Live data from Hacker News

New 'unremovable' xHelper malware has infected 45,000 Android devices

zdnet.com

1–10 of 110 posts

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#3
post #2

I know IOS isn't perfect, however, when I read articles like this, I just have to smile. There's something to be said for a tightly controlled platform and ecosystem.

What do you think iOS reviewers were thinking when carefully auditing these apps -

https://mashable.com/2017/06/12/apple-app-store-subcription-...

https://9to5mac.com/2019/10/25/malware-iphone-apps/

https://www.techtimes.com/articles/235985/20181204/apple-rem...

https://www.wired.com/2015/09/apple-removes-300-infected-app...

They get so much wrong, so often, you have to wonder if they really look at the apps at all or just have some checklist, screenshots and a quota to hit. They explicitly approved all the garbage practices that Apple Arcade's billing protects users from.

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#4
post #2

I know IOS isn't perfect, however, when I read articles like this, I just have to smile. There's something to be said for a tightly controlled platform and ecosystem.

To be fair, if you stick to just using the Google Play Store, _this_ malware wouldn't hit you.

> According to Malwarebytes, the source of these infections is "web redirects" that send users to web pages hosting Android apps. These sites instruct users on how to side-load unofficial Android apps from outside the Play Store. Code hidden in these apps downloads the xHelper trojan.

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#5
post #2

I know IOS isn't perfect, however, when I read articles like this, I just have to smile. There's something to be said for a tightly controlled platform and ecosystem.

It seems like they could get a better outcome by having levels of trust for unsanctioned apps. Like the default for side-loaded apps would be just as an app only. No background processing, notifications, loading services. To get the latter functionality you could make the user jump through a bunch of hoops with nasty warning messages or even just not allow it.

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#6
Wonder if it's written itself into recovery. Or the SIM card/baseband - SIM card in particular usually includes functionality for triggering a sideload of apps (eg for carrier apps), sending notifications, etc into the main SOC so it fits. Maybe the second instance of SIM card malware ever.

https://www.youtube.com/watch?v=31D94QOo2gY

There are only so many places it can be hiding if it's surviving a factory reset.

--Guy who is undoubtedly vastly underestimating the problem given that it's resisted AV vendors for a while

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#7
post #2

I know IOS isn't perfect, however, when I read articles like this, I just have to smile. There's something to be said for a tightly controlled platform and ecosystem.

To be fair, if you stick to just using the Google Play Store, _this_ malware wouldn't hit you. > According to Malwarebytes, the source of these infections is "web redirects" that send users to web pages hosting Android apps. These sites instruct users on how to side-load unofficial Android apps from outside the Play Store. Code hidden in these apps downloads the xHelper trojan.

Maybe not this malware, but there is other malware on the Play Store.

https://www.digitaltrends.com/mobile/google-play-store-malwa...

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#8
post #6

Wonder if it's written itself into recovery. Or the SIM card/baseband - SIM card in particular usually includes functionality for triggering a sideload of apps (eg for carrier apps), sending notifications, etc into the main SOC so it fits. Maybe the second instance of SIM card malware ever. https://www.youtube.com/watch?v=31D94QOo2gY There are only so many places it can be hiding if it's surviving a factory reset. --…

AV vendors have multiple conflicts of interest and should not be trusted.

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#9
post #2

I know IOS isn't perfect, however, when I read articles like this, I just have to smile. There's something to be said for a tightly controlled platform and ecosystem.

What do you think iOS reviewers were thinking when carefully auditing these apps - https://mashable.com/2017/06/12/apple-app-store-subcription-... https://9to5mac.com/2019/10/25/malware-iphone-apps/ https://www.techtimes.com/articles/235985/20181204/apple-rem... https://www.wired.com/2015/09/apple-removes-300-infected-app... They get so much wrong, so often, you have to wonder if they really look at the apps at all o…

> just have some checklist, screenshots and a quota to hit

From my own app review experience, this is all they do.

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#10
post #8
post #6

Wonder if it's written itself into recovery. Or the SIM card/baseband - SIM card in particular usually includes functionality for triggering a sideload of apps (eg for carrier apps), sending notifications, etc into the main SOC so it fits. Maybe the second instance of SIM card malware ever. https://www.youtube.com/watch?v=31D94QOo2gY There are only so many places it can be hiding if it's surviving a factory reset. --…

AV vendors have multiple conflicts of interest and should not be trusted.

Can you elaborate?
Post reply on HN