Earlier quoted context omitted.
To be fair, if you stick to just using the Google Play Store, _this_ malware wouldn't hit you. > According to Malwarebytes, the source of these infections is "web redirects" that send users to web pages hosting Android apps. These sites instruct users on how to side-load unofficial Android apps from outside the Play Store. Code hidden in these apps downloads the xHelper trojan.
Maybe not this malware, but there is other malware on the Play Store. https://www.digitaltrends.com/mobile/google-play-store-malwa...
New 'unremovable' xHelper malware has infected 45,000 Android devices
21–30 of 110 posts
Re: New 'unremovable' xHelper malware has infected 45,000 Android devices
#22Earlier quoted context omitted.
Stories of bad viruses actually help them
If you refer to the theory that AV actually wrote viruses (it's not clear), that's as realistic as saying that police commits crimes so that they can get extra reward from the new tasks. I've followed the VX scene for years (it died long ago) and there has never been shortage of new malware. Even if we wanted to give some credit to the theory, which type of virus would the AV companies develop? Something trivial, tha…
Re: New 'unremovable' xHelper malware has infected 45,000 Android devices
#23I know IOS isn't perfect, however, when I read articles like this, I just have to smile. There's something to be said for a tightly controlled platform and ecosystem.
What do you think iOS reviewers were thinking when carefully auditing these apps - https://mashable.com/2017/06/12/apple-app-store-subcription-... https://9to5mac.com/2019/10/25/malware-iphone-apps/ https://www.techtimes.com/articles/235985/20181204/apple-rem... https://www.wired.com/2015/09/apple-removes-300-infected-app... They get so much wrong, so often, you have to wonder if they really look at the apps at all o…
Apple's capricious app store review policy aside, iOS is so locked down that even a completely malicious sideloaded* iOS app can't dig itself into the system like this. Without a local privilege escalation exploit there's just no way to set up a persistent background service and no way to escape the sandboxing to allow an app to leave a mark on the system after your app is uninstalled.
(*a developer can basically sideload any app on their iOS device with an Apple developer license)
Re: New 'unremovable' xHelper malware has infected 45,000 Android devices
#24I know IOS isn't perfect, however, when I read articles like this, I just have to smile. There's something to be said for a tightly controlled platform and ecosystem.
What do you think iOS reviewers were thinking when carefully auditing these apps - https://mashable.com/2017/06/12/apple-app-store-subcription-... https://9to5mac.com/2019/10/25/malware-iphone-apps/ https://www.techtimes.com/articles/235985/20181204/apple-rem... https://www.wired.com/2015/09/apple-removes-300-infected-app... They get so much wrong, so often, you have to wonder if they really look at the apps at all o…
Re: New 'unremovable' xHelper malware has infected 45,000 Android devices
#25I know IOS isn't perfect, however, when I read articles like this, I just have to smile. There's something to be said for a tightly controlled platform and ecosystem.
Re: New 'unremovable' xHelper malware has infected 45,000 Android devices
#26Earlier quoted context omitted.
Stories of bad viruses actually help them
If you refer to the theory that AV actually wrote viruses (it's not clear), that's as realistic as saying that police commits crimes so that they can get extra reward from the new tasks. I've followed the VX scene for years (it died long ago) and there has never been shortage of new malware. Even if we wanted to give some credit to the theory, which type of virus would the AV companies develop? Something trivial, tha…
So very realistic then?
Or have you not encountered the numerous incidents where cops plant and manufacture evidence to frame people for various reasons such as increasing their numbers for a promotion or bad culture leading to quotas for arrests/tickets/etc.?
Re: New 'unremovable' xHelper malware has infected 45,000 Android devices
#27I know IOS isn't perfect, however, when I read articles like this, I just have to smile. There's something to be said for a tightly controlled platform and ecosystem.
Are you smiling because people who chose other options than you are having issues?
Re: New 'unremovable' xHelper malware has infected 45,000 Android devices
#28Software publishers which have been proven to be paying out commission money from "bait and install" app links, for things published in the Play Store, should have their entire app and developer profile removed with extreme prejudice.
Re: New 'unremovable' xHelper malware has infected 45,000 Android devices
#29Wonder if it's written itself into recovery. Or the SIM card/baseband - SIM card in particular usually includes functionality for triggering a sideload of apps (eg for carrier apps), sending notifications, etc into the main SOC so it fits. Maybe the second instance of SIM card malware ever. https://www.youtube.com/watch?v=31D94QOo2gY There are only so many places it can be hiding if it's surviving a factory reset. --…
I'd wager that the firmware came pre-infected by the manufacturer (or an update to the firmware has the infection). Based on the reddit thread at least one of the devices is from a no-name manufacturer. https://www.reddit.com/r/antivirus/comments/bj6isa/xhelper_k...
Re: New 'unremovable' xHelper malware has infected 45,000 Android devices
#30I know IOS isn't perfect, however, when I read articles like this, I just have to smile. There's something to be said for a tightly controlled platform and ecosystem.
It seems like they could get a better outcome by having levels of trust for unsanctioned apps. Like the default for side-loaded apps would be just as an app only. No background processing, notifications, loading services. To get the latter functionality you could make the user jump through a bunch of hoops with nasty warning messages or even just not allow it.
There are already many legitimate apps distributed outside of Google Play for various reasons, such as weird Google policies or simply being booted out with no or spurious reason & the developer not being able to ever reach a human to fix this.
So be careful what you wish for.