[HN Gopher] Malicious Android Apps Slip into Disguise
       ___________________________________________________________________
        
       Malicious Android Apps Slip into Disguise
        
       Author : todsacerdoti
       Score  : 71 points
       Date   : 2023-08-03 11:31 UTC (11 hours ago)
        
 (HTM) web link (krebsonsecurity.com)
 (TXT) w3m dump (krebsonsecurity.com)
        
       | Double_a_92 wrote:
       | Am I the only one that basically gave up on the Appstore and Apps
       | in general? It used to be exiting, but nowadays it's almost
       | always complete annoying garbage.
       | 
       | E.g. recently I wanted to try an App to identify insects. There
       | were a few that seemed nice and free. After I installed them they
       | were full of ads and nagged me for a 7-day trial signup. And even
       | after I did, the app didn't even work particularly well.
        
         | acomjean wrote:
         | I haven't downloaded an app from the store in forever.
         | 
         | Websites generally work on mobile so that is my chosen path
         | these days. They're not as slick, but I can accomplish what I
         | want.
        
           | binkHN wrote:
           | I do this where I can, but, for the sites I use more often, I
           | tend to get a far better experience with the app.
        
         | vctrnk wrote:
         | Out of curiosity, did you needed some particular feature in
         | such an app? I've found that Google Lens is pretty darn good at
         | identifying plants, insects, fungi and whatnot (assuming your
         | camera has a decent macro mode).
        
           | jabroni_salad wrote:
           | The only problem with Lens is that it is "magic" and doesn't
           | have a failure state beyond giving junk results should it
           | fail. I don't think I would ever trust it for a "can I eat
           | this" indicator on a mushroom with how many visual lookalikes
           | there are out there. What if the contrast isn't good enough
           | to catch colorations and the gills are not in sight?
           | 
           | Merlin Bird ID is so good in comparison, probably the best in
           | the "ID this thing" category of apps I have ever tried.
           | Photos do a lot, but if you don't get a good ID it will ask
           | some questions about the bird's behavior and your
           | circumstances to narrow down your search.
        
             | tetromino_ wrote:
             | Even if you identified the mushroom species, sometimes that
             | is not enough to know whether it is safe to eat. The same
             | species can be edible (perhaps after some soaking) or
             | dangerously poisonous depending on the geographic area
             | where it grew.
        
         | kotaKat wrote:
         | Same thing on iOS. Every time I open the App Store the "Today"
         | section is the same goddamn set of "popular apps", the same
         | stupid-ass MTX "matching" game with the same goofy face, and
         | the same old same old services and apps.
         | 
         | What's pushing me to discover if every time I open it it's an
         | ad begging me to install TikTok?
        
         | dylan604 wrote:
         | >Am I the only one that basically gave up on the Appstore and
         | Apps in general?
         | 
         | No, you're not alone, but I get the sense we're in a small
         | group of users. Maybe there are more collected here on HN, but
         | in the wild, most people will install an app without any
         | consideration for possible reasons not to install.
        
         | gochi wrote:
         | I feel similarly about all digital stores from apps to games.
         | There's zero curation anywhere. Everyone wants to be the "dump
         | all your garbage here and let consumers pick while we get
         | 10-30% cut". It's like wading through a sea of cheap rip offs
         | and apps named like a terrible Amazon listing trying to hit as
         | many keywords as possible.
         | 
         | I would love an app store that commits to much higher standards
         | on all fronts. I think the subscription format that the likes
         | of Setapp use could be very useful here in that it would be
         | shared among these apps that meet high standards.
        
           | criddell wrote:
           | I don't particularly have a problem with stores filed with
           | junk (as long as it isn't fraudulent) because I don't really
           | use the stores unless I know what I want. I don't think I
           | could trust in-store curators but that's okay because I get
           | good recommendations from friends and writers. Look for
           | curation outside of the stores.
        
         | jwells89 wrote:
         | I still download new apps on iOS and once in a blue moon on
         | Android, but they're rarely discovered through the App
         | Store/Play Store.
         | 
         | Nearly all new installs are apps by indie devs that I saw
         | someone mention in a Mastodon post or HN comment or something,
         | because that's where the gold is. Midsize and up companies
         | generally don't care enough about user experience to build
         | great apps (instead, optimizing for "engagement" and leaning on
         | A/B tests for design decisions), and obviously neither do
         | shovelware devs of any size. The interesting stuff is almost
         | always built by small operations run by passionate people.
        
           | binkHN wrote:
           | Seconded, and I develop apps in my spare time.
           | 
           | The stores tend to promote the apps that generate the most
           | revenue; often times the best app for your needs is not the
           | one that's making the most money.
        
         | robotnikman wrote:
         | Yep, the early days of the Android and iOS app stores were
         | great, and it was fun stumbling upon hidden gems and games.
        
       | hospitalJail wrote:
       | Stick to Firefox instead of using apps /problem solved.
       | 
       | I know that is an Android unique solution that can't be used on
       | NonAndroid devices, but it significantly reduces entry points.
        
       | jimmySixDOF wrote:
       | I have an old Android phone out of published support updates now
       | but am on the fence about switching to a new Lineage OS just
       | because who knows how much cross checking happens for an old
       | phone's code port maybe its just one or two contributors and
       | who's watching the watchers ?
        
         | tetris11 wrote:
         | This maintainers usually post their sources and their changes
         | from the stock are important, but usually amount to no more
         | than 500 diff lines
        
       | barbazoo wrote:
       | > ThreatFabric detailed how the crooks behind Anatsa will
       | purchase older, abandoned file managing apps, or create their own
       | and let the apps build up a considerable user base before
       | updating them with malicious components.
       | 
       | Maybe it's time to turn off auto update for apps. Auto update is
       | important from a security perspective but if the actor is bad, it
       | might be better to wait and update on demand to catch up with
       | missing fratures and by that time hopefully the malicious app has
       | been removed from the app store. Of course this would only work
       | for standalone apps.
       | 
       | Similar to how we often have intermediate package managers that
       | pin packages to a particular version to not get malware injected
       | one day.
        
         | moomoo11 wrote:
         | Or just use iOS and text, take photos, and use big name apps
         | only like IG.
         | 
         | I used to be into phones. These days I use $150-200 used iPhone
         | SE (2020). Don't care if I drop it or break it. And it takes
         | decent photos (not amazing, not terrible). And it's small.
        
           | Knee_Pain wrote:
           | Ok? Or buy a Samsung and only use Samsung's native apps?
        
           | kramerger wrote:
           | This sort of things happens on iOS also. The big difference
           | is that Google is open while Apple tries to hide it.
           | 
           | The Xcode ghost incident for example affected half a billion
           | installs and 100M users: https://www.intego.com/mac-security-
           | blog/xcodeghost-malware-...
           | 
           | Regarding big name apps... Well, WhatsApp on iOS has been the
           | main attack vector for state actors for a few years now.
           | 
           | https://thedefenceworks.com/blog/zero-click-infection-and-
           | wh...
        
           | kbenson wrote:
           | Just because this article references Android doesn't mean iOS
           | is without its own security issues.[1] The "just use iOS"
           | portion of your advice may be a bit optimistic.
           | 
           | 1: https://www.wired.com/story/kaspersky-apple-ios-zero-day-
           | int...
        
         | EGreg wrote:
         | Auto-updating should be tied to audits by reputable third
         | parties, to sign off on a release. At least two. Why isn't this
         | fone?
        
           | xena wrote:
           | Not doing that is cheaper and there's no regulation that
           | forces companies to do those audits to get things released.
           | We live in capitalism where cheaper wins.
        
             | EGreg wrote:
             | Forget government force, I am talking about industry
             | standards and defaults. People have RedHat, Apple and
             | others for distributing stable app and service versions
             | with operating systems. Same principle should apply to
             | package managers. How can a low-level package break or
             | poison 40,000 other repos overnight?
             | 
             | This culture of Tweeting at 5 am to 5 million people before
             | the truth has a chance to get its pants on is defended in
             | the name of "freedom of speech", but I much prefer the peer
             | review gated approach of science. Not one monopoly
             | gatekeeper but at least 2 reputable ones, before your OS or
             | package manager allows the download (but users can override
             | it if they insist). I think rpm and yum do that..
        
               | jstarfish wrote:
               | Supply chain attacks are a thing in Linux too. Some
               | activist clown tried to brick devices with Russian or
               | Belarusian IPs in the same manner. This system is
               | compromised.
        
           | Knee_Pain wrote:
           | Yes, just audit a 1M LoC app every 2 weeks!
        
         | Terr_ wrote:
         | > Maybe it's time to turn off auto update for apps.
         | 
         | It's very frustrating that I cannot specifically exclude
         | certain apps from auto-updates.
         | 
         | Android forces me to either permit blanket auto-updates, or to
         | click through a big list of pending updated, where a single
         | mis-tap will permanently update the wrong app with no easy way
         | to undo or downgrade.
        
       | [deleted]
        
       | baz00 wrote:
       | Question for people with more expertise here. I just switched to
       | Android recently because I don't fancy getting mugged again for a
       | huge pile of cash for an iPhone. So I've got a Pixel 6A. It's
       | pretty much loaded up with MSFT software and some very well known
       | high profile apps. What risks do I have if I stay out of the play
       | store gutter?
        
         | kramerger wrote:
         | Android had 3 zero days in 2022, iOS had 7. I think they are
         | pretty much similar if you don't install random crap.
         | 
         | I suspect this article is about a bug in Play Protect, which is
         | an on-device security scanner. I don't think iOS has something
         | similar.
        
           | charcircuit wrote:
           | Both platforms scan apps for malware when you upload them to
           | the store before they can be downloaded by users.
        
             | kramerger wrote:
             | Play Protect runs locally on the phone and also covers
             | sideloaded apps.
        
               | charcircuit wrote:
               | That is unrelated to the article.
        
         | jeroenhd wrote:
         | Practically: none, for you at least.
         | 
         | Don't download Microsoft Teams if it claims an app developer
         | with an unrecognisable name and only 500 downloadeds, don't
         | download cracked games, be wary of the obvious free-to-play
         | clones, and if a web page shows a flashing gif warning you that
         | Whatsapp is outdated, don't install the APK file it's trying to
         | push through your browser. It's also important to keep your
         | browser up to date and to think before you grant apps
         | permission described like "control the entire screen" and "give
         | app access to all input and screen content".
         | 
         | Android malware is not that different from Windows malware. It
         | spreads through devices infected from the factory, pirated
         | software, fake download ads, and less commonly, through clones
         | and abandonware on official storefronts like Google Play.
         | 
         | This threat actor is buying abandonware and spreading viruses
         | through updates. Dime-in-a-dozen PDF readers and file managers
         | (that your phone already came with anyway) are at risk, but if
         | you stick to reputable brands you'll be fine. Pick "Google
         | Drive PDF" over "Insomnia Media PDF Viewer - Reader & Editor"
         | with 10k downloads.
         | 
         | Google Play comes with an antivirus program built in (Google
         | Play Protect) that will warn you of known risks. You can
         | disable it if you don't want Google to know about every app you
         | install from other sources, but if you leave it enabled you'll
         | minimize the risk of getting infected.
         | 
         | If you want to be sure you're not getting infected, use
         | F-Droid. F-Droid compiles open-source apps on their own
         | servers, so the source code they receive is the source code the
         | compiled APK uses. Even if your app is open source, there's no
         | way to upload a precompiled APK to the F-Droid website. This
         | makes introducing malware without anyone noticing quite
         | difficult.
        
           | kbenson wrote:
           | > F-Droid compiles open-source apps on their own servers, so
           | the source code they receive is the source code the compiled
           | APK uses. Even if your app is open source, there's no way to
           | upload a precompiled APK to the F-Droid website. This makes
           | introducing malware without anyone noticing quite difficult.
           | 
           | This is a common model, and is basically how most Linux
           | distros work, but it only scales (safely) with people
           | actually paying attention. How many people does F-droid have
           | reviewing the apps that update that they build?
           | 
           | I agree it will be hard to introduce malware without anyone
           | noticing in a strict sense, I'm just not sure they have
           | enough resources to notice _before_ it becomes a problem
           | given how I assume that must work, but I would be happy to be
           | wrong.
        
             | jeroenhd wrote:
             | You're right, of course; being open source does not
             | automatically make apps safe. There's a vetting process by
             | the F-Droid devs before an app gets added ot the repo, but
             | after that changes get picked up without an in-depth
             | review.
             | 
             | With F-Droid it's almost impossible to hide the infection.
             | Once your malicious code has been found eventually, you're
             | one quick scan of every other app away from getting all of
             | your infected apps kicked from the store. You can obfuscate
             | your source code, but that makes any app with obfuscated
             | source code suspect immediately.
             | 
             | This is a lot harder with precompiled apps, especially
             | those loading native libraries. With the tens of thousands
             | of vague shadow companies that hobbyists and small dev
             | shops have left behind over the years, it's impossible to
             | find out which apps to reverse engineer if you're looking
             | for similar infections. Obfuscating compiled code is quite
             | normal as well, whereas open source projects stand to gain
             | very little from obfuscating their source code.
             | 
             | You still need a certain level of trust (and a certain
             | amount of hobbyists/security researchers to go through the
             | apps) but that's inherent in any modern computer system.
             | The days of the VIC-20 where one person could understand
             | the entire system from top to bottom are long behind us,
             | for better and for worse.
        
         | stOneskull wrote:
         | google needs to clean up the whole QR code reader app category.
         | they trick users by having a big button saying 'OPEN' that
         | takes the user to a website asking them to enter their credit
         | card to verify their ID.
        
       | mrd3v0 wrote:
       | Stop. Using. Proprietary. Software.
       | 
       | If you don't control the software, the software controls you.
       | 
       | If users are disallowed from auditing the software source code
       | easily, then this is bound to happen.
        
         | wruza wrote:
         | It still happens with open source software and has nothing to
         | do with a licensing mode.
        
           | easyKL wrote:
           | I don't remember last time I read about malicious code found
           | on an app here: forum.f-droid.org/ Code is available, and
           | license allow the project to distribute them.
        
             | saagarjha wrote:
             | Hardly anybody uses F-Droid, comparatively. The people that
             | do are generally less likely to fall for simple scams.
        
       ___________________________________________________________________
       (page generated 2023-08-03 23:02 UTC)