[HN Gopher] Malicious Android Apps Slip into Disguise
___________________________________________________________________
Malicious Android Apps Slip into Disguise
Author : todsacerdoti
Score : 71 points
Date : 2023-08-03 11:31 UTC (11 hours ago)
(HTM) web link (krebsonsecurity.com)
(TXT) w3m dump (krebsonsecurity.com)
| Double_a_92 wrote:
| Am I the only one that basically gave up on the Appstore and Apps
| in general? It used to be exiting, but nowadays it's almost
| always complete annoying garbage.
|
| E.g. recently I wanted to try an App to identify insects. There
| were a few that seemed nice and free. After I installed them they
| were full of ads and nagged me for a 7-day trial signup. And even
| after I did, the app didn't even work particularly well.
| acomjean wrote:
| I haven't downloaded an app from the store in forever.
|
| Websites generally work on mobile so that is my chosen path
| these days. They're not as slick, but I can accomplish what I
| want.
| binkHN wrote:
| I do this where I can, but, for the sites I use more often, I
| tend to get a far better experience with the app.
| vctrnk wrote:
| Out of curiosity, did you needed some particular feature in
| such an app? I've found that Google Lens is pretty darn good at
| identifying plants, insects, fungi and whatnot (assuming your
| camera has a decent macro mode).
| jabroni_salad wrote:
| The only problem with Lens is that it is "magic" and doesn't
| have a failure state beyond giving junk results should it
| fail. I don't think I would ever trust it for a "can I eat
| this" indicator on a mushroom with how many visual lookalikes
| there are out there. What if the contrast isn't good enough
| to catch colorations and the gills are not in sight?
|
| Merlin Bird ID is so good in comparison, probably the best in
| the "ID this thing" category of apps I have ever tried.
| Photos do a lot, but if you don't get a good ID it will ask
| some questions about the bird's behavior and your
| circumstances to narrow down your search.
| tetromino_ wrote:
| Even if you identified the mushroom species, sometimes that
| is not enough to know whether it is safe to eat. The same
| species can be edible (perhaps after some soaking) or
| dangerously poisonous depending on the geographic area
| where it grew.
| kotaKat wrote:
| Same thing on iOS. Every time I open the App Store the "Today"
| section is the same goddamn set of "popular apps", the same
| stupid-ass MTX "matching" game with the same goofy face, and
| the same old same old services and apps.
|
| What's pushing me to discover if every time I open it it's an
| ad begging me to install TikTok?
| dylan604 wrote:
| >Am I the only one that basically gave up on the Appstore and
| Apps in general?
|
| No, you're not alone, but I get the sense we're in a small
| group of users. Maybe there are more collected here on HN, but
| in the wild, most people will install an app without any
| consideration for possible reasons not to install.
| gochi wrote:
| I feel similarly about all digital stores from apps to games.
| There's zero curation anywhere. Everyone wants to be the "dump
| all your garbage here and let consumers pick while we get
| 10-30% cut". It's like wading through a sea of cheap rip offs
| and apps named like a terrible Amazon listing trying to hit as
| many keywords as possible.
|
| I would love an app store that commits to much higher standards
| on all fronts. I think the subscription format that the likes
| of Setapp use could be very useful here in that it would be
| shared among these apps that meet high standards.
| criddell wrote:
| I don't particularly have a problem with stores filed with
| junk (as long as it isn't fraudulent) because I don't really
| use the stores unless I know what I want. I don't think I
| could trust in-store curators but that's okay because I get
| good recommendations from friends and writers. Look for
| curation outside of the stores.
| jwells89 wrote:
| I still download new apps on iOS and once in a blue moon on
| Android, but they're rarely discovered through the App
| Store/Play Store.
|
| Nearly all new installs are apps by indie devs that I saw
| someone mention in a Mastodon post or HN comment or something,
| because that's where the gold is. Midsize and up companies
| generally don't care enough about user experience to build
| great apps (instead, optimizing for "engagement" and leaning on
| A/B tests for design decisions), and obviously neither do
| shovelware devs of any size. The interesting stuff is almost
| always built by small operations run by passionate people.
| binkHN wrote:
| Seconded, and I develop apps in my spare time.
|
| The stores tend to promote the apps that generate the most
| revenue; often times the best app for your needs is not the
| one that's making the most money.
| robotnikman wrote:
| Yep, the early days of the Android and iOS app stores were
| great, and it was fun stumbling upon hidden gems and games.
| hospitalJail wrote:
| Stick to Firefox instead of using apps /problem solved.
|
| I know that is an Android unique solution that can't be used on
| NonAndroid devices, but it significantly reduces entry points.
| jimmySixDOF wrote:
| I have an old Android phone out of published support updates now
| but am on the fence about switching to a new Lineage OS just
| because who knows how much cross checking happens for an old
| phone's code port maybe its just one or two contributors and
| who's watching the watchers ?
| tetris11 wrote:
| This maintainers usually post their sources and their changes
| from the stock are important, but usually amount to no more
| than 500 diff lines
| barbazoo wrote:
| > ThreatFabric detailed how the crooks behind Anatsa will
| purchase older, abandoned file managing apps, or create their own
| and let the apps build up a considerable user base before
| updating them with malicious components.
|
| Maybe it's time to turn off auto update for apps. Auto update is
| important from a security perspective but if the actor is bad, it
| might be better to wait and update on demand to catch up with
| missing fratures and by that time hopefully the malicious app has
| been removed from the app store. Of course this would only work
| for standalone apps.
|
| Similar to how we often have intermediate package managers that
| pin packages to a particular version to not get malware injected
| one day.
| moomoo11 wrote:
| Or just use iOS and text, take photos, and use big name apps
| only like IG.
|
| I used to be into phones. These days I use $150-200 used iPhone
| SE (2020). Don't care if I drop it or break it. And it takes
| decent photos (not amazing, not terrible). And it's small.
| Knee_Pain wrote:
| Ok? Or buy a Samsung and only use Samsung's native apps?
| kramerger wrote:
| This sort of things happens on iOS also. The big difference
| is that Google is open while Apple tries to hide it.
|
| The Xcode ghost incident for example affected half a billion
| installs and 100M users: https://www.intego.com/mac-security-
| blog/xcodeghost-malware-...
|
| Regarding big name apps... Well, WhatsApp on iOS has been the
| main attack vector for state actors for a few years now.
|
| https://thedefenceworks.com/blog/zero-click-infection-and-
| wh...
| kbenson wrote:
| Just because this article references Android doesn't mean iOS
| is without its own security issues.[1] The "just use iOS"
| portion of your advice may be a bit optimistic.
|
| 1: https://www.wired.com/story/kaspersky-apple-ios-zero-day-
| int...
| EGreg wrote:
| Auto-updating should be tied to audits by reputable third
| parties, to sign off on a release. At least two. Why isn't this
| fone?
| xena wrote:
| Not doing that is cheaper and there's no regulation that
| forces companies to do those audits to get things released.
| We live in capitalism where cheaper wins.
| EGreg wrote:
| Forget government force, I am talking about industry
| standards and defaults. People have RedHat, Apple and
| others for distributing stable app and service versions
| with operating systems. Same principle should apply to
| package managers. How can a low-level package break or
| poison 40,000 other repos overnight?
|
| This culture of Tweeting at 5 am to 5 million people before
| the truth has a chance to get its pants on is defended in
| the name of "freedom of speech", but I much prefer the peer
| review gated approach of science. Not one monopoly
| gatekeeper but at least 2 reputable ones, before your OS or
| package manager allows the download (but users can override
| it if they insist). I think rpm and yum do that..
| jstarfish wrote:
| Supply chain attacks are a thing in Linux too. Some
| activist clown tried to brick devices with Russian or
| Belarusian IPs in the same manner. This system is
| compromised.
| Knee_Pain wrote:
| Yes, just audit a 1M LoC app every 2 weeks!
| Terr_ wrote:
| > Maybe it's time to turn off auto update for apps.
|
| It's very frustrating that I cannot specifically exclude
| certain apps from auto-updates.
|
| Android forces me to either permit blanket auto-updates, or to
| click through a big list of pending updated, where a single
| mis-tap will permanently update the wrong app with no easy way
| to undo or downgrade.
| [deleted]
| baz00 wrote:
| Question for people with more expertise here. I just switched to
| Android recently because I don't fancy getting mugged again for a
| huge pile of cash for an iPhone. So I've got a Pixel 6A. It's
| pretty much loaded up with MSFT software and some very well known
| high profile apps. What risks do I have if I stay out of the play
| store gutter?
| kramerger wrote:
| Android had 3 zero days in 2022, iOS had 7. I think they are
| pretty much similar if you don't install random crap.
|
| I suspect this article is about a bug in Play Protect, which is
| an on-device security scanner. I don't think iOS has something
| similar.
| charcircuit wrote:
| Both platforms scan apps for malware when you upload them to
| the store before they can be downloaded by users.
| kramerger wrote:
| Play Protect runs locally on the phone and also covers
| sideloaded apps.
| charcircuit wrote:
| That is unrelated to the article.
| jeroenhd wrote:
| Practically: none, for you at least.
|
| Don't download Microsoft Teams if it claims an app developer
| with an unrecognisable name and only 500 downloadeds, don't
| download cracked games, be wary of the obvious free-to-play
| clones, and if a web page shows a flashing gif warning you that
| Whatsapp is outdated, don't install the APK file it's trying to
| push through your browser. It's also important to keep your
| browser up to date and to think before you grant apps
| permission described like "control the entire screen" and "give
| app access to all input and screen content".
|
| Android malware is not that different from Windows malware. It
| spreads through devices infected from the factory, pirated
| software, fake download ads, and less commonly, through clones
| and abandonware on official storefronts like Google Play.
|
| This threat actor is buying abandonware and spreading viruses
| through updates. Dime-in-a-dozen PDF readers and file managers
| (that your phone already came with anyway) are at risk, but if
| you stick to reputable brands you'll be fine. Pick "Google
| Drive PDF" over "Insomnia Media PDF Viewer - Reader & Editor"
| with 10k downloads.
|
| Google Play comes with an antivirus program built in (Google
| Play Protect) that will warn you of known risks. You can
| disable it if you don't want Google to know about every app you
| install from other sources, but if you leave it enabled you'll
| minimize the risk of getting infected.
|
| If you want to be sure you're not getting infected, use
| F-Droid. F-Droid compiles open-source apps on their own
| servers, so the source code they receive is the source code the
| compiled APK uses. Even if your app is open source, there's no
| way to upload a precompiled APK to the F-Droid website. This
| makes introducing malware without anyone noticing quite
| difficult.
| kbenson wrote:
| > F-Droid compiles open-source apps on their own servers, so
| the source code they receive is the source code the compiled
| APK uses. Even if your app is open source, there's no way to
| upload a precompiled APK to the F-Droid website. This makes
| introducing malware without anyone noticing quite difficult.
|
| This is a common model, and is basically how most Linux
| distros work, but it only scales (safely) with people
| actually paying attention. How many people does F-droid have
| reviewing the apps that update that they build?
|
| I agree it will be hard to introduce malware without anyone
| noticing in a strict sense, I'm just not sure they have
| enough resources to notice _before_ it becomes a problem
| given how I assume that must work, but I would be happy to be
| wrong.
| jeroenhd wrote:
| You're right, of course; being open source does not
| automatically make apps safe. There's a vetting process by
| the F-Droid devs before an app gets added ot the repo, but
| after that changes get picked up without an in-depth
| review.
|
| With F-Droid it's almost impossible to hide the infection.
| Once your malicious code has been found eventually, you're
| one quick scan of every other app away from getting all of
| your infected apps kicked from the store. You can obfuscate
| your source code, but that makes any app with obfuscated
| source code suspect immediately.
|
| This is a lot harder with precompiled apps, especially
| those loading native libraries. With the tens of thousands
| of vague shadow companies that hobbyists and small dev
| shops have left behind over the years, it's impossible to
| find out which apps to reverse engineer if you're looking
| for similar infections. Obfuscating compiled code is quite
| normal as well, whereas open source projects stand to gain
| very little from obfuscating their source code.
|
| You still need a certain level of trust (and a certain
| amount of hobbyists/security researchers to go through the
| apps) but that's inherent in any modern computer system.
| The days of the VIC-20 where one person could understand
| the entire system from top to bottom are long behind us,
| for better and for worse.
| stOneskull wrote:
| google needs to clean up the whole QR code reader app category.
| they trick users by having a big button saying 'OPEN' that
| takes the user to a website asking them to enter their credit
| card to verify their ID.
| mrd3v0 wrote:
| Stop. Using. Proprietary. Software.
|
| If you don't control the software, the software controls you.
|
| If users are disallowed from auditing the software source code
| easily, then this is bound to happen.
| wruza wrote:
| It still happens with open source software and has nothing to
| do with a licensing mode.
| easyKL wrote:
| I don't remember last time I read about malicious code found
| on an app here: forum.f-droid.org/ Code is available, and
| license allow the project to distribute them.
| saagarjha wrote:
| Hardly anybody uses F-Droid, comparatively. The people that
| do are generally less likely to fall for simple scams.
___________________________________________________________________
(page generated 2023-08-03 23:02 UTC)