Live data from Hacker News

Android emulator abused to introduce malware onto PCs

blog.malwarebytes.com

1–10 of 44 posts

Re: Android emulator abused to introduce malware onto PCs

#3
post #2

it's 2021. updating apps should not be something every developer has to write themselves. it should be part of the operating system, separate from the app stores...

I'm not entirely sure what you mean by "part of operating system, separate from the app stores", but in this case a server was delivering tainted updates, so having an OS-based update mechanism/package manager by itself wouldn't have prevented this. Unless you also mean that this update should have gone through the OS's repositories (which I feel is close to app store).

Re: Android emulator abused to introduce malware onto PCs

#4
I knew nox has been adware for a while and I'm surprised it's still being used. Literally go to r/noxappplayer and you'll see most of the top posts are about it being malware. If anyone's need a good android emulator, genymotion is probably the best and it's free for personal uses https://www.genymotion.com/fun-zone/

Re: Android emulator abused to introduce malware onto PCs

#5
post #2

it's 2021. updating apps should not be something every developer has to write themselves. it should be part of the operating system, separate from the app stores...

A quick search showed compromised packages in arch aur repos: https://www.bleepingcomputer.com/news/security/malware-found...

You only change the focal point, but a centralised package manager is good for reasons other than security. Sure, a central tool will keep your whole system updated and improve security overall, but it won't prevent supply-chain attacks from happening.

Reading mailing lists and being careful with what you install will take you a long way in preventing malware.

Re: Android emulator abused to introduce malware onto PCs

#9
post #8

The article's focus on it being an emulator feels misleading. They compromised an auto-update feature, it can happen to any software that offers updates. Even manual updates.

Feels clickbaity. I was interested because this implied they somehow broke outside both Android's sandbox and the emulator's hypervisor but nope, it was way more mundane (but not less severe of course). The magic is in not knowing.
Post reply on HN