makes introducing malware without anyone noticing quite difficult.
This is a common model, and is basically how most Linux distros work, but it only scales (safely) with people actually paying attention. How many people does F-droid have reviewing the apps that update that they build?
I agree it will be hard to introduce malware without anyone noticing in a strict sense, I'm just not sure they have enough resources to notice before it becomes a problem given how I assume that must work, but I would be happy to be wrong.
With F-Droid it's almost impossible to hide the infection. Once your malicious code has been found eventually, you're one quick scan of every other app away from getting all of your infected apps kicked from the store. You can obfuscate your source code, but that makes any app with obfuscated source code suspect immediately.
This is a lot harder with precompiled apps, especially those loading native libraries. With the tens of thousands of vague shadow companies that hobbyists and small dev shops have left behind over the years, it's impossible to find out which apps to reverse engineer if you're looking for similar infections. Obfuscating compiled code is quite normal as well, whereas open source projects stand to gain very little from obfuscating their source code.
You still need a certain level of trust (and a certain amount of hobbyists/security researchers to go through the apps) but that's inherent in any modern computer system. The days of the VIC-20 where one person could understand the entire system from top to bottom are long behind us, for better and for worse.
Fbreader is a good go to and with its extensions support every format I have use for (pdf, epub, cbr, etc)
Ah, so pretty much all the warning signs people ignore when clicking on a phishing link or an advertisement saying they’re the millionth visitor.
I don’t want this coming anywhere near iOS. Maybe a controversial opinion, but I’d rather have that than my Grandma’s entire retirement account being emptied because of a malicious app.
You could download cracked games but you can't install them without enabling third party apk installs. Grandma isn't likely to do that.
Same for any random webpage that pushes an apk.
I also never had viruses or malware or what else because I only install official app versions (Teams / WhatsApp / Skype messengers, Netflix / Amazon / HBO / Disney streaming platforms, Google / Microsoft / Custom Bank authenticators, Chrome / Firefox browsers etc).
My kid though ... my God. He installs random games from PlayStore, if I wouldn't have seen I wouldn't have believed it. Every corner of the phone was infested with ads and popups and crap, had to do a factory reset to clean it as even after uninstalling the games the crapyware continued).
Overall if you stay out of games and stick to tried and tested official apps, you're good. Well, apart from Chinese phone bugs, which are unavoidable given the price tag.
Like at least I got used to Xiaomi's bugs but my kid just wanted so much a Huawei Honor Magic5 Lite coze it looks nice and that's all that matters.
Crashed once right when I was setting up my Google account, second attempt succeeded. Then started pre-installed YouTube and took 5 crashes before the 6th attempt finally succeeded and the application started.
For the same money he could have gotten a Redmi Note 12 Pro from Xiaomi, with slightly better hardware specs (but not the slick curved glass look) and as it seems, leaps and bounds better tested software.
RIP the other devices on your network.
It's the part of the "recover lost/stolen phone" thing, but it's an overkill for that purpose. It's not documented what they are doing with the data, and this clearly violates the GDPR. Btw. never had this feature enabled.
Flashed a custom ROM the next day after my discovery.
I know that is an Android unique solution that can't be used on NonAndroid devices, but it significantly reduces entry points.
Maybe it's time to turn off auto update for apps. Auto update is important from a security perspective but if the actor is bad, it might be better to wait and update on demand to catch up with missing fratures and by that time hopefully the malicious app has been removed from the app store. Of course this would only work for standalone apps.
Similar to how we often have intermediate package managers that pin packages to a particular version to not get malware injected one day.
This culture of Tweeting at 5 am to 5 million people before the truth has a chance to get its pants on is defended in the name of “freedom of speech”, but I much prefer the peer review gated approach of science. Not one monopoly gatekeeper but at least 2 reputable ones, before your OS or package manager allows the download (but users can override it if they insist). I think rpm and yum do that..
I used to be into phones. These days I use $150-200 used iPhone SE (2020). Don’t care if I drop it or break it. And it takes decent photos (not amazing, not terrible). And it’s small.
1: https://www.wired.com/story/kaspersky-apple-ios-zero-day-int...
The Xcode ghost incident for example affected half a billion installs and 100M users: https://www.intego.com/mac-security-blog/xcodeghost-malware-...
Regarding big name apps... Well, WhatsApp on iOS has been the main attack vector for state actors for a few years now.
https://thedefenceworks.com/blog/zero-click-infection-and-wh...
It's very frustrating that I cannot specifically exclude certain apps from auto-updates.
Android forces me to either permit blanket auto-updates, or to click through a big list of pending updated, where a single mis-tap will permanently update the wrong app with no easy way to undo or downgrade.
Release notes is MUCH bigger problem. App stores should show a history of every update issued since your current version. Also, ban devs who just write useless two word "Bug fixed" release notes.
It does no such thing.
Google does.
If you don't control the software, the software controls you.
If users are disallowed from auditing the software source code easily, then this is bound to happen.