> The ads and notifications redirect users to the Play Store, where victims are asked to install other apps -- a means through which the xHelper gang is making money from pay-per-install commissions. Software publishers which have been proven to be paying out commission money from "bait and install" app links, for things published in the Play Store, should have their entire app and developer profile removed with extr…
New 'unremovable' xHelper malware has infected 45,000 Android devices
31–40 of 110 posts
Re: New 'unremovable' xHelper malware has infected 45,000 Android devices
#32> The ads and notifications redirect users to the Play Store, where victims are asked to install other apps -- a means through which the xHelper gang is making money from pay-per-install commissions. Software publishers which have been proven to be paying out commission money from "bait and install" app links, for things published in the Play Store, should have their entire app and developer profile removed with extr…
How do you prove this? What if they start randomizing?
Also from bulk analysis tools running against known-malware hosting http daemons out on the Internet. Anybody who's used an android phone for a sufficiently long time and visited a few weird places has seen the javascript redirects for scary-looking pages with "CLEAN 581 VIRUSES FROM YOUR PHONE NOW" pages, designed to mimic android or ios system GUI elements. Inevitably accompanied by a link to a play store page.
Re: New 'unremovable' xHelper malware has infected 45,000 Android devices
#33Earlier quoted context omitted.
If you refer to the theory that AV actually wrote viruses (it's not clear), that's as realistic as saying that police commits crimes so that they can get extra reward from the new tasks. I've followed the VX scene for years (it died long ago) and there has never been shortage of new malware. Even if we wanted to give some credit to the theory, which type of virus would the AV companies develop? Something trivial, tha…
> that's as realistic as saying that police commits crimes so that they can get extra reward from the new tasks. So very realistic then? Or have you not encountered the numerous incidents where cops plant and manufacture evidence to frame people for various reasons such as increasing their numbers for a promotion or bad culture leading to quotas for arrests/tickets/etc.?
Re: New 'unremovable' xHelper malware has infected 45,000 Android devices
#34Re: New 'unremovable' xHelper malware has infected 45,000 Android devices
#35Earlier quoted context omitted.
It seems like they could get a better outcome by having levels of trust for unsanctioned apps. Like the default for side-loaded apps would be just as an app only. No background processing, notifications, loading services. To get the latter functionality you could make the user jump through a bunch of hoops with nasty warning messages or even just not allow it.
Note that if you enforce this for all side loaded apps are turning Android closer to the walled garden that is iOS. There are already many legitimate apps distributed outside of Google Play for various reasons, such as weird Google policies or simply being booted out with no or spurious reason & the developer not being able to ever reach a human to fix this. So be careful what you wish for.
I think Apple's desktop solution to unverified developers is a good way to split the difference. Deny by default but allow whitelisting. They go even further under the privacy tab and only allow certain applications permission to access accessibility features or full disk access, etc.
Re: New 'unremovable' xHelper malware has infected 45,000 Android devices
#36Earlier quoted context omitted.
I'd wager that the firmware came pre-infected by the manufacturer (or an update to the firmware has the infection). Based on the reddit thread at least one of the devices is from a no-name manufacturer. https://www.reddit.com/r/antivirus/comments/bj6isa/xhelper_k...
a not insignificant portion of generic weird mediatek chipset android phones come rooted from the manufacturer, because the OS is built with a root/developer configuration. This also helps malware like this spread on the sub-$80 android phones sold to non technically sophisticated users in the developing world.
Re: New 'unremovable' xHelper malware has infected 45,000 Android devices
#37Earlier quoted context omitted.
Stories of bad viruses actually help them
If you refer to the theory that AV actually wrote viruses (it's not clear), that's as realistic as saying that police commits crimes so that they can get extra reward from the new tasks. I've followed the VX scene for years (it died long ago) and there has never been shortage of new malware. Even if we wanted to give some credit to the theory, which type of virus would the AV companies develop? Something trivial, tha…
More like saying private 'protection companies' commit crimes so they can get you to pay for their 'protection'.
Re: New 'unremovable' xHelper malware has infected 45,000 Android devices
#38That's what, 0.0018% of devices infected?
Re: New 'unremovable' xHelper malware has infected 45,000 Android devices
#3945,000 is a trivial number of infections when you consider that there are 2.5bn monthly active Android devices: https://venturebeat.com/2019/05/07/android-passes-2-5-billio... That's what, 0.0018% of devices infected?
Re: New 'unremovable' xHelper malware has infected 45,000 Android devices
#40Earlier quoted context omitted.
a not insignificant portion of generic weird mediatek chipset android phones come rooted from the manufacturer, because the OS is built with a root/developer configuration. This also helps malware like this spread on the sub-$80 android phones sold to non technically sophisticated users in the developing world.
I remember reading something about mediatek based phones saving on the BOM by utilizing virtualization on a single SoC to run the baseband RTOS and the Smartphone OS.