Live data from Hacker News

CamScanner, a malicious Android app with more than 100M downloads in Google Play

kaspersky.com

81–90 of 155 posts

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#81
post #35

I've been using this app for years and also telling other people to use it, so this sucks. If anyone else is looking for a replacement there's a Microsoft app called "Office Lens" that seems to do a really nice job and is as safe a bet as anything.

It's amazing to me that so few people are not aware of the excellent scanning apps from Google. They work better, you're not expanding your privacy risk ... and they're free and integrated with Google docs etc. * namely, Drive Scan and Photoscan

I’ll vouch for PhotoScan. Great for digitising Instax shots!

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#82
post #72

> CamScanner was actually a legitimate app, with no malicious intensions whatsoever, for quite some time. It used ads for monetization and even allowed in-app purchases. However, at some point, that changed, and recent versions of the app shipped with an advertising library containing a malicious module. IMO, this is more a legal matter than a technical one. Google needs to sue this company, not engage in a whack-a-m…

That's a little presumptuous - isn't it likely that CamScanner was somehow compromised? This could happen in the source code or in the build and release pipeline.

...or they just included some [pupular ad library] that has gone bad, and noone checked.

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#83
post #71

Earlier quoted context omitted.

Blogspam happens when someone writes a blog article that sources or references something from a more authoritative source, such as this one linking to the Kaspersky story, without adding anything of significance to the original.

Which I don't think is exactly the case here - the Forbes site is not a blog, it's a news site. This article is their reporting of something newsworthy (even if not the best quality article).

Actually Forbes IS a blog these days. Look at the URL - anything under /sites/ is a blog post by some random guy.

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#84

PlayProtect is not detecting and warning users about CamScanner even when it has been removed from the Playstore. I've tested it via manual scan on PlayProtect as well, no dice. Isn't that what it is supposed to do? Has anyone ever got any app flagged by PlayProtect? If it's useless, then rather I would disable it than to give it access to all my installed apps. Google Engineers here, please ping your Google Play tea…

I certainly flags PhoneGap Build apps without a signing certificate. So at least you know that the malicious parties have paid some money to get a cert!

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#85

PlayProtect is not detecting and warning users about CamScanner even when it has been removed from the Playstore. I've tested it via manual scan on PlayProtect as well, no dice. Isn't that what it is supposed to do? Has anyone ever got any app flagged by PlayProtect? If it's useless, then rather I would disable it than to give it access to all my installed apps. Google Engineers here, please ping your Google Play tea…

> Has anyone ever got any app flagged by PlayProtect? I know it famously flags the Apptoide app store (a Google Play rival) as malware[1] [1]: https://techcrunch.com/2019/06/04/aptoide-a-play-store-rival...

I just took a look at Apptoide, why does everything have some sort of coin associated with it. Does anybody else just close the tab as soon as they see any mention of Bitcoin etc?

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#86
post #71

Earlier quoted context omitted.

Which I don't think is exactly the case here - the Forbes site is not a blog, it's a news site. This article is their reporting of something newsworthy (even if not the best quality article).

There's no fundamental difference between a news site and a blog. A lot of them even use the same software. News sites just tend to have lower quality entries than blogs and often engage in blogspam instead of providing links to superior sources or adding something of value. Obviously. Since they want to keep people on their site. I wonder what the average time spent on a "news article" vs. a "blog post" is.

> There's no fundamental difference between a news site and a blog.

There is a difference. A blog is short for web log which implies a personal journal. Anyone can publish a blog without editorial oversight. A news site implies that professional journalists are producing reports with editorial and literary standards. Clearly many media companies blur this line though to the detriment of readers and journalists.

> A lot of them even use the same software.

What difference does that make? The vast majority of web sites use the same web server software (Apache/Nginx)...and the same software elsewhere in the stack.

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#87
post #13

Blogspam of https://www.kaspersky.com/blog/camscanner-malicious-android-... (Forbes contributor posts are almost always blogspam)

As if Kaspersky itself isn’t spamming.

To make sure you never find yourself in such trouble, use a reliable antivirus for Android app and scan your smartphone from time to time. (The paid version of Kaspersky Internet Security for Android scans automatically.)

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#88

Earlier quoted context omitted.

There's no fundamental difference between a news site and a blog. A lot of them even use the same software. News sites just tend to have lower quality entries than blogs and often engage in blogspam instead of providing links to superior sources or adding something of value. Obviously. Since they want to keep people on their site. I wonder what the average time spent on a "news article" vs. a "blog post" is.

> There's no fundamental difference between a news site and a blog. There is a difference. A blog is short for web log which implies a personal journal. Anyone can publish a blog without editorial oversight. A news site implies that professional journalists are producing reports with editorial and literary standards. Clearly many media companies blur this line though to the detriment of readers and journalists. > A l…

"Professional journalist" just means you're a blogger that gets paid. And everybody has standards. Some people just like to wave theirs around a little more.

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#89
post #2

For the past few days I've been seen spam events in my calendar about "free iPhones" and "webcam girls" - I couldn't figure out where they were coming from. I have CamScanner installed, so presumably that's the source... Now, I can remove CamScanner (which is a shame, it's a really good app), but how can I ensure the trojan is also removed? I tried the Avast AntiVirus app, but it didn't find anything. What does every…

> how can I ensure the trojan is also removed? The trojan is inside the app. Remove the app, and you remove the trojan.

Is this a solid guarantee? Usually on Windows a Trojan replicates itself outside of the main application it was installed through.

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#90

So what exactly did this malware do most of the time? In the original kaspersky report it says "For example, an app with this malicious code may show intrusive ads and sign users up for paid subscriptions.". So how/did it sign up users for paid subscriptions without user interaction? Does android allow something like that? Aren't all apps sandboxed? In general how is the android sandboxing and permission system nowad…

This. As an iOS user / developer who isn't too familiar with Android, I also don't get it. Either these reports are lacking, and there is in fact a vulnerability being exploited down the line, or Android is completely broken. I find it odd that this important detail is being ignored in the reports/discussion.
Post reply on HN