Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Real-Time Behavior-Based Detection on Android Reveals Dozens of Malicious Apps on Google Play Store
bit defemder ^

Posted on 08/18/2022 12:04:56 PM PDT by BenLurkin

Most of the time, users can choose to delete the...these new malicious apps trick victims into installing them, only to change their name and icons and even take some extra steps to conceal their presence on the device. Users can still delete them at will, the developers make it more difficult to find them on the affected devices.

The 'GPS Locations Maps' app makes it difficult for users to find and uninstall it by changing its icon. Also, on some devices, a few malicious apps even request permission to bypass the battery optimization feature and start foreground services notifications to stay alive and not get killed by the system.

Many of the detected apps also request permission to display over other apps, which means that they are likely also simulating user clicks to rake on profits.

One way to stay hidden from a user bent on uninstalling the app is to change the icon into something innocuous, like the 'Settings' app. It does that by declaring an alias launcher. After installing another icon and label, it changes the main launcher, replacing it with the alias one with the label and icon for 'Settings.'

The alias launcher corresponds to another activity, hidden inside the `com.android.setting` package, probably to look more legit. When launched, this activity renders itself with '0' size in a corner, then launches the setting page for the phone, tricking the user into thinking that the real settings button was pressed.

Another interesting technique developers use to obscure apps is to ensure they don't show in the list of the most recently used apps on Android. These apps also have the flag android:excludeFromRecents="true" set in their manifest, meaning that when a user looks at recent apps opened on the device, the adware app is not present among them.

(Excerpt) Read more at bitdefender.com ...


TOPICS: Computers/Internet
KEYWORDS: android; googleplay; malware

1 posted on 08/18/2022 12:04:56 PM PDT by BenLurkin
[ Post Reply | Private Reply | View Replies]

To: BenLurkin

I love, love, love Bitdefender!


2 posted on 08/18/2022 12:13:08 PM PDT by Howie66 (Let's Go Brandon!!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: BenLurkin

I despise Apple, but had to get away from Android devices exactly because of Google. They are the demonic enemy.


3 posted on 08/18/2022 12:35:04 PM PDT by fwdude (Racism is not dead, but it is on life support - kept alive by politicians….” — Thomas Sowell)
[ Post Reply | Private Reply | To 1 | View Replies]

To: fwdude

Despite the iOS ecosystem being a “walled garden” at times, at least I can use for my for several years with yearly iOS updates. If I still had my old iPhone X, I could have easily updated to iOS 16.0 when that arrives next month.


4 posted on 08/18/2022 12:46:56 PM PDT by RayChuang88 (FairTax: America's Economic Cure)
[ Post Reply | Private Reply | To 3 | View Replies]

To: BenLurkin

Every time I use my android phone, Biden gets 1 more vote.


5 posted on 08/18/2022 1:11:51 PM PDT by entropy12 (Trump & MAGA are the only road to keep USA viable.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: BenLurkin

Malicious apps?

No, malicious OS. Turn off EVERY option on anything anywhere near Gurgle.


6 posted on 08/18/2022 3:06:23 PM PDT by nicollo (arbitrary law is not rule of law)
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson