News: 1667835008

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Oh, look: More malware in the Google Play store

(2022/11/07)


in brief A quartet of malware-laden Android apps from a single developer have been caught with malicious code more than once, yet the infected apps remain on Google Play and have collectively been downloaded more than one million times.

The apps come from developer Mobile apps Group, and are infected with the Trojan known as HiddenAds, [1]said security shop Malwarebytes. It analyzed one of Mobile apps Group's products, Bluetooth Auto Connect, which ostensibly does what its name suggests but also much more.

A run of over ten months with malicious code on Google Play? Perhaps it's time to say three strikes and you're out to Mobile apps Group

According to Malwarebytes, once installed the app waits for a few days to start behaving maliciously. Once it takes action, the app begins opening phishing sites in Chrome that range from harmless pay-per-click spam, to sites telling users to download updates, or take action because their device has been infected.

"As a result, unlocking your phone after several hours means closing multiple tabs," Malwarebytes' Nathan Collier said.

Interestingly, the malware in Mobile apps Group's .APKs was removed twice – in January 2021 and again the next month – when the developer uploaded clean versions of Bluetooth Auto Connect before adding the malware back in a future update.

[2]

Collier believes that the developer was likely caught by Google, leading to the clean uploads. Despite that, he notes that the last clean version was published on October 21, 2021, with a new malware-infested version was added to Google Play in December of last year.

[3]

[4]

"Now on version 5.7, that malicious code remains to this date. A run of over ten months with malicious code on Google Play. Perhaps it's time to say three strikes and you're out to Mobile apps Group," Collier said.

Google Play has a history of hosting malicious apps, with perhaps one of the most egregious cases coming to light this past July when [5]60 apps installed by more than 3.3 million users were taken down due to malware.

[6]

This isn't even the first time [7]the HiddenAds Trojan was found on Google Play: It was [8]spotted on the store in 2020, while in 2021 a popular barcode scanning app installed on over 10 million devices was [9]updated to add HiddenAds (and also researched by Collier).

Google has also been accused of [10]failing to police malware pre-loaded onto cheap Android devices , which more than 50 advocacy groups called the company out for in 2020.

Software supply chain attack hits US news media

Proofpoint Threat Research is warning that more than 250 local and regional US newspaper websites have been accessing and serving malicious code to readers following a software supply chain attack.

[11]Google stops enforcing Play store payment rules in India

[12]Windows Subsystem for Android declared ready for prime time

[13]Russia's Facebook-like VK removed from Apple App Store

[14]TikTok faces $29m fine for 'failing to protect UK kids' privacy'

The group responsible is believed to be TA569, or SocGholish, Proofpoint said in a [15]Twitter thread . The group reportedly compromised an unnamed media company that serves JavaScript ads and videos to news sites across the country "by modifying the codebase of this otherwise benign JS."

Proofpoint has tracked TA569 for several years, and [16]in 2020 warned that it was performing similar attacks via HTML injections and CMS compromises. According to Proofpoint, the end goal is an infection with [17]SocGholish malware , which masquerades as an update file for Firefox and other web browsers.

Only the infected media companies serving the ads have the real tally showing how widespread the damage is, Proofpoint said, adding that compromised sites were found serving Boston, New York, Chicago, Washington, DC and other metro areas.

[18]

Proofpoint said TA569 regularly removes and adds new malicious code, "therefore the presence of the payload and malicious content can vary from hour to hour," making this one hard to detect, too.

Nearly half of US government employees use out-of-date mobile devices

Just under half the mobile devices used by US civil servants at all levels of government are running out-of-date OSes, according to a report examining telemetry from more than 200 million devices.

According to security firm [19]Lookout , this includes US federal, state and local employees using outdated versions of Android and iOS on their devices, with far worse numbers reported for Android.

Ten months after the release of Android 12, only 67 percent of federal devices and 54 percent of state/local devices were running the up to date version. Android 11 was on roughly 15 percent of devices at all government levels, while more than 10 percent of state and local devices were still running Android 9.

The only large group of iOS devices not running iOS 15 (the newest version during the data period) were state and local devices, around a quarter of which were still running iOS 14 ten months after the iOS 15 release.

But cybercriminals bent on accessing government devices are turning away from malware and toward simple credential harvesting, meaning those outdated OSes might not be to blame for threat actors gaining a foothold in US government agencies.

Around 50 percent of phishing attacks on government employees attempted to steal credentials, up from around a third the year prior, Lookout said. One bit of good news from the report is that government employees appear to be learning their lesson from being phished.

"Well over 50 percent of federal, state, and local employees who received a notification that they had clicked on a phishing link did not click on a subsequent mobile phishing link." ®

Get our [20]Tech Resources



[1] https://www.malwarebytes.com/blog/news/2022/11/malware-on-the-google-play-store-leads-to-harmful-phishing-sites

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y2k5qvUq6tsyCqGTWIVBWwAAAAk&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y2k5qvUq6tsyCqGTWIVBWwAAAAk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y2k5qvUq6tsyCqGTWIVBWwAAAAk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2022/07/19/google_malware_apps/

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y2k5qvUq6tsyCqGTWIVBWwAAAAk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.malwarebytes.com/blog/detections/android-trojan-hiddenads

[8] https://www.theregister.com/2020/01/09/google_poor_privacy_android/

[9] https://www.theregister.com/2021/02/08/barcode_scan_app_malwarebytes_update/

[10] https://www.theregister.com/2020/01/09/google_poor_privacy_android/

[11] https://www.theregister.com/2022/11/02/play_store_payment_rules_india_paused/

[12] https://www.theregister.com/2022/10/21/windows_subsystem_for_android_released/

[13] https://www.theregister.com/2022/09/28/vk_removed_from_apple_app_store/

[14] https://www.theregister.com/2022/09/26/tiktok_uk_ico_privacy/

[15] https://twitter.com/threatinsight/status/1587865920130752515

[16] https://www.proofpoint.com/us/blog/security-briefs/fake-downloaders-aimed-organizations-canada-france-germany-spain-italy-united

[17] https://redcanary.com/threat-detection-report/threats/socgholish/

[18] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y2k5qvUq6tsyCqGTWIVBWwAAAAk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[19] https://www.lookout.com/form/threats-government-threat-report-lp

[20] https://whitepapers.theregister.com/



"before adding the malware back in a future update"

Pascal Monett

So how is it that said developper is not completely banned ?

He cannot say that he didn't do it on purpose.

Re: "before adding the malware back in a future update"

RyokuMas

Unless things have changed drastically since I was last developing anything in mobile-space (which was a few years ago, I'll admit), a ban could be worked roun easily enough with another $25 and some new personal details for a new developer account.

"Well over 50 percent .."

Pascal Monett

That, to me, says that there's well over 30% that did.

We're not out of the woods yet.

I bet you can't even list apps by publisher

Anonymous Coward

in crappy Googles crappy Android.

Which would be the single easiest way to help folk dump dodgy apps if you aren't going to stop them being inserted into the warez you fling.

I wonder how much longer these outfits can keep up the pretence they aren't liable for any malware they've allowed into their stores. After all, if Waitrose negligence allowed people to infect food with salmonella, you can bet they'd be liable.

Re: I bet you can't even list apps by publisher

Jamie Jones

Sorry to interrupt your little rant, but in the play store app, you can simply do this to view by publisher:

pub:Mobile apps Group

The above links you to this page: [1]pub:Mobile apps Group

HTH. HAND.

[1] https://play.google.com/store/apps/dev?id=5631376253411320738

Re: I bet you can't even list apps by publisher

Anonymous Coward

That wasn't what was asked.

you really must work for Google.

Re: I bet you can't even list apps by publisher

Paul Herber

How does that help though? They look as legitimate as any other app dev.

Robert Tappen Morris, Jr., got six months in jail for crashing 10% of the
computers that Bill Gates made $100 million crashing last weekend.