bk99.de entertain the web since 1997

The tricks with the Google security hole

Summary

In early 2020 Trend Micro found malicious apps in the Google Play Store that exploited an Android hole previously used by customers of the spyware maker NSO. Google itself had discovered the hole around a year and a half earlier. The apps Camero and Filecrypt Manager served as droppers and secretly installed the spy app Callcam.

Ideas

  • Harmless-looking apps download the actual malware afterwards.
  • A known hole that had not been closed everywhere remained exploitable for a long time.
  • The installation was hidden from the user.
  • Filecrypt Manager abused the accessibility function to hide installations behind a full-screen window.

Insights

  • With Android, a lot of time often passes between discovery and the fix reaching all devices.
  • State spyware techniques later end up with ordinary criminals.

Facts

  • The apps were discovered by the researchers Ecular Xu and Joseph C. Chen.
  • The apps were available in the official Play Store.
  • The privilege escalation worked on the Pixel 2, Nokia 3, LG V20, Oppo F9 and Redmi 6A, among others.
  • According to Trend Micro, the attackers had probably been active since March 2019.

References

Critique

  • The report does not give the identifier of the hole, which makes checking your own patch level harder.

Recommendations

  • Only use Android devices as long as they receive monthly security updates.
  • Install apps sparingly and check permissions and publishers.

Read the original article

Search the Web Archive