Live data from Hacker News

The Judy Malware: Possibly the largest malware campaign found on Google Play

blog.checkpoint.com

31–40 of 85 posts

Re: The Judy Malware: Possibly the largest malware campaign found on Google Play

#31
It looks like the common component across the apps mentioned is in the "net.shinhwa21.jsylibrary" namespace.

I made a list of the apps with that namespace, preview here: https://mixrank.com/playstore/apps?expiration=2017-06-30&lis...

This list is a few times bigger than the ones mentioned in the article (been crawling for a long time, and try to be complete). If there's any security folks here that want access to the APKs for research, I'm happy to share (scott at mixrank).

Re: The Judy Malware: Possibly the largest malware campaign found on Google Play

#32
post #26

Earlier quoted context omitted.

If I read the article correct it downloads JavaScript code to load ad pages. It never bypassed the sandbox. I don't think you can call this malware

I work in the security space, and I would definitely consider this malware. Generally, any software used with a malicious purpose is considered malware. As an example, keyloggers generally aren't exploiting any vulnerability (though malware often uses a vulnerability to install the keylogger in the first place), they're using the standard functionality of the computer as intended, but with malicious intent, and so ke…

Yeah, technically I can see it as malware, but not really in the same way... keyloggers obviously harm the user in collecting data against them, there's no malicious intent against the user here. This is only a minor increase over the already quite nasty but common mobile advertising practices.

In fact, I'd argue the information harvesting most mobile ad networks do is much more harmful than this click fraud. Do we ban all of those as malware too? Most them don't mention that they send things like unique device identifiers, connected wifi networks or Google account information.

Re: The Judy Malware: Possibly the largest malware campaign found on Google Play

#33

I'm curious if anyone has a sense for how much they made from this? I just don't have a good sense for scale and dimensions of this. If it went undetected for so long they must not have been at least somewhat conservative in their approach, so say 5mil DAU times 1 click a day at $0.25/click. So, million-ish dollars a day?

Per a Forbes article on the subject [0] "Check Point estimated the firm was making millions from the ad clicks, in the region of $300,000 per month." I imagine your price per click is over-estimated by a couple orders of magnitude, but that's just a guess. [0] https://www.forbes.com/sites/thomasbrewster/2017/05/26/googl...

somewhere between $250K - $400K a month seems to be the thoughts of various open sources on the matter. That would put it in the $3 - $5 million per year at its peak. Assuming their play took a while to ramp up maybe $25 million total?

Google makes more than $25B/year in revenue so even with a 30/70 payout (30 percent to the fraudsters) maybe .001% of Google's ad revenue?

And that is why people do this stuff. Other than getting booted off the store nothing else will happen to these people who just made tens of millions of dollars.

Re: The Judy Malware: Possibly the largest malware campaign found on Google Play

#34

This isn't really malware in the traditional sense, it doesn't damage users of the app itself or harvest information from them, this is simply ad fraud, it only damages Google and its advertisers. It seems to me like CheckPoint is fishing for internet points with this title.

I gotta agree, even tho technically it is malware.

Re: The Judy Malware: Possibly the largest malware campaign found on Google Play

#35

Earlier quoted context omitted.

I work in the security space, and I would definitely consider this malware. Generally, any software used with a malicious purpose is considered malware. As an example, keyloggers generally aren't exploiting any vulnerability (though malware often uses a vulnerability to install the keylogger in the first place), they're using the standard functionality of the computer as intended, but with malicious intent, and so ke…

Yeah, technically I can see it as malware, but not really in the same way... keyloggers obviously harm the user in collecting data against them, there's no malicious intent against the user here. This is only a minor increase over the already quite nasty but common mobile advertising practices. In fact, I'd argue the information harvesting most mobile ad networks do is much more harmful than this click fraud. Do we b…

>there's no malicious intent against the user here

Eating up their battery/resources running hidden code that pretends to be them is kinda malicious. I also count hidden bitcoin miners as malicious.

Re: The Judy Malware: Possibly the largest malware campaign found on Google Play

#36
post #35

Earlier quoted context omitted.

Yeah, technically I can see it as malware, but not really in the same way... keyloggers obviously harm the user in collecting data against them, there's no malicious intent against the user here. This is only a minor increase over the already quite nasty but common mobile advertising practices. In fact, I'd argue the information harvesting most mobile ad networks do is much more harmful than this click fraud. Do we b…

>there's no malicious intent against the user here Eating up their battery/resources running hidden code that pretends to be them is kinda malicious. I also count hidden bitcoin miners as malicious.

For sure, but any extra battery and resource consumption here would be extremely minor compared to a bitcoin miner. Many apps do various forms of push advertising and background reporting which does quite similar things, do you consider that to be malware too? Ultimately the only difference here is that this one abuses Google and their advertisers instead of the user, which seems to be an accepted and common advertising practice. In my opinion at least, it's not significantly different from those behaviors.

Re: The Judy Malware: Possibly the largest malware campaign found on Google Play

#37
post #26

Earlier quoted context omitted.

If I read the article correct it downloads JavaScript code to load ad pages. It never bypassed the sandbox. I don't think you can call this malware

I work in the security space, and I would definitely consider this malware. Generally, any software used with a malicious purpose is considered malware. As an example, keyloggers generally aren't exploiting any vulnerability (though malware often uses a vulnerability to install the keylogger in the first place), they're using the standard functionality of the computer as intended, but with malicious intent, and so ke…

> keyloggers generally aren't exploiting any vulnerability

That's a very odd definition you have.

Rest assured, nobody is saying this kind of apps are acceptable. But calling them malware is not right when they technically don't use more than they been given access to (network + some cpu time)?

Re: The Judy Malware: Possibly the largest malware campaign found on Google Play

#38

Earlier quoted context omitted.

Not really the truth - Android apps are all sandboxed and have relatively little access. In fact the only thing this oh-so-evil malware did was generate fake Google Ad clicks. Not really an offense against its users at all and it can be trivially uninstalled. I certainly wouldn't compare that to ransomware, DDoS botnets, search hijackers, etc that deeply nest themselves in your system and resist uninstallation so muc…

>I certainly wouldn't compare that to ransomware, DDoS botnets, search hijackers, etc that deeply nest themselves in your system and resist uninstallation so much that reinstalling the OS is often the suggested recovery option. Lot's of adware can be equally sticky because it keeps on loading new crap on the system if you just miss it in one place. Tbh the worst disaster system I've seen usually involved adware, sure…

> Lot's of adware can be equally sticky because it keeps on loading new crap on the system if you just miss it in one place. Tbh the worst disaster system I've seen usually involved adware, sure it's not a total data loss but I'd guess it's far more widespread than ransomware.

Important to note that you're talking on Windows here. On Android it can't do anything of the sort.

> And I'd consider any behavior, that's not approved by the user, as an offense against the user. After all, this stuff is taking up resources that otherwise wouldn't be used (traffic, memory, CPU cycles and as such battery)

Nasty advertising practices are already quite common in the mobile world, compare with the apps that do push ads, notifications for in app purchases, full screen ads that are hard to click off, etc.

> This stuff might, for now, be rather easy to uninstall but nobody can guarantee that won't change in the future and infected phones end up in a similar bad state like Windows systems with sticky adware infections.

Short of sandbox breakouts becoming rampant - which would surely get noticed quickly - it can be guaranteed this will never become a concern on Android or any similar platform.

Re: The Judy Malware: Possibly the largest malware campaign found on Google Play

#39

Earlier quoted context omitted.

I work in the security space, and I would definitely consider this malware. Generally, any software used with a malicious purpose is considered malware. As an example, keyloggers generally aren't exploiting any vulnerability (though malware often uses a vulnerability to install the keylogger in the first place), they're using the standard functionality of the computer as intended, but with malicious intent, and so ke…

Yeah, technically I can see it as malware, but not really in the same way... keyloggers obviously harm the user in collecting data against them, there's no malicious intent against the user here. This is only a minor increase over the already quite nasty but common mobile advertising practices. In fact, I'd argue the information harvesting most mobile ad networks do is much more harmful than this click fraud. Do we b…

> no malicious intent against the user

Lots of malware doesn't have malicious intent against the user. Like botnets for DDoS attacks. Those things generally don't have any noticeable impact on the user, aside from increased network usage, but do immense damage to their targets.

I agree it's different than typical malware. As for considering ad tracking malware, the term "malicious" is obviously open to interpretation, so yes, you could make the argument that that is malware. You'd just have to convince others this meets the criteria for maliciousness. I've certainly heard people say that DRM software is malware.

Re: The Judy Malware: Possibly the largest malware campaign found on Google Play

#40
post #26
post #17

Earlier quoted context omitted.

Well malware has many categories and one is adware.

If I read the article correct it downloads JavaScript code to load ad pages. It never bypassed the sandbox. I don't think you can call this malware

So if I'm on a metered data connection, getting hit with would result in...?
Post reply on HN