Six new HiddenAd Trojans found on Google Play with 280,000+ downloads. If you have them installed, remove them. https://t.co/fB1CCttfIZ
Fake VPN app found on Google Play can download and install additional apps.
https://twitter.com/m0br3v/status/1166680295023812609?s=19
https://twitter.com/m0br3v/status/1166680295023812609?s=19
Twitter
I.Zhilyakov
Fake VPN client has been found and removed from Google Play. On command: -opens web, #instagram, #telegram and google play pages -downloads and tries to install other applications ioc: d789d13c6187ad3cd2991b6d387d9e943d394a8c #android #trojan #malware
Two adware apps found on Google Play with over 1.5 million installs.
https://www.symantec.com/blogs/threat-intelligence/stealthy-ad-clicking-apps-google-play
https://www.symantec.com/blogs/threat-intelligence/stealthy-ad-clicking-apps-google-play
Symantec
New Stealthy Ad Clicking Tactics Found in Popular Apps on Google Play
Two apps with over 1.5 million downloads use new method to stealthily click ads on users’ devices. Apps present on Play Store for almost a year before being discovered.
👍1
Forwarded from The Bug Bounty Hunter
Google adds all Android apps with +100m installs to its bug bounty program
https://www.zdnet.com/article/google-adds-all-android-apps-with-100m-installs-to-its-bug-bounty-program/
https://www.zdnet.com/article/google-adds-all-android-apps-with-100m-installs-to-its-bug-bounty-program/
ZDNet
Google adds all Android apps with +100m installs to its bug bounty program
Google will pay security researchers for bugs they report in non-Google Android apps that have over 100 million installs.
Russian police take down malware gang that infected 800,000+ Android smartphones
They rented Hqwar, Asacub (Honli), Cron, CatsElite (MarsElite), Lokibot and modernized Marcher (Rahunok).
https://www.zdnet.com/article/russian-police-take-down-malware-gang-that-infected-800000-android-smartphones/
They rented Hqwar, Asacub (Honli), Cron, CatsElite (MarsElite), Lokibot and modernized Marcher (Rahunok).
https://www.zdnet.com/article/russian-police-take-down-malware-gang-that-infected-800000-android-smartphones/
ZDNet
Russian police take down malware gang that infected 800,000+ Android smartphones
TipTop malware gang was making between $1,500 and $10,500 in daily profits.
Brazilian Android RAT distributed by over 20 apps via Google Play mostly as WhatsApp update exploiting WhatsApp's CVE-2019-3568.
One of the apps had 10,000+ installs.
https://securelist.com/spying-android-rat-from-brazil-brata/92775/
One of the apps had 10,000+ installs.
https://securelist.com/spying-android-rat-from-brazil-brata/92775/
Securelist
Fully equipped Spying Android RAT from Brazil: BRATA
BRATA” is a new Android remote access tool malware family. It exclusively targets victims in Brazil.
A very deep dive into iOS Exploit chains found in the wild
Waterhole attacks - get your iPhone hacked only by visiting hacked website.
https://googleprojectzero.blogspot.com/2019/08/a-very-deep-dive-into-ios-exploit.html
Waterhole attacks - get your iPhone hacked only by visiting hacked website.
https://googleprojectzero.blogspot.com/2019/08/a-very-deep-dive-into-ios-exploit.html
Blogspot
A very deep dive into iOS Exploit chains found in the wild
Posted by Ian Beer, Project Zero Project Zero’s mission is to make 0-day hard. We often work with other companies to find and report se...
How to Extract and Decrypt Signal Conversation History from the iPhone
https://blog.elcomsoft.com/2019/08/how-to-extract-and-decrypt-signal-conversation-history-from-the-iphone/
https://blog.elcomsoft.com/2019/08/how-to-extract-and-decrypt-signal-conversation-history-from-the-iphone/
ElcomSoft blog
How to Extract and Decrypt Signal Conversation History from the iPhone
With over half a million users, Signal is an incredibly secure cross-platform instant messaging app. With emphasis on security, there is no wonder that Signal is frequently picked as a communication tool by those who have something to hide. Elcomsoft Phone…
ARES ADB IOT Botnet Targeting Android Devices especially STBs/ TVs
https://www.wootcloud.com/blogs/ars_botnet.html
https://www.wootcloud.com/blogs/ars_botnet.html
Facebook Android app scans system libraries from their user’s phone in the background and uploads them to their server...without user's permission
https://twitter.com/wongmjane/status/1167463054709334017?s=19
https://twitter.com/wongmjane/status/1167463054709334017?s=19
Twitter
Jane Manchun Wong
Facebook scans system libraries from their Android app user’s phone in the background and uploads them to their server This is called "Global Library Collector" at Facebook, known as "GLC" in app’s code It periodically uploads metadata of system libraries…
Analysis and Reproduction of iOS/OSX Vulnerability: CVE-2019-7286
▪️CVE-2019-7286 was exploited in the wild
▪️The vulnerability seems to be of critical severity
▪️Vulnerability reproduced (includes POC code)
▪️The vulnerability could be used to escalate privileges to root as part of a chain for jailbreak on iOS 12.1.3.
https://blog.zecops.com/vulnerabilities/analysis-and-reproduction-of-cve-2019-7286/
▪️CVE-2019-7286 was exploited in the wild
▪️The vulnerability seems to be of critical severity
▪️Vulnerability reproduced (includes POC code)
▪️The vulnerability could be used to escalate privileges to root as part of a chain for jailbreak on iOS 12.1.3.
https://blog.zecops.com/vulnerabilities/analysis-and-reproduction-of-cve-2019-7286/
Jamf
Jamf Threat Labs | Blog
Global Rankings in Updating Smartphone Software and Security (besides Pixel)
1) Nokia
2) Samsung
3) Xiaomi
4) Huawei
5) Lenovo
https://www.counterpointresearch.com/nokia-leads-global-rankings-updating-smartphone-software-security/
1) Nokia
2) Samsung
3) Xiaomi
4) Huawei
5) Lenovo
https://www.counterpointresearch.com/nokia-leads-global-rankings-updating-smartphone-software-security/
Roaming Mantis(MoqHao/XLoader): spreads via SMShing
Distribution:
Infected Android device sends a SMS with a bit.ly link that links to a Tumblr blog that redirects to a malicous landing page.
https://hitcon.org/2019/CMT/slide-files/d2_s1_r1.pdf
Distribution:
Infected Android device sends a SMS with a bit.ly link that links to a Tumblr blog that redirects to a malicous landing page.
https://hitcon.org/2019/CMT/slide-files/d2_s1_r1.pdf
Review of harmful apps found on Google Play in August 2019
Summary: 204 apps with over 438,400,00 installs.
https://lukasstefanko.com/2019/09/android-security-monthly-recap-8.html
Summary: 204 apps with over 438,400,00 installs.
https://lukasstefanko.com/2019/09/android-security-monthly-recap-8.html
Top Android malware threats in August, 2019
Full list http://skptr.me/malware_timeline_2019.html
Download samples https://github.com/sk3ptre/AndroidMalware_2019
Full list http://skptr.me/malware_timeline_2019.html
Download samples https://github.com/sk3ptre/AndroidMalware_2019
GitHub
GitHub - sk3ptre/AndroidMalware_2019: Popular Android threats in 2019
Popular Android threats in 2019. Contribute to sk3ptre/AndroidMalware_2019 development by creating an account on GitHub.
Fake cryptocurrency exchange app found on Google Play that bypasses SMS 2FA by stealing SMS notifications.
Targets users of 6 different cryptocurrency exchanges. https://twitter.com/ESETresearch/status/1168850608872460288
Targets users of 6 different cryptocurrency exchanges. https://twitter.com/ESETresearch/status/1168850608872460288
Twitter
ESET research
Fake multi-cryptocurrency exchange app found on Google Play bypasses SMS 2FA by stealing SMS notifications. Targets users of 6 different cryptocurrency exchanges. We informed about this threat in June 2019: https://t.co/ILNqPfnmQD #ESETresearch 1/2
Price For Mobile Exploits
For the first time Zerodium pays more for Android then iOS.
https://zerodium.com/program.html#changelog
For the first time Zerodium pays more for Android then iOS.
https://zerodium.com/program.html#changelog
Heap Exploit Development – Case study from an in-the-wild iOS 0-day
https://azeria-labs.com/heap-exploit-development-part-1/
https://azeria-labs.com/heap-exploit-development-part-1/
Azeria-Labs
Heap Exploit Development
Weekly tests of APK files uploaded on Virus Total based on Antivirus engines
Results:
1. K7GW
2. ESET-NOD32
3. Trustlook
4. Avira
5. AhnLab-V3
https://blog.trustlook.com/virustotal-apk-malware-detection-data-20190826-20190901/
Results:
1. K7GW
2. ESET-NOD32
3. Trustlook
4. Avira
5. AhnLab-V3
https://blog.trustlook.com/virustotal-apk-malware-detection-data-20190826-20190901/
Trustlook blog
VirusTotal APK Malware Detection Data -
Week 35: 20190826-20190901
Week 35: 20190826-20190901
At Trustlook, we monitor live feed from VirusTotal (VT). On a daily basis, we
collect APK samples from VT along with detection results from Anti-Virus (AV)
vendors hosted on VT. Using a conservative labeling policy, we are able to
select thousands of benign…
collect APK samples from VT along with detection results from Anti-Virus (AV)
vendors hosted on VT. Using a conservative labeling policy, we are able to
select thousands of benign…
HiddenAd adware with 50,000+ installs found on Google Play
https://twitter.com/ReBensk/status/1169127907958112256
https://twitter.com/ReBensk/status/1169127907958112256
Twitter
Re-ind
Hiddad APP found on Google Play 50,000+ Installs https://t.co/jeFC1OG4Ho after install hides it's icon from the App Drawer and running in the background. force the user to install another app https://t.co/0xYwJ7tNoI
Android banking Trojan - Hydra - found on Google Play with 10,000+ installs
https://twitter.com/0xabc0/status/1169186569615532032
https://twitter.com/0xabc0/status/1169186569615532032
Twitter
Ahmet Bilal Can
#hydra 10.000+ installs. reported on 12 july, still up :( https://t.co/lk3TyLBQVO time check bypass noscript : https://t.co/aRUtRo2R9y sends request to ip-api.json checks if country code is `TR`. c2: hxxp://23.106.124.182:2055