HiddenApp Trojans that hide its presence and display ads found on Google Play: discovered 15 apps with over 1,300,000 installs
https://news.sophos.com/en-us/2019/10/08/icon-hiding-android-adware-returns-to-the-play-market/
https://news.sophos.com/en-us/2019/10/08/icon-hiding-android-adware-returns-to-the-play-market/
Sophos News
Icon-hiding Android adware returns to the Play Market
Adware apps attempt to evade easy removal by, literally, hiding their app icons from users
Doctor Web’s overview of malware detected on mobile devices in September 2019
https://news.drweb.com/show/?i=13446&lng=en
https://news.drweb.com/show/?i=13446&lng=en
Dr.Web
Dr.Web — Doctor Web’s overview of malware detected on mobile devices in September 2019
Find out on Doctor Web’s site about the latest virus threats and information security issues.
Two spy apps that steal contact list found on Google Play with 110+ installs
https://twitter.com/s_metanka/status/1181192866875559936
https://twitter.com/s_metanka/status/1181192866875559936
Twitter
smtnk
These two young apps on @GooglePlay steal the users' contact lists and leak them all (~3k unique records) via unprotected Firebase instances, mostly UAE/Pakistan/Saudi Arabia victims it seems. #Android #Malware https://t.co/6INCOHBiLE https://t.co/o1mPKjrHNr
New Joker Trojan app with 100,000+ installs found on Google Play
https://twitter.com/s_metanka/status/1181592422796664837
https://twitter.com/s_metanka/status/1181592422796664837
Twitter
smtnk
A new Joker app on @GooglePlay ”Amusing game station" - 100,000+ installs. The loader is slightly improved, the core build is an old s8-7-release. Targets: GR,AT,DE,PK,UAE,BD,TH. Distribution C&C: doocims[.]com, main C&C: 18.139.46[.]15 https://t.co/NXfFLZz6rD…
Analysis of WhatsApp bug CVE-2019-3568
https://github.com/maddiestone/ConPresentations/blob/master/Jailbreak2019.WhatsUpWithWhatsApp.pdf
https://github.com/maddiestone/ConPresentations/blob/master/Jailbreak2019.WhatsUpWithWhatsApp.pdf
GitHub
ConPresentations/Jailbreak2019.WhatsUpWithWhatsApp.pdf at master · maddiestone/ConPresentations
Slide decks from my conference presentations. Contribute to maddiestone/ConPresentations development by creating an account on GitHub.
Google has removed 29 popular Android apps with a total download of more 10 million from Google Play store
https://m.gadgetsnow.com/slideshows/delete-these-29-popular-apps-from-your-android-phone-right-now/amp_photolist/71573856.cms
https://m.gadgetsnow.com/slideshows/delete-these-29-popular-apps-from-your-android-phone-right-now/amp_photolist/71573856.cms
Gadgets Now
Delete these 29 popular apps from your Android phone right now | Gadgets Now
Adware app with 10,000+ installs on Google Play
https://twitter.com/ReBensk/status/1183742308652466178?s=19
https://twitter.com/ReBensk/status/1183742308652466178?s=19
Twitter
Re-ind
AdDisplay.Clevernet Malware Found on Google Play 10,000+ Installs Display Ads with full screen https://t.co/as6KAW65eY
Joker Trojan found on Google Play with 10,000+ installs
https://twitter.com/sh1shk0va/status/1184054662003134464?s=19
https://twitter.com/sh1shk0va/status/1184054662003134464?s=19
Twitter
Tatyana Shishkova
Yet another #Joker Trojan on Google Play. 10,000+ installs, contacts nichfyy[.]com, 52.77.93[.]217. https://t.co/PeUMxyCUbc
Seven HiddenApp Trojans with 190,000+ installs found on Google Play
https://twitter.com/0xabc0/status/1184373381086531584
https://twitter.com/0xabc0/status/1184373381086531584
Twitter
Ahmet Bilal Can
#HiddenApp total of 190.000+ installs. drops another app to show full screen ads. Dropper apps : https://t.co/INVS618R2G Adware : https://t.co/EVo7A9rN71
Subnoscription scam with 1,000,000+ installs requests €94.99 per week after 3 day free trial
https://twitter.com/fs0c131y/status/1184414820281540608?s=19
https://twitter.com/fs0c131y/status/1184414820281540608?s=19
Twitter
Elliot Alderson
This horoscope app available on the PlayStore has been downloaded 1M+ times. You have 3-days free and after it’s €94.99/week… Don’t worry this app has been verified by PlayProtect... https://t.co/gWlmacyucY
Qu1ckR00t - Exploit CVE-2019-2215 to Achieve Root
Blog: https://hernan.de/blog/2019/10/15/tailoring-cve-2019-2215-to-achieve-root/
PoC exploit: https://github.com/grant-h/qu1ckr00t
Blog: https://hernan.de/blog/2019/10/15/tailoring-cve-2019-2215-to-achieve-root/
PoC exploit: https://github.com/grant-h/qu1ckr00t
hernan.de
Tailoring CVE-2019-2215 to Achieve Root
When I heard about the emergency disclosure of CVE-2019-2215 by Project Zero, I decided to replicate the exploit on my local device to see it in action. I so...
How to Reverse Engineer an iOS App and macOS Software
https://www.apriorit.com/dev-blog/363-how-to-reverse-engineer-os-x-and-ios-software
https://www.apriorit.com/dev-blog/363-how-to-reverse-engineer-os-x-and-ios-software
Apriorit
How to Reverse Engineer an iOS App - Apriorit
Learn how to reverse engineer an iOS app, break down its components, and understand functionality without source code access for debugging or maintenance.
Checkrain fake iOS jailbreak leads to click fraud
https://blog.talosintelligence.com/2019/10/checkrain-click-fraud.html
https://blog.talosintelligence.com/2019/10/checkrain-click-fraud.html
Cisco Talos Blog
Checkrain fake iOS jailbreak leads to click fraud
By Warren Mercer and Paul Rascagneres.
Introduction
Attackers are capitalizing on the recent discovery of a new vulnerability that exists across legacy iOS hardware. Cisco Talos recently discovered a malicious actor using a fake website that claims to give…
Introduction
Attackers are capitalizing on the recent discovery of a new vulnerability that exists across legacy iOS hardware. Cisco Talos recently discovered a malicious actor using a fake website that claims to give…
Fake Antivirus on Google Play with 1,000+ installs
https://twitter.com/ReBensk/status/1184830278532882433?s=19
https://twitter.com/ReBensk/status/1184830278532882433?s=19
Twitter
Re-ind
Fake-AV Found on Google Play 1,000+ Installs https://t.co/oqDiHtfhQy
Subnoscription scams found on Google Play
26 apps with 8,000,000+ installs
https://twitter.com/fs0c131y/status/1184447437781557248?s=19
26 apps with 8,000,000+ installs
https://twitter.com/fs0c131y/status/1184447437781557248?s=19
Twitter
Elliot Alderson
The scammers behind this app have released 26 apps, under 3 different names, with a total of over 8,000,000 downloads. @GooglePlay: It's time to do something! Developer accounts: - https://t.co/xn8ExycwM9 - https://t.co/9IoddRqg6u - https://t.co/YSh1jEKS0y…
Clicker for Android subscribes users to paid services #Joker #Malware
https://news.drweb.com/show/?i=13464&lng=en
https://news.drweb.com/show/?i=13464&lng=en
Dr.Web
Clicker for Android subscribes users to paid services
Doctor Web has detected a clicker trojan that can automatically subscribe users to paid services in the official Android app store.
Hiddad app found on Google Play 100,000+ Installs
https://twitter.com/ReBensk/status/1185065215416623104
https://twitter.com/ReBensk/status/1185065215416623104
Twitter
Re-ind
Hiddad app found on Google Play 100,000+ Installs Display Ads with full screen https://t.co/WFf61QP9Ww
UC Browser downloaded a third-party app store over unsecured channels
https://www.zscaler.com/blogs/research/uc-browser-app-abuses-may-have-exposed-500-million-users
https://www.zscaler.com/blogs/research/uc-browser-app-abuses-may-have-exposed-500-million-users
Zscaler
UC Browser app abuses and exposed 500 million users | Blog
As we began to analyze the UC Browser app, we found requests were being made to download an additional APK over an unsecured channel.
HiddenApp found on Google Play with 500,000+ installs
https://twitter.com/ReBensk/status/1185188429518139392?s=19
https://twitter.com/ReBensk/status/1185188429518139392?s=19
Twitter
Re-ind
Hiddad app Packed with Jiagu packer found on Google Play 500,000+ Installs after install hides it's icon from the App Drawer and running in the background. https://t.co/0cPl31uuhN
Joker Trojan found on Google Play
Three apps with 20,000+ installs
https://twitter.com/ReBensk/status/1186227496460513280
Three apps with 20,000+ installs
https://twitter.com/ReBensk/status/1186227496460513280
Twitter
Re-ind
Three Joker app's found on Google Play: https://t.co/apqhtPsAcp https://t.co/QZgD6Yj6Nt https://t.co/UBXuVj4nW3
More Joker Trojans on Google Play
8 apps with 196,000+ installs
https://twitter.com/m0br3v/status/1186277973923696641
https://twitter.com/sh1shk0va/status/1186291616769814529
8 apps with 196,000+ installs
https://twitter.com/m0br3v/status/1186277973923696641
https://twitter.com/sh1shk0va/status/1186291616769814529
Twitter
I.Zhilyakov
And more #joker samples: com.billiards.wallpapers - October 18, 2019, 10,000+ com.peculiarwallpaper.wpshow - October 15, 2019, 50,000+ com[.de.sourceforge.opencamera - October 16, 2019, 10,000+ com.zima.latest.gamelist - October 15, 2019, 100,000+ #malware…