Security researchers have discovered a new Android banking trojan they named Brokewell that can capture every event on the device, from touches and information displayed to text input and the applications the user launches.
@[email protected]
link
fedilink
English
5
edit-2
10M

Why are articles about mobile malware or hack tools always written vaguely enough to suggest they’re 0-click? What valuse does an article have if it doesn’t list the steps to get infected or uninfected?

lemmyng
link
fedilink
English
710M

Not sure what you are talking about. Paragraph 1 has

The malware is delivered through a fake Google Chrome update that is shown while using the web browser.

and the article makes it pretty clear after that that the user is tricked into installing the fake apk.

@[email protected]
link
fedilink
English
610M

That’s an incredibly vague statement that’d lead most people to think they’re fucked if they so much as open a site that says to update chrome.

Unless it’s using some unmentioned exploit, the user in question needs to:

  1. Download the ‘update’ from their browser instead of play store
  2. Ignore the dangerous download warning chromium browsers show
  3. Run the download
  4. Enable installing apk from their browser / file manager
  5. Ignore that the prompt says ‘install’ and not ‘update’
  6. Ignore the play protect unknown app warning (or dangerous app warning if it recognizes the malware)
  7. Find and enable the accessibility service for the malware
  8. Ignore the accessibility warning
  9. Enable all the other permissions or disable settings app accessibility protection

Unless the app is circumventing the above steps, much more than just a “fake Google Chrome update that is shown while using the web browser.” is needed to get infected. Not specifying if this is just an ordinary app with malicious intentions or if it actually uses exploits to achieve what normally can’t be is misleading.

Create a post

DROID DOES

Welcome to the droidymcdroidface-iest, Lemmyest (Lemmiest), test, bestest, phoniest, pluckiest, snarkiest, and spiciest Android community on Lemmy (Do not respond)! Here you can participate in amazing discussions and events relating to all things Android.

The rules for posting and commenting, besides the rules defined here for lemmy.world, are as follows:

Rules


1. All posts must be relevant to Android devices/operating system.


2. Posts cannot be illegal or NSFW material.


3. No spam, self promotion, or upvote farming. Sources engaging in these behavior will be added to the Blacklist.


4. Non-whitelisted bots will be banned.


5. Engage respectfully: Harassment, flamebaiting, bad faith engagement, or agenda posting will result in your posts being removed. Excessive violations will result in temporary or permanent ban, depending on severity.


6. Memes are not allowed to be posts, but are allowed in the comments.


7. Posts from clickbait sources are heavily discouraged. Please de-clickbait titles if it needs to be submitted.


8. Submission statements of any length composed of your own thoughts inside the post text field are mandatory for any microblog posts, and are optional but recommended for article/image/video posts.


Community Resources:


We are Android girls*,

In our Lemmy.world.

The back is plastic,

It’s fantastic.

*Well, not just girls: people of all gender identities are welcomed here.


Our Partner Communities:

[email protected]


  • 1 user online
  • 74 users / day
  • 177 users / week
  • 351 users / month
  • 1.75K users / 6 months
  • 1 subscriber
  • 1.82K Posts
  • 33.9K Comments
  • Modlog