Malware was downloaded over 600 million times in 2023 from the Google Play Store

0
[ad_1]
Cybersecurity firm Kaspersky has figured out that thanks to new and sneakier techniques used by bad actors to get malicious apps through Google’s security scans, Android users downloaded malicious apps over 600 million times in 2023. That’s a mind-blowing number and is helped along by the huge number of apps in the Play Store (more than 3 million unique apps says Kaspersky) that makes it impossible for even a company with resources like Google to completely check out each one in depth.

Some malware starts life as a legit app until an update adds some malicious features

The first case study that Kaspersky lists in its blog post is interesting because it shows how these apps are getting installed on Android phones. The iRecorder app was first added to the Play Store in September 2021 and 11 months later, an update added code from Trojan AhMyth which caused the app to record every 15 minutes from the microphone on all phones that had the app installed. The recordings were sent to the server of the app creator.

By the time the iRecorder app was considered to be malware in May 2023, it had been downloaded 50,000 times. But the iRecorder story is illustrative of how these apps slip through Google’s checkpoints; they start life as a regular app that does only what the developer says it does. But after some time goes by, an update is sent out that includes malware, and instantly that benign app you installed on your Android phone has become dangerous.

Another strategy employed by cybercriminals is to open multiple developer accounts with Google. This way, if Google kicks out a malware-laden app, another similar one can be uploaded to the Play Store. As an example, Kaspersky describes three apps: Beauty Slimming Photo Editor, Photo Effect Editor, and GIF Camera Editor Pro. This trio chalked up 620,000 installs while featuring the Fleckpe subscription Trojan.

35 million installs were tallied for clones of Minecraft which contained adware

Once these apps were opened on a phone, the malicious payload was downloaded on the device which would then open a browser window that the phone’s user could not see. The browser would direct itself to sites offering paid subscriptions and after intercepting confirmation codes, the malware would sign up the device owner for paid subscriptions through his/her cellular account which the app had been able to access.

One of the most distributed malware apps that came from the Google Play Store last year were apps of Minecraft clones. Because of the popularity of the real Minecraft app, 35 million downloads were tallied under such names as Block Box Master Diamond. These apps contained adware called HiddenAds that ran ads in the background that the user could not see. While this made money for the bad actors, these apps would negatively impact the battery life of the phones on which they were installed.

Malware called SpinOk was behind the biggest case of the year according to Kaspersky. About 200 infected apps were installed an incredible 451 million times. The apps were supposed to deliver mini-games that would pay out cash rewards to players. But what these apps really did was collect user data and send it to the bad actor’s command-and-control server.

One thing you can do to prevent yourself from installing malware is to check the comments section in the Play Store on each app from an unknown developer that you want to install. Forget the positive comments with high scores because those can be faked. Instead, check the negative comments with low ratings as these will probably be the ones that give you the true story behind the app. 

Look for red flags in these comments from those who have installed the app on their phones. Such complaints include reduced battery life, overheating, and the constant freezing of a device. Also, check the app’s Play Store listing for spelling errors, and grammatical mistakes; if something doesn’t look right, your best bet is to refrain from installing the app.


[ad_2]
Source link

Microsoft Authenticator New Feature Blocks Malicious Notification

0
[ad_1]

In an age where online threats loom large, safeguarding our personal and professional accounts has never been more critical. 

With hackers tirelessly attempting to breach security barriers, the need for robust identity verification methods has become paramount. 

In response to these challenges, Microsoft has introduced a cutting-edge solution: the Microsoft Authenticator app, revolutionizing the way we secure our digital lives.

Multi-Factor Authentication: A Strong Defense

Multi-factor authentication (MFA) stands as a beacon of hope in the battle against cyber threats. 

MFA provides an extra layer of security by necessitating multiple forms of verification, such as passwords coupled with unique codes or biometric data. 

Microsoft Authenticator Blocks Malicious Notification
Approve-in

However, not all MFA methods are created equal, with some susceptible to interception and spoofing by tech-savvy hackers.

Microsoft Authenticator Blocks Malicious Notification
Emphasizing Security by Default with Advanced Microsoft Authenticator Features.
Authenticator

Microsoft Authenticator: Security Redefined

Enter the Microsoft Authenticator app, a game-changer in online security. 

This free app, compatible with smartphones and tablets, supports MFA for a plethora of accounts, including Microsoft, email, social media, and banking services.

Document
Protect Your Storage With SafeGuard

StorageGuard scans, detects, and fixes security misconfigurations and vulnerabilities across hundreds of storage and backup devices.

Its seamless user experience sets it apart: with a single tap, users can access their accounts without the hassle of passwords or codes.

What truly elevates the Microsoft Authenticator app is its integration of artificial intelligence and machine learning. 

The app distinguishes genuine login attempts from suspicious by analyzing factors like location, device information, and user behavior. 

Microsoft Authenticator Blocks Malicious Notification
Emphasizing Security by Default with Advanced Microsoft Authenticator Features.
Authenticator

If a potential threat is detected, the app prompts users to confirm their identity within the app, thwarting phishing attempts and ensuring secure access.

The app maintains a comprehensive history of login requests, allowing users to review their account activities anytime. 

Any irregularities or unauthorized attempts can be promptly reported to Microsoft, contributing to ongoing improvements in security protocols. 

According to Alex Weinert, VP Director of Identity Security at Microsoft, the app’s implementation since September 2023 has significantly reduced irrelevant notifications and prevented over 6 million potentially malicious login attempts initiated by hackers.

Embracing a Password-Free Future

Microsoft Authenticator fortifies online security and liberates users from the constraints of passwords, offering a hassle-free yet highly secure authentication experience. 

By leveraging this intelligent app, individuals can confidently navigate the digital landscape, knowing that their accounts are shielded from threats.

To embrace the future of online security and experience the seamless convenience of Microsoft Authenticator, visit the [Microsoft Authenticator website] and embark on a journey towards a safer digital existence. Stay protected, stay empowered.

Secures your storage & backup systems With StorageGuard – Watch a 40-second Video Tour.


[ad_2]
Source link

Serbian Citizen Pleads Guilty to Running Monopoly Drug Market

0
[ad_1]

After being apprehended by the US government, a Serbian citizen confessed to placing multiple orders on the Monopoly drugs market, which operates on the darknet.

The individual in question has admitted to engaging in the illicit purchase of drugs through this platform.

As per the evidence presented by the government, it has been revealed that Desnica, hailing from Smederevska Palanka, Serbia, conspired in 2019 to create and manage a website that would facilitate the sale of illegal drugs.

This website, which came to be known as Monopoly Market, gradually evolved into a massive online marketplace for peddling illicit narcotics products.

During the year 2021, law enforcement agencies in the United States placed several orders for drugs through the popular board game, Monopoly. These orders were made to various suppliers and totaled more than 100 grams in quantity.

Document
Protect Your Storage With SafeGuard

StorageGuard scans, detects, and fixes security misconfigurations and vulnerabilities across hundreds of storage and backup devices.

According to the FBI’s investigation, Monopoly was involved in facilitating the illegal sale of drugs worth more than $18 million to customers all around the world.

Shockingly, the banned drugs weighing over 30 kilos were also sold to consumers in the US.

After conducting a thorough investigation, it was discovered that a woman named Desnica was operating a monopoly.

Further information revealed that Desnica was extradited from Austria to the United States on June 23, 2023, to face charges relating to her involvement in narcotics trafficking.

The Justice Department’s Office of International Affairs went to great lengths to provide significant assistance and support in the efforts to ensure Desnica’s arrest and extradition from Austria.

Their unwavering commitment to justice and cooperation with international authorities played a crucial role in the successful resolution of this case.

Patch Manager Plus, the one-stop solution for automated updates of over 850 third-party applications: Try Free Trial.


[ad_2]
Source link

Chinese APT Infrastructure Mimics Cloud Backup Services

0
[ad_1]

Cambodian government entities were discovered to be targeted and compromised by Chinese APT actors.

The threat actors are using the infrastructure to masquerade as a cloud backup service. The infrastructure also exhibits several malicious nature and persistent connections.

China has recently invested in a project to modernize Cambodia’s Ream Naval base, which was initially stopped by both countries. This created a controversy among the Western Nations. 

Chinese APT Mimics Cloud Backup

A malicious SSL certificate was found to be used by six facing IP addresses, each of which had several host domains linked with six domains.

On further analyzing the names of the domains, they were found to be masquerading as cloud storage services. 

Since these domains provide a sense of legitimacy to their names, they draw an unusual amount of traffic during high levels of activities like data exfiltration from the victim network.

Source: Palo Alto Unit 42
Source: Palo Alto Unit 42

Nearly 24 Cambodian government organizations were found to be regularly communicating with this infrastructure between September and October 2023.

Document
Protect Your Storage With SafeGuard

StorageGuard scans, detects, and fixes security misconfigurations and vulnerabilities across hundreds of storage and backup devices.

These organizations provide critical services, which include National Defense, Election oversight, Human rights, National treasury and finance, Commerce, Politics, Natural resources, and Telecommunications.

Golden Week in China

Further investigating the infrastructure, the threat actor was found to be doing their activities between 8:30 and 17:30 UTC +08:00 (China Standard Time) on Weekdays (Mon to Fri). There is also a suspicion that the threat actor is trying to blend in with Cambodian business hours.

However, the threat actor’s activity between September 29 and October 8, 2023, confirmed that the threat actor is based out of China.

China’s Golden Week starts on September 29 and ends on October 6, 2023, whereas Oct 7 and 8 are designated as “Special Working Days”. These days were aligned with low amounts of activity through the week of Oct. 2-8 from the threat actor confirmed the suspicion.

Source: Palo Alto Unit 42
Source: Palo Alto Unit 42

A complete report about the threat actors’ activities has been published, providing detailed information about the compromise, Cambodian government entities, and other information.

Indicators of Compromise

Domains

  • api.infinitycloud[.]info
  • connect.infinitycloud[.]info
  • ns.infinitycloud[.]info
  • connect.infinitybackup[.]net
  • ns1.infinitybackup[.]net
  • share.infinitybackup[.]net
  • file.wonderbackup[.]com
  • login.wonderbackup[.]com
  • sync.wonderbackup[.]com
  • update.wonderbackup[.]com
  • ads.teleryanhart[.]com
  • mfi.teleryanhart[.]com
  • dfg.ammopak[.]site
  • fwg.ammopak[.]site
  • jlp.ammopak[.]site
  • kwe.ammopak[.]site
  • lxo.ammopak[.]site
  • connect.clinkvl[.]com

Infrastructure IP Addresses

  • 165.232.186[.]197
  • 167.71.226[.]171
  • 104.248.153[.]204
  • 143.110.189[.]141
  • 172.105.34[.]34
  • 194.195.114[.]199

SSL Certificate SHA-1 Fingerprint

  • B8CFF709950CFA86665363D9553532DB9922265C

Secures your storage & backup systems With StorageGuard – Watch a 40-second Video Tour.


[ad_2]
Source link

IBM Unveils Cloud-Native QRadar SIEM to Maximize Power SOC

0
[ad_1]

IBM has recently announced the launch of its Cloud-Native SIEM solution, which is designed to enhance the scale, speed, and flexibility of security teams.

With this new offering, organizations can benefit from improved threat detection and response capabilities, empowering them to better protect their digital assets and stay ahead of potential cyber-attacks.

IBM Security helps secure the world’s largest enterprises and governments with an integrated portfolio of security products and services infused with dynamic AI and automation capabilities.

With an extensive security research, development, and delivery organization, IBM has established itself as a leading global player in the security domain. Its worldwide presence enables it to monitor over 150 billion security events each day across 130+ countries, keeping a vigilant eye on potential threats.

IBM’s commitment to innovation is reflected in its impressive portfolio of 10,000+ security patents that have been granted worldwide.

The report highlights the challenges of securing the cloud, which has a complex attack surface to defend against. The IT industry faces difficulty in detecting and identifying threats in this environment, making it a challenging task.

Document
Protect Your Storage With SafeGuard

StorageGuard scans, detects, and fixes security misconfigurations and vulnerabilities across hundreds of storage and backup devices.

In reality, a recent global survey found that less than half (49%) of the alerts that SOC specialists are expected to check during a typical workday are reviewed.

Cloud-Native QRadar SIEM

With the aid of the new cloud-native QRadar SIEM, security teams can optimize their resources to the fullest extent, efficiently identifying and responding to security threats in real-time.

It’s meant to design and improve the job of security analysts by using artificial intelligence to do repetitive tasks so that they may focus on finding and responding to critical security issues.

“Our new cloud-native SIEM is a core element of IBM’s mission to usher in the next generation of security operations, built for the hybrid cloud and AI era,” said Kevin Skapinetz, Vice President of Strategy and Product Management, IBM Security. 

Notably, it is designed to reduce the complexity of security technology and simplify the user experience.

Additionally, it is designed by the Red Hat OpenShift and QRadar SIEM, allowing deeper interoperability to Harness security community detections and investigate across data sources, Deep Partner Network.

IBM also plans to release Generative AI  in early 2024 to advance SOC productivity to better security and perform higher work like:

  • Automate Reporting
  • Accelerate Threat Hunting
  • Interpret Machine-Generated Data
  • Curate Threat Intelligence

Secures your storage & backup systems With StorageGuard – Watch a 40-second Video Tour.


[ad_2]
Source link

Code in iOS 17.2 beta reveals that Apple will allow iPhone to sideload apps

0
[ad_1]
Apple has always been against allowing iPhone users to sideload apps on the iPhone. Sideloading is when apps from a third-party app store are downloaded on a phone. Google allows Android users to do this, but Apple has not thus earning it the “walled garden” nickname. Apple claims that apps installed on the iPhone from a third-party app store could contain malware or other security issues and since Apple can’t vet apps not downloaded from the App Store, it believes that it is better to just not allow it.
Another reason why Apple doesn’t want to allow sideloading on the iPhone is to prevent developers from listing their iOS apps on a third-party app store as a way to get around paying Apple as much as 30% of their in-app revenue. Since the App Store is the only official iOS app storefront, there is no way to escape the so-called “Apple Tax” unless a developer stops accepting in-app purchases.
The EU’s Digital Markets Act (DMA) says that mobile device users should be able to install apps from third-party stores. Earlier this year, Bloomberg’s man on the Apple beat Mark Gurman said that Apple would allow sideloading but only in the 27 countries that are members of the EU which would limit any damage caused by malicious apps. It would also provide Apple with some real-life data to see whether it should allow sideloading in other markets.
9to5Mac has discovered that the iOS 17.2 beta contains internal code that would give third-party apps permission to have other apps installed. With this capability, developers would be able to create their own third-party iOS app storefront. The code also has a region lock which would allow Apple to restrict sideloading to specific countries. This makes sense if Apple is forced to allow sideloading by the DMA.

[ad_2]
Source link

Burp Suite 2023.10.3.4 Released: What’s New!

0
[ad_1]
Burp Suite 2023.10.3.4

Burp Suite 2023.10.3.4 is the name of the newest version of Burp Suite, which was just published by the PortSwigger developers.

The Burp Suite is a cybersecurity tool that is used for evaluating the security of online applications. It performs the role of an intercepting proxy and enables users to see and alter the traffic between a web browser and the application that focuses their attention.

Burp Suite helps identify and address security vulnerabilities, such as:-

It also helps identify other common web application flaws, making it an essential tool for ethical hackers and security professionals.

Document
Protect Your Storage With SafeGuard

StorageGuard scans, detects, and fixes security misconfigurations and vulnerabilities across hundreds of storage and backup devices.

What’s New?

The latest version of Burp Suite includes Bambdas, a filter for HTTP requests that can be customized using Java code snippets. Additionally, subdomains may be added to the target scope, TLS passthrough can be enabled for out-of-scope objects, and BChecks can be exported.

Here below, we have mentioned all the new additions:-

  • Advanced HTTP history filtering using Bambdas: Customize Burp Suite with Bambdas with the help of small Java code snippets now available in Proxy > HTTP history. Filter your HTTP history for precise results, eliminating noise. Try Bambdas in Proxy > HTTP history tab for a tailored experience. 
  • Exporting BChecks: Easily share BChecks across Burp instances by exporting selected ones. See their GitHub repository for BChecks from PortSwigger and the Burp Suite community.
  • Increased support for notes throughout Burp: PortSwigger expands notes, allowing you to record key info on tabs for easy access later. Notes copy between tabs and tools for seamless use. Use the sidebar’s Notes panel to add and access notes efficiently.
  • TLS passthrough for out-of-scope items: Optimize performance by applying TLS passthrough for out-of-scope items in the target scope settings. It’s enabled automatically when choosing to Stop logging out-of-scope items.
  • Include subdomains in target scope: Expand target scope by including subdomains of selected hosts. Check ‘Include subdomains’ in Target > Scope settings to activate.
  • Improved Task details dialog:
  • Replaced the Details tab with Summary for easier navigation. 
  • Includes critical vulnerabilities, task progress, and real-time task log. 
  • New Issues tab lists all scan findings. 
  • Renamed Issue activity to Audit log. 
  • Easily view further details in the Event log with a single click.

Checks Grammar Enhancements:

  • A removing query_string action that removes an entire query string from a request.
  • A new variable that returns Burp’s User-Agent header.
  • A new pre-defined variable called insertion_point_base_value contains the base value of the current insertion point.
  • A new per-path BCheck template that you can base your checks on.
  • BChecks can now return more than one issue.
  • Developers have also updated the grammar version to v2-beta.

Other Improvements

After a scan, the Burp Scanner checks the Collaborator server every minute for 10 minutes, then reverts to 10-minute intervals. 

Besides this, the instant out-of-band interactions are now reported faster. Burp’s built-in browser upgraded to version:-

  • 119.0.6045.123 on Mac/Linux
  • 119.0.6045.123/.124 on Windows

You can download the lastest version of Burp Suite Here.

Patch Manager Plus, the one-stop solution for automated updates of over 850 third-party applications: Try Free Trial.


[ad_2]
Source link

Google CEO to testify in trial vs Epic next week

0
[ad_1]

The Google vs Epic trial has been an insightful peek into Google’s business, and now it looks like Google CEO Sundar Pichai is set to testify in the trial starting next week. The trial has been going on for just the past few days and already the public has learned quite a bit. Most recently Epic’s rejection of a nine-figure deal offered by Google. The deal Epic claims was an attempt by Google to stall what it thought would be a mass exodus of other big publishers. Following Epic’s choice to avoid launching Fortnite on Google Play.

Epic also claims that Google has repeatedly destroyed evidence to keep that evidence out of the courtroom. This could be a topic brought up when Pichai takes the stand. In addition to Epic’s claim about destroying evidence, Google has been accused by the US Justice Department of setting internal chats to automatically delete conversations when finished. The claim by the DOJ is part of a separate trial focused on Google’s alleged operation of an illegal monopoly over the search market.

Whereas the trial with Epic is about Google operating an illegal monopoly through Google Play.

Google CEO Sundar Pichai expected to testify on Tuesday

According to a report by The Verge, Pichai is set to take the stand on Tuesday. Google hasn’t confirmed Pichai’s involvement in the trial via testimony. However, it’s noted that Google requested the use of a podium for Tuesday which suggests that Pichai will be testifying. As he had need of one in a previous testimony during the trial with the DOJ.

Pichai is also on Epic’s witness list. So it was already suspected that he may end up taking the stand at some point before Epic’s side of the trial was finished. It’s not entirely clear if Pichai will be called to testify next week. But it seems likely. And it would make sense given his role as CEO. Not to mention how much he would have been involved in decisions that could have led to this trial.

Epic has been lobbying against Google’s Play Store efforts for years now. Claiming the company has used its money and means to prevent healthy competition for another app store on Android. A big part of Epic’s complaint is Google’s 30% cut of in-app purchase fees. Which it has argued are no longer the industry standard.


[ad_2]
Source link

Google and Spotify’s secret deal that gives Spotify a financial edge

0
[ad_1]

In early 2022, multiple companies joined forces to challenge the “app store tax” imposed by Google and Apple. Epic Games, the brains behind Fortnite, is currently battling Google in court. They claim that the Google Play Store is a monopoly. Epic is demanding that Google permit payment processing from sources other than Google and reduce the burden of paying nearly 30% of earnings to the tech giant. Recent disclosures from Google’s attorney, Glenn Pomerantz, show that Google has been playing favorites in regard to its app store fees. Pomerantz disclosed Google has a secret agreement with Spotify, enabling the music streaming giant to pay less than other apps.

This legal battle is the culmination of numerous companies urging Apple and Google to slash the fees they levy on app revenues. Google unveiled a pilot program with Spotify in early 2022, named User Choice Billing, that allowed circumvention of Google Play billing on Android. With this, apps gain the flexibility to handle payments independently. Currently operational in 35 countries, Bumble was the second major app to join the program. However, the exact amount Google still pockets from User Choice Billing remains unknown.

Initially, developers were led to believe that User Choice Billing would lower rates by a flat four percent

During the Epic Games vs. Google trial, Google’s attorney pleaded with the judge to withhold the Spotify figures in an upcoming exhibit, citing potential harm to ongoing negotiations with other parties. Pomerantz emphasized, “Disclosure of the Spotify deal would be very, very detrimental for the negotiation we’d be having with those other parties.”

Epic Games’ attorney countered, asserting, “There is a rate set much much lower than the rates you’ve been hearing about at trial, and that is going to be an important part of what you’re going to be hearing about.” The exact figures, however, have yet to be publicly disclosed.

Epic initiated the lawsuit before the User Choice Billing program kicked off but remains adamant that the program is a “sham.” They contend, “The economic terms of the proposal that we are aware of based on public information — in our view, this is not a real option for developers.”

Reports indicate that Bumble, the second major adopter of User Choice Billing, did not secure any secret agreement with Google. Their Q3 2023 earnings call revealed, “As a percentage of revenue, cost of revenue was 29 percent versus 27 percent in the year-ago period, mostly due to higher App Store fees as a result of compliance with the Google Play mandate.”

As the Epic vs. Google lawsuit unfolds, the jury will determine whether Google’s fees are monopolistic and unjust. However, it should not be shocking that big tech players are making behind-the-scenes deals. Unfortunately, it leaves smaller developers stuck with the high fees set by Google.


[ad_2]
Source link

OnePlus 12 camera could be the same as the OnePlus Open

0
[ad_1]

The OnePlus 12’s release is getting closer every day and a new rumor suggests the camera could be similar to the one on the OnePlus Open. The OnePlus Open has been well-received by critics and consumers alike, and it has given the Samsung Galaxy Z Fold 5 some serious competition.

One of the things that makes the OnePlus Open so impressive is its camera. Notably, a similar sensor is expected to be used in OnePlus 12 camera setup.

OnePlus 12 camera could be similar to OnePlus Open, Oppo Find N3

OnePlus joined hands with Sony for the latter’s camera sensors for its flagship phones, including the OnePlus Open. The debut foldable comes with an LYT-T808 sensor for its primary camera. Similarly, the next flagship— the OnePlus 12 is likely to feature a similar Sony-manufactured lens.

The Chinese phone maker has shared more details about the OnePlus 12 camera setup on Weibo. The sensor is dubbed “LYT-808” and it is expected to power up the next flagship.

OnePlus notes that the LYT-808 and LYT-T808 sensors are essentially the same, but the LYT-T808 is designed specifically for foldable smartphones. Notably, both, the OnePlus Open and Oppo Find N3 sport an LYT-T808 camera sensor. Both sensors are said to have excellent imaging capabilities.

Additionally, OnePlus has also shared other key details of the OnePlus 12’s camera. Aside from the new Sony LYT-808 sensor, it will also feature a 64MP periscope camera with a ½-inch sensor, OIS, f/2.6 aperture, and 3x optical zoom. The rear cameras also come equipped with Hasselblad.

What else to expect from OnePlus 12

The OnePlus 12 will most likely house a Snapdragon 8 Gen 3 chip. It could also include a Pro XDR display with 2K resolution and previous reports suggest that BOE could produce it. The peak brightness could be 2,600 units.

GSMArena recently reported that it could also equip at least 12GB RAM and up to 24GB models. Subsequently, it will run Android 14-based Oxygen OS 14 out of the box. Other rumors point to a 5,400mAh battery with support for 100W wired and 50W wireless charging.

With the leaked specifications and never-ending rumors, the upcoming flagship looks promising. The OnePlus 12 is expected to launch in early January 2024, with China likely to see it first. Other markets would follow shortly after most likely.


[ad_2]
Source link