Jump to content

Fifty apps in Google Play Store, downloaded 4.2 million times, secretly charging users

Basically some apps passed Google's detection for malware, and these apps which were downloaded millions of times, and these apps used there permissions to access SMS to charge the user. If Play Protect is disabled by user on infected phones or an older version of android that doesn't support the feature, users will need to uninstall manually. If Play Protect is active, then Google will automatically remove any apps detected to have malware

 

Quote

"The apps then used the phone numbers to sign up unwitting users to premium services and to send fraudulent premium text messages, a move that caused users to be billed. Check Point researchers didn't know how much revenue was generated by the apps."

 -Ars Technica article

 

https://arstechnica.com/information-technology/2017/09/malicious-apps-with-1-million-downloads-slip-past-google-defenses-twice/

 

https://community.spiceworks.com/topic/2050412-snap-equifax-woes-continue-google-announces-pixel-event

Link to comment
Share on other sites

Link to post
Share on other sites

Google should have stricter guidelines on how apps are submitted to the Play Store and/or improve their malware detection -_-

CPU: Intel Core i7-5820K | Motherboard: AsRock X99 Extreme4 | Graphics Card: Gigabyte GTX 1080 G1 Gaming | RAM: 16GB G.Skill Ripjaws4 2133MHz | Storage: 1 x Samsung 860 EVO 1TB | 1 x WD Green 2TB | 1 x WD Blue 500GB | PSU: Corsair RM750x | Case: Phanteks Enthoo Pro (White) | Cooling: Arctic Freezer i32

 

Mice: Logitech G Pro X Superlight (main), Logitech G Pro Wireless, Razer Viper Ultimate, Zowie S1 Divina Blue, Zowie FK1-B Divina Blue, Logitech G Pro (3366 sensor), Glorious Model O, Razer Viper Mini, Logitech G305, Logitech G502, Logitech G402

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, jagdtigger said:

Or just take away all permissions from apps and let the user decide what an app can access. LineageOS FTW...

Android 7.1 and 8.0 also does this 

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, jagdtigger said:

Or just take away all permissions from apps and let the user decide what an app can access. LineageOS FTW...

LineageOS is definitely my preferred OS for permission controls when it comes to Android. My HTC One is on AICP which is based on LineageOS. I'm glad stock andoid has been getting granular permissions control too. Its one of the advantages iOS had over android for awhile that is now more even

Link to comment
Share on other sites

Link to post
Share on other sites

4 minutes ago, nerdslayer1 said:

Android 7.1 and 8.0 also does this 

Yeah but only a few phone will get it, most of the phones stuck with the version they got at release so for many people only option is to use a "cooked ROM"... 9_9 And CM had this function way before it was implemented into the stock android.

Link to comment
Share on other sites

Link to post
Share on other sites

I believe any apps that go on the Google play store or the Apple store should have their source code checked. Uploaded to a secure site and then the app can be on the Stores.

CPU: AMD Ryzen 5 5600X | CPU Cooler: Stock AMD Cooler | Motherboard: Asus ROG STRIX B550-F GAMING (WI-FI) | RAM: Corsair Vengeance LPX 16 GB (2 x 8 GB) DDR4-3000 CL16 | GPU: Nvidia GTX 1060 6GB Zotac Mini | Case: K280 Case | PSU: Cooler Master B600 Power supply | SSD: 1TB  | HDDs: 1x 250GB & 1x 1TB WD Blue | Monitors: 24" Acer S240HLBID + 24" Samsung  | OS: Win 10 Pro

 

Audio: Behringer Q802USB Xenyx 8 Input Mixer |  U-PHORIA UMC204HD | Behringer XM8500 Dynamic Cardioid Vocal Microphone | Sound Blaster Audigy Fx PCI-E card.

 

Home Lab:  Lenovo ThinkCenter M82 ESXi 6.7 | Lenovo M93 Tiny Exchange 2019 | TP-LINK TL-SG1024D 24-Port Gigabit | Cisco ASA 5506 firewall  | Cisco Catalyst 3750 Gigabit Switch | Cisco 2960C-LL | HP MicroServer G8 NAS | Custom built SCCM Server.

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

35 minutes ago, nerdslayer1 said:

Android 7.1 and 8.0 also does this 

6.0 too, that was released almost 2 years ago

I believe any apps that go on the Google play store or the Apple store should have their source code checked. Uploaded to a secure site and then the app can be on the Stores.

That's exactly what happens now. But of course those algorithms aren't perfect.

Link to comment
Share on other sites

Link to post
Share on other sites

19 minutes ago, Abdul201588 said:

I believe any apps that go on the Google play store or the Apple store should have their source code checked. Uploaded to a secure site and then the app can be on the Stores.

That woulds severely degrade the ecosystem because 1. you have to pay someone to code review it 2. it may take a long time for an app to go through the process and 3. they may still slip up and let something pass.

 

You can either have it open, cheap, and fluid, or closed, expensive, and rigid as all hell.

Link to comment
Share on other sites

Link to post
Share on other sites

Of course it's stupid cameras, wallpapers and filters apps. 

 

Who would have thought it would have been anything different. 

Our Grace. The Feathered One. He shows us the way. His bob is majestic and shows us the path. Follow unto his guidance and His example. He knows the one true path. Our Saviour. Our Grace. Our Father Birb has taught us with His humble heart and gentle wing the way of the bob. Let us show Him our reverence and follow in His example. The True Path of the Feathered One. ~ Dimboble-dubabob III

Link to comment
Share on other sites

Link to post
Share on other sites

5 minutes ago, M.Yurizaki said:

That woulds severely degrade the ecosystem because 1. you have to pay someone to code review it 2. it may take a long time for an app to go through the process and 3. they may still slip up and let something pass.

 

You can either have it open, cheap, and fluid, or closed, expensive, and rigid as all hell.

So Android vs iOS. 

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, Meechgalhuquot said:

So Android vs iOS. 

I doubt Apple code reviews things though. They probably review it on a higher level so that you can't make an app that costs $999 just to say "lol i can wipe my ass with $100 bills" whereas I'd imagine on Android someone has to report the app first before someone takes action.

 

But I don't know. I don't publish for either ecosystem.

Link to comment
Share on other sites

Link to post
Share on other sites

Apple doesn't review code all that much either, plenty of malicious apps made it into their app store.

 

Stuff like this is why I only use F-Droid anymore.  

Link to comment
Share on other sites

Link to post
Share on other sites

Does this meant he apps had permission to access sms yet that wasn't made clear during install? 

 

I have never understood why any game or most apps need permission to access accounts, sms, phone history etc.  Let alone why people install them.

 

 

Grammar and spelling is not indicative of intelligence/knowledge.  Not having the same opinion does not always mean lack of understanding.  

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, jagdtigger said:

Yeah but only a few phone will get it, most of the phones stuck with the version they got at release so for many people only option is to use a "cooked ROM"... 9_9 And CM had this function way before it was implemented into the stock android.

My tablet has Android 7.1.2, and its from late 2011/early 2012.

"We also blind small animals with cosmetics.
We do not sell cosmetics. We just blind animals."

 

"Please don't mistake us for Equifax. Those fuckers are evil"

 

This PSA brought to you by Equifacks.
PMSL

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, M.Yurizaki said:

I doubt Apple code reviews things though. They probably review it on a higher level so that you can't make an app that costs $999 just to say "lol i can wipe my ass with $100 bills" whereas I'd imagine on Android someone has to report the app first before someone takes action.

 

But I don't know. I don't publish for either ecosystem.

http://gizmodo.com/5034122/guy-buys-999-im-rich-app-discovers-hes-just-dumb

http://latimesblogs.latimes.com/technology/2008/08/iphone-i-am-ric.html

https://web.archive.org/web/20110525112738/http://asia.cnet.com/crave/wealth-flaunting-app-arrives-on-android-phones-62106338.htm

http://www.webcitation.org/5vBAXX1x7?url=http://www.mobilecrunch.com/2010/12/22/i-am-rich-windows-phone/

 

Although the iOS release was 9 years ago, things should be better now. 

Our Grace. The Feathered One. He shows us the way. His bob is majestic and shows us the path. Follow unto his guidance and His example. He knows the one true path. Our Saviour. Our Grace. Our Father Birb has taught us with His humble heart and gentle wing the way of the bob. Let us show Him our reverence and follow in His example. The True Path of the Feathered One. ~ Dimboble-dubabob III

Link to comment
Share on other sites

Link to post
Share on other sites

11 hours ago, Dabombinable said:

My tablet has Android 7.1.2, and its from late 2011/early 2012.

Then you have one of the exceptions... :D The last official ROM that my phone(Galaxy S5) got was 6.0.

Link to comment
Share on other sites

Link to post
Share on other sites

8 minutes ago, jagdtigger said:

Then you have one of the exceptions... :D The last official ROM that my phone(Galaxy S5) got was 6.0.

Oh its not official, Android stopped at 4.1.2 for it-meaning that without a custom ROM I couldn't even use MS Word on it (though it runs perfectly under 7.1.2 with zram enabled)

"We also blind small animals with cosmetics.
We do not sell cosmetics. We just blind animals."

 

"Please don't mistake us for Equifax. Those fuckers are evil"

 

This PSA brought to you by Equifacks.
PMSL

Link to comment
Share on other sites

Link to post
Share on other sites

13 hours ago, nerdslayer1 said:

Android 7.1 and 8.0 also does this 

6 too, or at least it gives you the option to block permissions.

Don't ask to ask, just ask... please 🤨

sudo chmod -R 000 /*

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×