Showing posts with label Android app. Show all posts
Showing posts with label Android app. Show all posts

Saturday, 10 June 2017

Say Hello to Dvmap: The First Android Malware with Code Injection

A powerful Android Trojan with novel code injection features that posed as a game has been discovered in the Google Play Store.

The Trojan has been downloaded from Google's official app marketplace over 50,000 times since March 2017 and is a particularly dangerous form of malware because it it can inject code into the system library and remove root-detection features designed to detect malicious intrusions.


Uncovered by cyber-security researchers at Kaspersky Lab, the Dvmap Trojan is not only capable of obtaining root access rights on Android devices but has the ability to monitor information and install other applications.

Dvmap was distributed while posing as a simple, addictive puzzle game called colourblock, posted under the name "Retgumhoap Kanumep". Developers bypassed the store's security checks by uploading a clean app at the end of March. They then updated this with a malicious version for a short period of time before uploading another clean version. Researchers say they did at least five times in the space of four weeks, successfully tricking Google Play in the process.

Once successfully installed on the device, the Trojan installs a root exploit back installing several tools - which appear to contain comments in Chinese, potentially pointing to the malware authors - in order to run the main phase and overwriting Android's code with malicious code. Researchers note that this could be "very dangerous" and cause some devices to crash.

If successfully installed and executed, Dvmap can successfully connect to a command and control server - but in the device being investigated it received no comments. Researchers suggest that if allowed to run, additional malware or advertising files could be stored on the device.

Those worried they may have been infected by Dvmap are advised to back up all their data and perform a factory data reset of their device.

Kaspersky Lab has reported the Trojan to Google, and it has now been removed from the store - but it represents just the latest instance of malicious apps sneaking into the Play store, in Google's ongoing battle with Android malware.

Tuesday, 30 May 2017

After WannaCry, it’s Judy now: malware hides in apps, infects 36.5million devices

There’s a new piece of Android malware on the loose and it’s a doozy. Originally discovered by researchers at Check Point last week, the malware has been dubbed “Judy” and is potentially one of the most widely spread pieces of Android malware we’ve seen to date. It’s currently believed that upwards of 36.5 million Android devices may have already been infected.


As the firm explains, the malware "is an auto-clicking adware which was found on 41 apps developed by a Korean company."

Checkpoint says 'Judy' generates fraudulent clicks on ads, which results in revenue for the perpetrators, who created a "benign bridgehead app", which inserts a connection to the users' phone into the app store.

That means once a particular user downloads an app, it "silently registers receivers which establish a connection with the C&C server," which in turn replies with the "malicious payload."

Notably, Google is aware of the malware campaign and has removed the offending apps, which comprised several cooking and fashion games using the 'Judy' brand, from its online store.

The Korean publisher thought to be responsible for the infected apps is reportedly known as "ENISTUDIO," though other publishers have also been said to have released apps with the malware included.

Precisely how the infected apps made it through the Google Play Store screening process remains unclear, but Checkpoint does offer the following explanation: "Hackers can hide their apps' real intentions or even manipulate users into leaving positive ratings, in some cases unknowingly. Users cannot rely on the official app stores for their safety, and should implement advanced security protections capable of detecting and blocking zero-day mobile malware."

Check CSU for more info.

Saturday, 8 October 2016

How to encrypt your Facebook messages with Secret Conversations?



If your eyes lit up at this headline, it’s likely that you’ve got something to hide.
Facebook has now rolled out its secret chats to everyone. But you probably haven’t actually got them.

The company has announced that it has turned on encrypted chats for all of the 900 million people who use Facebook Messenger. That technology makes it impossible for anyone but the person sending or receiving messages to read them – meaning that neither Facebook nor other people like spying agencies would be able to read them.

But the feature is opt-in. That means that for the vast majority of users, Facebook messages are still readable by Facebook itself as well as anyone who was able to gain access to Facebook’s data.

And it must be opted into for every single conversation, too. With other tools like WhatsApp, encrypted conversations are either on or off – with Facebook Messenger, they must be begun each time every time you speak to someone.

The difficulties with turning on encryption are likely to stem from two main things. The first is that hiding messages from law enforcement can be tricky, as has been seen with authorities that have arrested WhatsApp executives because the company has refused to open up conversations. The other is that it keeps the information out of the reaches of Facebook, making it harder to mine for data.

Facebook says that those messages that aren’t encrypted are still safe. But they are far from as safe as when they are encrypted, and they are also able to be read by the company for things like ads and data collection – even if they’re not actually being read by human beings that are intercepting them.

“Your messages are already secure, but Secret Conversations are encrypted from one device to another,” a message in the app says when the feature is switched on.
That’s done by using the app and clicking the secret option in the top right of the new message screen. It requires the latest version of the app for iOS or Android.

As well as making those chats encrypted, it also allows people to set expiration timers for their messages, meaning they’ll disappear in five seconds or one day depending on the settings.

The decision to roll out encryption across Facebook Messenger comes soon after WhatsApp did the same. But WhatsApp turned the feature on by default, meaning that as soon as people started using the most recent version of the app it got turned on.

How to use Secret Conversations?

From the Messenger landing page, tap on your profile section, which is the person icon on the upper right of the screen. Scroll down until you see Secret Conversations and tap it. On the next screen, make sure the Secret Conversations slider is activated. Once it is, Secret Conversations are enabled for your device. 



There are two ways to start an encrypted conversation in Messenger. The first is to create a new message as you usually do. Right at the top of the message creation screen you’ll see a lock icon next to a slider button. Click that and the screen theme changes color from blue to black. Now, choose the contact you want to start an encrypted conversation with, and you’re on your way.

After you send an encrypted message the person receiving it will have to agree to use the Secret Conversations feature. Once they do, they’ll see your message.

The second way is to initiate an encrypted conversation from a pre-existing message thread. Tap the i icon in the top right-hand corner of the message thread, and on the next screen tap Secret Conversation. The screen will turn to a black theme again, and you’re good to go.

To view an open secret conversation thread just choose it from the list of open message threads on the main screen of the app.

Secret Conversations work almost like regular Facebook messages but not quite. You can send text, emoji, stickers, and pictures; however, gifs, videos, voice calling, and payments are not supported.

Facebook Link