Live data from Hacker News

CamScanner, a malicious Android app with more than 100M downloads in Google Play

kaspersky.com

101–110 of 155 posts

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#101
post #32

Earlier quoted context omitted.

in regard to iOS: When tencent bought the iOS version, the "user contract" was grossly changed. Just uninstall it and use the native iOS Notes app to scan your .pdf documents.

Wow, I never knew you can use the Notes app to scan documents.

If you add the Notes shortcut to your Control Center, you can hard-press on it and tap Scan Document to very quickly be able to scan a document. It does a really good job too!

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#102
post #2

For the past few days I've been seen spam events in my calendar about "free iPhones" and "webcam girls" - I couldn't figure out where they were coming from. I have CamScanner installed, so presumably that's the source... Now, I can remove CamScanner (which is a shame, it's a really good app), but how can I ensure the trojan is also removed? I tried the Avast AntiVirus app, but it didn't find anything. What does every…

Most antivirus software on Android is more like malware itself. You’re better off only using applications from F-Droid, very carefully vetting everything yourself, or not using Android. The Android security model is getting better, but it’s still really broken compared to anything on iOS.

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#103
post #35

I've been using this app for years and also telling other people to use it, so this sucks. If anyone else is looking for a replacement there's a Microsoft app called "Office Lens" that seems to do a really nice job and is as safe a bet as anything.

Open Note Scanner in F-Droid has been serving my (admittedly limited) needs instead.

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#104

Earlier quoted context omitted.

> how can I ensure the trojan is also removed? The trojan is inside the app. Remove the app, and you remove the trojan.

Is this a solid guarantee? Usually on Windows a Trojan replicates itself outside of the main application it was installed through.

I think it would have to exploit a vulnerability in Android’s sandboxing mechanism (not hard considering how many people can’t or don’t update) to be able to become separate from its parent application. Win32 doesn’t do any kind of app sandboxing at all.

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#105
post #98

Guess what - this was caused by a third-party ad network: https://twitter.com/CamScanner/status/1166733219841986561/ph...

That is and for many, always an issue. Adverts help pay for content, be that a game or website - people literally make a living that way that it has become a bit of a defacto approach. But when you are tied to including some code that goes off to a site that you have no or very little control over, you are outsourcing part of your company (web or app) into the hands of another in which, if they mess up. You are the t…

Here it sounds like the malicious code was in the advertising SDK itself, so ad blocking at the network level wouldn't necessarily have helped.

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#106

Maybe Google should pay more attention to their own ecosystem and less focus on embarrassing other vendors.

I too wish they should stop using their resources to find security problems Apple should have found themselves. But I very much disagree this is about embarrassing Apple. In fact, Google is doing them a huge favor. (The iMessage bug for example could have been turned into a worm and infected ALL iPhones on the planet in matter of minutes if it was found by blackhat hackers instead. Apple should be thankful)

Project Zero is doing Apple a huge favor. Google isn’t a single organism; Project Zero isn’t taking away resources from the Android division. And it’s not like Project Zero doesn’t look for Android vulnerabilities, it’s just that iOS is a much more interesting target from a security standpoint because it’s widely considered to be actually secure (not to mention that people actually run the latest version of it).

I think Fuchsia can’t come fast enough for an opportunity to break backwards compatibility and catch up with the rest of the world on security.

(I also think that Google needs to put some more humans in the Play Store review process, but as we all know Google despises using humans when they can automate a process.)

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#107

Earlier quoted context omitted.

> Has anyone ever got any app flagged by PlayProtect? I know it famously flags the Apptoide app store (a Google Play rival) as malware[1] [1]: https://techcrunch.com/2019/06/04/aptoide-a-play-store-rival...

I just took a look at Apptoide, why does everything have some sort of coin associated with it. Does anybody else just close the tab as soon as they see any mention of Bitcoin etc?

> Does anybody else just close the tab as soon as they see any mention of Bitcoin etc?

Yup. I also usually take the time to ridicule the offenders for being very silly.

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#108

Earlier quoted context omitted.

I don't know this particular case, but "malware" seems to be used to describe "adware" these days by some blogs to generate more clicks. Android is just as secure/unsecure as iOS. Some recent "malware" campaigns targeted both platforms but in general Apple silently removes them while Android gets scrutinized to death. Edit: to answer your questions, these apps still operate within the limits of the sandbox. Which is…

This is clearly not the case. Not only is Android’s permission system more permissive, most Android phones don’t get updates as frequently and definitely not as far long as iOS.

> most Android phones don’t get updates as frequently and definitely not as far long as iOS.

This is irrelevant. Most phones period don't get updates frequently. Does that mean you shouldn't buy any phone? No, you should buy a phone that does get updated, and there are plenty of Android options.

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#109

PlayProtect is not detecting and warning users about CamScanner even when it has been removed from the Playstore. I've tested it via manual scan on PlayProtect as well, no dice. Isn't that what it is supposed to do? Has anyone ever got any app flagged by PlayProtect? If it's useless, then rather I would disable it than to give it access to all my installed apps. Google Engineers here, please ping your Google Play tea…

According to https://www.androidpolice.com/2019/08/28/camscanner-play-sto..., if you have an update within the last month, you have a safe version of the app, so it should not be flagged.
Post reply on HN