Spyware backdoor prompts Google to pull 500 apps with >100m downloads

  • 23 August 2017
  • 0 replies
  • 1 view

Userlevel 7
Badge +54

Google killed secret plugin download capability after being alerted by researchers.

 


 
Dan Goodin - 8/22/2017
 
At least 500 apps collectively downloaded more than 100 million times from Google's official Play Market contained a secret backdoor that allowed developers to install a range of spyware at any time, researchers said Monday.
 
The apps contained a software development kit called Igexin, which makes it easier for apps to connect to ad networks and deliver ads that are targeted to the specific interests of end users. Once an app using a malicious version of Igexin was installed on a phone, the developer kit could update the app to include spyware at any time, with no warning. The most serious spyware installed on phones were packages that stole call histories, including the time a call was made, the number that placed the call, and whether the call went through. Other stolen data included GPS locations, lists of nearby Wi-Fi networks, and lists of installed apps.
 
Full Article.

0 replies

Be the first to reply!

Reply