Live data from Hacker News

CamScanner, a malicious Android app with more than 100M downloads in Google Play

kaspersky.com

31–40 of 155 posts

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#31

Is this just a non issue on iOS? If so, why?

I had camscanner and at some time it started trying to upload my pdfs to the cloud. It seems it was bought by tencent around that time.

At first the app store privacy policy was a broken link. Later they got it to work, and it basically used broken english to say: we can collect anything.

uninstall and never looked back.

One tip:

The iOS native Notes app can scan documents into a .pdf file.

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#32
post #7

Just to clarify the headline: the app didn't have malware when most of the users installed it. A recent update added the malware.

in regard to iOS:

When tencent bought the iOS version, the "user contract" was grossly changed.

Just uninstall it and use the native iOS Notes app to scan your .pdf documents.

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#33

Is this just a non issue on iOS? If so, why?

It's not a non-issue: https://www.theiphonewiki.com/wiki/Malware_for_iOS The store rules and moderation is a bit stricter, do that may be one reason we hear less about iOS malware. But it's still out there.

Correct me if I'm wrong, but the iOS sandbox also seems weaker - I've seen a few occasions in which calling undocumented functions can be all it takes to bypass protections significantly. I assume this is part of the reason Apple is so reliant on reviews.

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#34
> So a dropper might be used to install malware that steals banking credentials or generates fake advertising clicks or signs up for fake subscriptions.

This is basically wrong, you can't modify a browser or charge someone's card without breaking out of the sandbox.

Worst case they could burn your cellular data or encrypt your photos and such if you gave it permission.

Is there any evidence they maliciously used this or was it probably just in there so they could drop more creepy ad code?

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#35
I've been using this app for years and also telling other people to use it, so this sucks.

If anyone else is looking for a replacement there's a Microsoft app called "Office Lens" that seems to do a really nice job and is as safe a bet as anything.

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#36
post #35

I've been using this app for years and also telling other people to use it, so this sucks. If anyone else is looking for a replacement there's a Microsoft app called "Office Lens" that seems to do a really nice job and is as safe a bet as anything.

I use Adobe Scan.

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#38
post #35

I've been using this app for years and also telling other people to use it, so this sucks. If anyone else is looking for a replacement there's a Microsoft app called "Office Lens" that seems to do a really nice job and is as safe a bet as anything.

Google Drive has a scanner too.

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#39

Rather than disappear it from the Store entirely, it would be nice if Google could leave a placeholder with a warning; at least it would serve an educational purpose. Also, does the Play Store app have a way to notify users of a banned app that is still installed? I decided to check my wife's phone proactively, but I don't think she would otherwise have had a clue of malware (but has been getting weird and annoying p…

> Rather than disappear it from the Store entirely, it would be nice if Google could leave a placeholder with a warning; at least it would serve an educational purpose. This would also make the Play Store look bad.

Which would also be fitting, wouldn't it? Google missed it and dropped the ball.

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#40

Does anyone have information on affected and unaffected version numbers? I have a version of this installed, but it's an old one, and may not have updated to the malware one because I disabled automatic updates. (Specifically because I was afraid of this, in fact.)

May 22, 2019: 5.10.6.20190522 – safe June 6, 2019: 5.11.0.20190611 – safe June 14, 2019: 5.11.3.20190614 – safe June 16, 2019: 5.11.3.20190616 – unsafe June 24, 2019: 5.11.5.20190624 – unsafe July 10, 2019: 5.11.7.20190710 – unsafe July 23, 2019: 5.12.0.20190723 – unsafe July 25, 2019: 5.12.0.20190725 – unsafe July 30, 2019: 5.12.0.20190730 – safe August 8, 2019: 5.12.3.20190809 – safe August 14, 2019: 5.12.3.2019081…

Any speculation why they would only leave in the malicious code for about a month? Changed their mind? Done without full knowledge? Achieved some high value heist and rolled it back?
Post reply on HN