News: 1598300818

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

This'll upset the Apple cart: 1,200 iOS apps downloaded 300 million times a month include 'ad fraud' code

(2020/08/24)


Video For over a year, a widely used code library from Chinese mobile ad biz Mintegral is alleged to have been covertly capturing data about app users' online interactions to steal ad revenue.

According to security biz Snyk, the Mintegral SDK purports to be a tool that helps app developers make money from ads in mobile apps. Used in an estimated 1,200 iOS apps that generate 300 million downloads per month, the iOS version of the library is said to contain malicious code designed to monitor user activity in order to facilitate what's known as attribution fraud.

To maximize mobile ad revenue, developers will often include third-party SDKs in their app code so the app works with multiple ad networks. Ad mediation platforms attempt to maximize the revenue for the app maker by choosing the optimal ad provider for each click and keeping track of which network gets credit for the interaction.

Attribution fraud occurs when someone tries to take credit for ad-related events – in this instance, clicks resulting in the installation of an advertised app – that should be attributed to another party.

Chrome Web Store slammed again after 295 ad-injecting, spammy extensions downloaded 80 million times [1]READ MORE

"The Mintegral SDK is able to intercept all of the ad clicks (and other URL clicks as well) within the application," said Alyssa Miller, application security advocacy at Snyk, in a [2]blog post on Monday.

"It uses this information to forge click notifications to the attribution provider. The forged notifications make it appear that the ad click came through their network even though it may have been a competing ad network that served the ad."

This not only steals advertising revenue that should have gone to other networks, says Miller, but also makes Mintegral appear to perform better than competing ad platforms, making it more attractive to developers.

What's more, Miller says that the SDK also captures sensitive data – the URL requested, which could include personally identifying information; the headers of the request, which could include auth tokens that incorporate personal data like email addresses; and the device's IDFA and IMEI identifiers.

China-based apps TikTok and WeChat recently got in trouble for less overtly dubious behavior, the [3]undisclosed collection of personal information.

According to Miller, the Mintegral SDK includes anti-forensic capabilities designed to turn off malicious behavior when someone might be trying to analyze the code. It checks to see if the phone is rooted, or whether it can detect use of a proxy or debugging tools.

As Synk demonstrates in this video below, those investigating the app had to set flags on the server endpoint response to convince the app it wasn't being monitored.

[4]Youtube Video

The Mintegral SDK, it's [5]claimed , relies on a technique called method swizzling, a way of changing runtime functionality that involves injecting code into iOS event handlers to capture click events. The company logs that data to its server and registers a click notification with the attribution platform alongside the ad network that was actually responsible.

Thanks to what's known as the last-touch attribution model, where ad conversion credit goes to the provider closest to the user's action, Mintegral gets paid instead of the ad network that was actually responsible.

The malicious functionality supposedly has been present since version ( [6]5.5.1 ) of the iOS SDK was published on Jul 17, 2019. Snyk says the Android SDK doesn't exhibit bad behavior.

Apple, Mintegral, and Snyk did not immediately respond to requests for comment. ®

Get our [7]Tech Resources



[1] https://www.theregister.com/2020/08/07/chrome_web_store_slammed/

[2] https://snyk.io/blog/sourmint-malicious-code-ad-fraud-and-data-leak-in-ios/

[3] https://www.theregister.com/2020/08/07/us_wechat_tiktok_national_security_threats/

[4] https://www.youtube.com/watch?v=MMuL5MaQeLM&feature=emb_title

[5] https://snyk.io/research/sour-mint-malicious-sdk/

[6] https://github.com/Mintegral-official/MintegralAdSDK-iOS/releases/tag/5.5.1

[7] https://whitepapers.theregister.com/

That 30% well worth it

Falmari

Nice to see that 30% Apple cream off protecting their users.

I assume Apple are getting 30% of the add click revenue that goes to the app creator.

Re: That 30% well worth it

LeahroyNake

Now that it is in the media expect Apple to ummmm do something, or just maybe look at the revenue it is bringing in and quietly ignore it.a

MoPub says what?

Anonymous Coward

Apparently MoPub had a web page for downloading the Mintegral SDK as well but now it's serving up a 404:

https://developers.mopub.com/publishers/mediation/networks/mintegral/

Damage control?

How did this slip through?

HildyJ

Google's Play Store gets rightly dinged for apps such as this but the numbers are orders of magnitude less than this. While I decry Apple's walled garden, I previously did buy their argument that the wall keeps this sort of thing for,from happening. Did Apple know and not care (for economic or political reasons)? Or is their app vetting just a myth?

Barth's Distinction:
There are two types of people: those who divide people into two
types, and those who don't.