News: 1612818857

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Barcode scan app amassed millions of downloads before weird update starting popping open webpages...

(2021/02/08)


Barcode Scanner, a popular Android app, slipped undesirable code into an update in early December, an update that had the potential to reach more than 10m devices though actual distribution is believed to be far less.

Several weeks later, Google removed the app from Google Play. Those who downloaded the software and accepted the update may still have on their mobile devices the problematic code, which appears to open the browser and visits websites all by itself.

[1]

Barcode Scanner, distributed by a London-based company called LavaBird, received an update on December 4, 2020, that appears to have introduced the code in question, according to Nathan Collier, a security researcher at Malwarebytes. LavaBird's now-banished Android app shouldn't be confused with ZXing Team's Barcode Scanner that remains in the Play Store.

LavaBird – which was [2]incorporated in March, 2020, and is run by Dmytro Kizema, a resident of Ukraine – did not immediately respond to a request for comment. However, those involved appear to have been using variations on that name for several years and have [3]other apps that they use to sell traffic to advertisers.

[4]

Collier said in a [5]blog post that this was not a case of a third-party SDK within the app going weird: it was a deliberate change. "Furthermore, the added code used heavy obfuscation to avoid detection," he noted.

Collier said Malwarebytes confirmed that the app developer was responsible because the code-signing certificate for known clean versions of the code matched the altered version.

Oops: Google admits failing to wipe all Android apps with location-selling X-Mode SDK from its Play Store [6]READ MORE

After the update was pushed out, it took about three weeks before [7]people's complaints drew attention to Barcode Scanner, at which point Malwarebytes began to block it. The software, which opens users' browsers, redirects them to unwanted websites, and prompts further software installation, has been dubbed Android/Trojan.HiddenAds.AdQR.

The Register asked Google to confirm when it removed Barcode Scanner and whether it has taken, or plans to take, any action to remove subverted versions of Barcode Scanner on Android users' devices. Google's app defense mechanism, [8]Google Play Protect , has the ability to issue notifications about apps, to disable them, and to remove them automatically. We've not heard back from Google about how it responded.

Collier, via a spokesperson for Malwarebytes, said the antivirus biz could not confirm when Google removed the app but it was after he posted about it on the Malwarebytes forum on December 24, 2020. He said he's not sure how many people actually installed the update, and added that Google Play Protect has not removed the app from Android devices.

[9]

Switching up barcode scanning apps appears to be popular. In June last year, security biz TrendMicro [10]reported finding two adware-laden barcode reading apps in Google Play, with 2m downloads between them. The outfit also identified 51 other apps that exhibited the same adware behavior. ®

Get our [11]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YCHChjULQOhLZcO7XkbQCwAAAAY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://find-and-update.company-information.service.gov.uk/company/12512812

[3] https://lavabird-dstudio.com/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YCHChjULQOhLZcO7XkbQCwAAAAY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://blog.malwarebytes.com/android/2021/02/barcode-scanner-app-on-google-play-infects-10-million-users-with-one-update/

[6] https://www.theregister.com/2021/02/06/google_xmode_android_apps_play_store/

[7] https://forums.malwarebytes.com/topic/268286-android-chrome-redirect-not-same-as-others-posted-on-here/?tab=comments#comment-1428593

[8] https://support.google.com/googleplay/answer/2812853?hl=en

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YCHChjULQOhLZcO7XkbQCwAAAAY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://www.trendmicro.com/en_us/research/20/f/barcode-reader-apps-on-google-play-found-using-new-ad-fraud-technique.html

[11] https://whitepapers.theregister.com/

This was inevitable. But Android handled it well.

needmorehare

...and it won't be the last time either. Thankfully, Android pulls all the stops to make sure malware gets minimal privileges. Separate UIDs, separate SELinux contexts (same types, separate categories) and in the future, separate namespaces and seccomp-bpf to limit syscalls.

I fear the day someone deliberately modifies a popular freeware desktop app on Linux/Windows/macOS and actually slurps data en-masse. Desktop systems need proper hardening ASAP.

Re: This was inevitable. But Android handled it well.

IGotOut

Yeah.....thats right. It not like privileges tend to be all or nothing.

It's took ten years to get even basics right...and lets not even mention the location bullshit when "off" actually means "sort of off".

"What surprises you most about mankind?"

God answered:

"That they get bored of being children, are in a rush to grow up, and then long
to be children again. That they lose their health to make money and then lose
their money to restore their health. That by thinking anxiously about the
future, they forget the present, such that they live neither for the present
nor the future. That they live as if they will never die, and they die as if
they had never lived."
-- Jim Brown, published by Reata Strickland as
An Interview with God ISBN 0743229576. (Variation of it was misattributed
to https://en.wikiquote.org/wiki/Tenzin_Gyatso,_14th_Dalai_Lama )