Skip to main content

Posts

Showing posts with the label Android

Elliot Alderson also known as @fs0c131y Exposed on Aarogya Setu App so called Security Issues!!!!

Elliot Alderson's Tweet Claiming Issues in the Application. Well, you heard right, this is the same person who had earlier provided many issues regarding the Indian Government various applications from DigiLocker to Aadhar application, etc. Well, this time it seems the findings posted by him are not completely right rather say just a twist of some technical words so that his wast audience who is mostly non-technical and very less to no knowledge of technicality of android/application environment/ space or even what is classified as a violation of privacy. A team of Indian Security researchers  Sri Ram, Nidhish Pandya, Biprodeep Roy, Kunwar Atal & Sunny Nehra have gone into depts and length of the posted privacy issues and have explained the findings. A Quick Gist of the Blog Here is the link to a blog post published in their findings. Let me know your thoughts and comments on it.

New Android Malware Steals Banking Passwords, Private Data and Keystrokes

A new type of mobile banking malware has been discovered abusing Android's accessibility features to exfiltrate sensitive data from financial applications, read user SMS messages, and hijack SMS-based two-factor authentication codes. Called "EventBot" by Cybereason researchers, the malware is capable of targeting over 200 different financial apps, including banking, money transfer services, and crypto-currency wallets such as Paypal Business, Revolut, Barclays, CapitalOne, HSBC, Santander, TransferWise, and Coinbase. "EventBot is particularly interesting because it is in such early stages," the  researchers  said. "This brand new malware has real potential to become the next big mobile malware, as it is under constant iterative improvements, abuses a critical operating system feature, and targets financial applications." The campaign, first identified in March 2020, masks its malicious intent by posing as legitimate applications (e.g., Adobe Flash...

Google Suggesting Android Developers to Encrypt App Data On Device!!

Google has published a blog post recommending mobile app developers to encrypt data that their apps generate on the users' devices, especially when they use unprotected external storage that's prone to hijacking. Moreover, considering that there are not many reference frameworks available for the same, Google also advised using an easy-to-implement  security library  available as part of its Jetpack software suite. The open-sourced  Jetpack Security  (aka JetSec) library lets Android app developers easily read and write encrypted files by following  best security practices , including storing cryptographic keys and protecting files that may contain sensitive data, API keys, OAuth tokens. To give a bit of context, Android offers developers  two different ways  to save app data. The first one is app-specific storage, also known as internal storage, where the files are stored in a sandboxed folder meant for a specific app's use and inaccessible t...

More than 1.9B Malicious App Installs in 2019 were blocked by Google Play Protect

Google continues to enhance the safety of Google Play with continuous improvements, enhancements, and teams to fight against malicious apps and developers. Google Play Protect is built-in malware protection for Android, it was introduced in the year 2017, aiming to detect malicious apps in the Google Play and off of user’s devices. According to Android Security & Privacy  report  2018, Google blocks more than 3.2 billion malicious apps installation. Starting from October 2018, Google announced a new policy update to limit the apps unnecessarily accessing sensitive information such as SMS and Call Log data. Google Play Protect scans over 100B apps Google Play protects scans more than 100B apps every day and alerts the users about the security measures and the steps that need to be taken. It also notified you if you have installed new or rarely installed apps in the ecosystem when the play protects is enabled it shows the following warning when the malicious ...

5 * Ratings & Fake Reviews given to Malicious Apps by newer Malware Installed by Hackers on Android Devices

Researchers discovered a new type of strange malware that targeting android device, and use the victim’s mobiles to provide fake ratings in Google play store apps for malicious apps. You may have seen reviews in Google Play apps that seem to be talking about something unrelated to the apps. this malware named as Trojan-Dropper.AndroidOS.Shopper.a. give it five stars, while dozens of users rate it as 1 start. Cybercriminals used this trojan to boosting malicious, fake and adware apps and increasing the number of installations. Also, the Trojan will perform various malicious activities such as display advertising messages on the infected device, create shortcuts to ad sites, and perform other actions. Apart from reviewing with fake comments, the malware evades the user’s detection, the installation window is concealed by the app’s “invisible” window.  Shopper.a also enables the AccessibilityService to install the new apps from the 3rd party services. Acc...

4.6 Million Android Devices Affected by 100+ Malicious Apps on Google Play

Researchers discovered over 100 malicious apps from Google play store that downloaded by more than 4.6 android users around the globe. Most of the malicious apps are commits ad fraud, and the app malicious apps are using the same common code package dubbed “Soraka” ( com.android.sorakalibrary.* ). “GBHackers on Security” reported  several adware incidents  in the past few months, and it’s rapidly growing to exclusively target the Android users to generate millions of dollars revenue. Malware, Spyware, and Adware can accompany them, become a parasite in user’s systems resulting in unnecessary disruptions, and breaches of the personal data in your Android devices. In addition to the Soraka code package, Researchers also discovered, in some of the apps, a variant with similar functionality which we dubbed “Sogo” ( com.android.sogolibrary.* ): Some of The Malicious Apps Activities An app called “ Best Fortune Explorer App ” published under the publisher JavierGent...

Super Critical Bug Fixed by Whats App , the bug could have let anyone crash Whats app of All Group Members

WhatsApp, the world's most popular end-to-end encrypted messaging application, patched an incredibly frustrating software bug that could have allowed a malicious group member to crash the messaging app for all members of the same group, Just by sending a maliciously crafted message to a targeted group, an attacker can trigger a fully-destructive WhatsApp crash-loop, forcing all group members to completely uninstall the app, reinstall it, and remove the group to regain normal function. Since the group members can't selectively delete the malicious message without opening the group window and re-triggering the crash-loop, they have to lose the entire group chat history, indefinitely, to get rid of it. Discovered by researchers at Israeli cybersecurity firm  Check Point , the latest bug resided in the WhatsApp's implementation of XMPP communication protocol that crashes the app when a member with invalid phone number drops a message in the group. "When we attempt ...