I'm really confused. How is it possible something like this survives a factory reset? To be fair, I have a very limited knowledge of hardware like this, but my assumption is a factory reset should remove EVERYTHING that didn't come on the phone put of the box. Some other comments are questioning weather this is happeneing to 'budget' devices sold by sketchy manufacturers. Would that explain something like this. I sur…
Android devices have multiple storage partitions. "Factory reset" generally refers to wiping the data partitions, but not the system partitions. It does not mean reflashing the phone's entire storage from an external image as you would expect. I would imagine this malware modifies one of the partitions that is not customarily wiped. And I would expect that doing a proper full reflash from a computer (eg starting from…
New 'unremovable' xHelper malware has infected 45,000 Android devices
61–70 of 110 posts
Re: New 'unremovable' xHelper malware has infected 45,000 Android devices
#62Earlier quoted context omitted.
Of course there is, just like on the Apple web store.
Links please
Re: New 'unremovable' xHelper malware has infected 45,000 Android devices
#63Wonder if it's written itself into recovery. Or the SIM card/baseband - SIM card in particular usually includes functionality for triggering a sideload of apps (eg for carrier apps), sending notifications, etc into the main SOC so it fits. Maybe the second instance of SIM card malware ever. https://www.youtube.com/watch?v=31D94QOo2gY There are only so many places it can be hiding if it's surviving a factory reset. --…
Writing to /system requires it to be mounted read/write and permissions to do so, so they'd need a root exploit in order to pull it off, but there's quite a few to choose from especially as devices age and given that they're doing this outside Play Store where Google won't pick them up.
I'm just crossing my fingers advanced users don't lose the ability to side-load apps over bad publicity like this, maybe they should make it harder to enable though.
Re: New 'unremovable' xHelper malware has infected 45,000 Android devices
#64I know IOS isn't perfect, however, when I read articles like this, I just have to smile. There's something to be said for a tightly controlled platform and ecosystem.
I don't know why you're being downvoted. You've got a point. There's no perfection in the App Store when it comes to review, but it's an ecosystem that is built around trying to create a sense of control and privacy. Sorry if you don't disagree but I reckon facts overwhelmingly disagree with you if you do. That's not to say in any way ANDROID BAD or anything like that, it's just a broader attack vector that you're up…
It's incredibly frustrating to read these pro-walled-garden-arguments. By the same argument you could say that the people in Hong Kong or elsewhere should just shut up and accept that their leaders will know what's best for them.
I worry about a future where these locked-down devices will be the norm for all of us. Don't defend Apple for locking you in. That's ridiculous.
Re: New 'unremovable' xHelper malware has infected 45,000 Android devices
#65Earlier quoted context omitted.
I don't know why you're being downvoted. You've got a point. There's no perfection in the App Store when it comes to review, but it's an ecosystem that is built around trying to create a sense of control and privacy. Sorry if you don't disagree but I reckon facts overwhelmingly disagree with you if you do. That's not to say in any way ANDROID BAD or anything like that, it's just a broader attack vector that you're up…
I didn't downvote but I understand why others did (I would have if it wasn't already grey). It's incredibly frustrating to read these pro-walled-garden-arguments. By the same argument you could say that the people in Hong Kong or elsewhere should just shut up and accept that their leaders will know what's best for them. I worry about a future where these locked-down devices will be the norm for all of us. Don't defen…
Re: New 'unremovable' xHelper malware has infected 45,000 Android devices
#66In other words, the conclusion is right, but this incident is NOT the selling point. Ad blockers and manifest V3 is a much better research study into their stupidity.
Re: New 'unremovable' xHelper malware has infected 45,000 Android devices
#67Sounds big, but likely paltry compared to active Android devices. That said, for other reasons that are more compelling, Apple is killing Google on "captive portal advantages". Google needs to dedicate more resources to both the PlayStore and the Chrome Extension store for many, many, reasons. They are not getting the inflection point of their "automation is fine" approach. In other words, the conclusion is right, bu…
Re: New 'unremovable' xHelper malware has infected 45,000 Android devices
#68Sounds big, but likely paltry compared to active Android devices. That said, for other reasons that are more compelling, Apple is killing Google on "captive portal advantages". Google needs to dedicate more resources to both the PlayStore and the Chrome Extension store for many, many, reasons. They are not getting the inflection point of their "automation is fine" approach. In other words, the conclusion is right, bu…
This doesn't really seem like a detection issue, but more of a design issue that Google needs to fix. Why is an app able to display ads across the system, even when you aren't running it? And how is it even possible for an app to make itself uninstallable?
Just noting that 45,000 users affected IS NOT the PlayStore failure reference story. It's bigger than that.
10 million uBlock Origin Chrome users are soon to be abandoned due to Google's policies. That's way more interesting, and ties the PlayStore issues to the same Chrome Extension issues.
Apple is credibly watching out for their customers. Google is credibly watching out for Google. Pretty much unapologetically with little pushback.
Personally frustrating for me as I've been a loyal Android user for a long time. Almost ready to switch to an iPhone, despite my unfamiliarity and the much higher price point. Google should pay attention.
Re: New 'unremovable' xHelper malware has infected 45,000 Android devices
#69Earlier quoted context omitted.
I didn't downvote but I understand why others did (I would have if it wasn't already grey). It's incredibly frustrating to read these pro-walled-garden-arguments. By the same argument you could say that the people in Hong Kong or elsewhere should just shut up and accept that their leaders will know what's best for them. I worry about a future where these locked-down devices will be the norm for all of us. Don't defen…
The analogy isn't useful because you're comparing a government to a corporation.
Re: New 'unremovable' xHelper malware has infected 45,000 Android devices
#70I know IOS isn't perfect, however, when I read articles like this, I just have to smile. There's something to be said for a tightly controlled platform and ecosystem.
Sure, except that once you get past the idea of trusting others for your security, and instead learning and securing stuff yourself, you quickly realize that "tightly controlled" is just a synonym for "you don't really own your device, we just let you use it how we see fit". As so recently demonstrated by Apples ability to remove the HKmap.live app. In general really wonder why people still defend Apple these days. E…