Live data from Hacker News

New 'unremovable' xHelper malware has infected 45,000 Android devices

zdnet.com

11–20 of 110 posts

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#11
post #2

I know IOS isn't perfect, however, when I read articles like this, I just have to smile. There's something to be said for a tightly controlled platform and ecosystem.

What do you think iOS reviewers were thinking when carefully auditing these apps - https://mashable.com/2017/06/12/apple-app-store-subcription-... https://9to5mac.com/2019/10/25/malware-iphone-apps/ https://www.techtimes.com/articles/235985/20181204/apple-rem... https://www.wired.com/2015/09/apple-removes-300-infected-app... They get so much wrong, so often, you have to wonder if they really look at the apps at all o…

That doesn't feel like the same thing at all. A shady developer tricking people into a subscription because they don't know any better is way different from malware that reinstalls itself even after a factory reset. People have to agree to pay for the subscription from an OS-level prompt in the first instance. They don't have a choice in the 2nd.

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#13
post #6

Wonder if it's written itself into recovery. Or the SIM card/baseband - SIM card in particular usually includes functionality for triggering a sideload of apps (eg for carrier apps), sending notifications, etc into the main SOC so it fits. Maybe the second instance of SIM card malware ever. https://www.youtube.com/watch?v=31D94QOo2gY There are only so many places it can be hiding if it's surviving a factory reset. --…

I'd wager that the firmware came pre-infected by the manufacturer (or an update to the firmware has the infection).

Based on the reddit thread at least one of the devices is from a no-name manufacturer.

https://www.reddit.com/r/antivirus/comments/bj6isa/xhelper_k...

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#14
post #6

Wonder if it's written itself into recovery. Or the SIM card/baseband - SIM card in particular usually includes functionality for triggering a sideload of apps (eg for carrier apps), sending notifications, etc into the main SOC so it fits. Maybe the second instance of SIM card malware ever. https://www.youtube.com/watch?v=31D94QOo2gY There are only so many places it can be hiding if it's surviving a factory reset. --…

Only semi-related, but I wonder if owning the SIM card could be used as some sort of rooting mechanism?

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#15
post #10

Earlier quoted context omitted.

Can you elaborate?

Stories of bad viruses actually help them

This only really goes to the "don't entirely trust their statements regarding their product being the only effective barrier" part of the story. Reputable anti-virus companies do have a huge conflict of interest reporting on viruses they find and can tackle, but they also remain an important source of information about viruses. Disreputable anti-virus companies sell product which could be as simple as a "hollywood OS" green stripe animated GIF which says "virus cleaned" for all they really do: they probably install more malware rather than removing any.

Also, an anti virus company saying they can't understand how a virus remains infected after removal is interesting.

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#17
post #10

Earlier quoted context omitted.

Can you elaborate?

Stories of bad viruses actually help them

If you refer to the theory that AV actually wrote viruses (it's not clear), that's as realistic as saying that police commits crimes so that they can get extra reward from the new tasks.

I've followed the VX scene for years (it died long ago) and there has never been shortage of new malware.

Even if we wanted to give some credit to the theory, which type of virus would the AV companies develop? Something trivial, that requires a variation of a signature to detect? Or something extremely complex, that requires month of work, and that slows down the AV engine because it's algorithmically complex to detect?

None of this makes any sense. The truth is very simple - malware has always been an interesting subject, and writing viruses always had a subversive appeal to young rebels.

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#18

Earlier quoted context omitted.

Stories of bad viruses actually help them

If you refer to the theory that AV actually wrote viruses (it's not clear), that's as realistic as saying that police commits crimes so that they can get extra reward from the new tasks. I've followed the VX scene for years (it died long ago) and there has never been shortage of new malware. Even if we wanted to give some credit to the theory, which type of virus would the AV companies develop? Something trivial, tha…

Ya totally nothing to do with APT's and plausible deniability.

Darn kids.

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#19

Earlier quoted context omitted.

Stories of bad viruses actually help them

If you refer to the theory that AV actually wrote viruses (it's not clear), that's as realistic as saying that police commits crimes so that they can get extra reward from the new tasks. I've followed the VX scene for years (it died long ago) and there has never been shortage of new malware. Even if we wanted to give some credit to the theory, which type of virus would the AV companies develop? Something trivial, tha…

> If you refer to the theory that AV actually wrote viruses (it's not clear), that's as realistic as saying that police commits crimes so that they can get extra reward from the new tasks.

This analogy is not helping your case at all. It's not unheard of for police to plant evidence for such purposes. It's also been proven that law enforcement has been willfully using technology having high rates of false positives for things like drug testing to bring real charges against otherwise innocent people.

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#20

Earlier quoted context omitted.

Stories of bad viruses actually help them

If you refer to the theory that AV actually wrote viruses (it's not clear), that's as realistic as saying that police commits crimes so that they can get extra reward from the new tasks. I've followed the VX scene for years (it died long ago) and there has never been shortage of new malware. Even if we wanted to give some credit to the theory, which type of virus would the AV companies develop? Something trivial, tha…

> that's as realistic as saying that police commits crimes so that they can get extra reward from the new tasks.

https://www.washingtonpost.com/nation/2019/07/11/florida-cop...

Post reply on HN