Live data from Hacker News

New 'unremovable' xHelper malware has infected 45,000 Android devices

zdnet.com

31–40 of 110 posts

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#31

> The ads and notifications redirect users to the Play Store, where victims are asked to install other apps -- a means through which the xHelper gang is making money from pay-per-install commissions. Software publishers which have been proven to be paying out commission money from "bait and install" app links, for things published in the Play Store, should have their entire app and developer profile removed with extr…

How do you prove this? What if they start randomizing?

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#32

> The ads and notifications redirect users to the Play Store, where victims are asked to install other apps -- a means through which the xHelper gang is making money from pay-per-install commissions. Software publishers which have been proven to be paying out commission money from "bait and install" app links, for things published in the Play Store, should have their entire app and developer profile removed with extr…

How do you prove this? What if they start randomizing?

Through screenshots (and photographs, if needed) of the actual malware running on example devices, or in sandbox environments, or both, and what Play store install pages they're sending people to. I'd certainly hope that there's some team of people at Google doing exactly this already.

Also from bulk analysis tools running against known-malware hosting http daemons out on the Internet. Anybody who's used an android phone for a sufficiently long time and visited a few weird places has seen the javascript redirects for scary-looking pages with "CLEAN 581 VIRUSES FROM YOUR PHONE NOW" pages, designed to mimic android or ios system GUI elements. Inevitably accompanied by a link to a play store page.

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#33

Earlier quoted context omitted.

If you refer to the theory that AV actually wrote viruses (it's not clear), that's as realistic as saying that police commits crimes so that they can get extra reward from the new tasks. I've followed the VX scene for years (it died long ago) and there has never been shortage of new malware. Even if we wanted to give some credit to the theory, which type of virus would the AV companies develop? Something trivial, tha…

> that's as realistic as saying that police commits crimes so that they can get extra reward from the new tasks. So very realistic then? Or have you not encountered the numerous incidents where cops plant and manufacture evidence to frame people for various reasons such as increasing their numbers for a promotion or bad culture leading to quotas for arrests/tickets/etc.?

Now imagine a wholly for-profit police force.

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#34

Earlier quoted context omitted.

Maybe not this malware, but there is other malware on the Play Store. https://www.digitaltrends.com/mobile/google-play-store-malwa...

Of course there is, just like on the Apple web store.

Links please

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#35
post #30
post #5

Earlier quoted context omitted.

It seems like they could get a better outcome by having levels of trust for unsanctioned apps. Like the default for side-loaded apps would be just as an app only. No background processing, notifications, loading services. To get the latter functionality you could make the user jump through a bunch of hoops with nasty warning messages or even just not allow it.

Note that if you enforce this for all side loaded apps are turning Android closer to the walled garden that is iOS. There are already many legitimate apps distributed outside of Google Play for various reasons, such as weird Google policies or simply being booted out with no or spurious reason & the developer not being able to ever reach a human to fix this. So be careful what you wish for.

I wish apple would allow side loaded apps. I'm not saying eliminate side loaded apps all together. Merely, it seems like its a binary view. Either allow side loaded apps and make no attempt to design the installation process with security features, or deny un-approved applications entirely in the name of security.

I think Apple's desktop solution to unverified developers is a good way to split the difference. Deny by default but allow whitelisting. They go even further under the privacy tab and only allow certain applications permission to access accessibility features or full disk access, etc.

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#36
post #13

Earlier quoted context omitted.

I'd wager that the firmware came pre-infected by the manufacturer (or an update to the firmware has the infection). Based on the reddit thread at least one of the devices is from a no-name manufacturer. https://www.reddit.com/r/antivirus/comments/bj6isa/xhelper_k...

a not insignificant portion of generic weird mediatek chipset android phones come rooted from the manufacturer, because the OS is built with a root/developer configuration. This also helps malware like this spread on the sub-$80 android phones sold to non technically sophisticated users in the developing world.

I remember reading something about mediatek based phones saving on the BOM by utilizing virtualization on a single SoC to run the baseband RTOS and the Smartphone OS.

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#37

Earlier quoted context omitted.

Stories of bad viruses actually help them

If you refer to the theory that AV actually wrote viruses (it's not clear), that's as realistic as saying that police commits crimes so that they can get extra reward from the new tasks. I've followed the VX scene for years (it died long ago) and there has never been shortage of new malware. Even if we wanted to give some credit to the theory, which type of virus would the AV companies develop? Something trivial, tha…

> [...] that's as realistic as saying that police commits crimes so that they can get extra reward from the new tasks.

More like saying private 'protection companies' commit crimes so they can get you to pay for their 'protection'.

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#39
post #38

45,000 is a trivial number of infections when you consider that there are 2.5bn monthly active Android devices: https://venturebeat.com/2019/05/07/android-passes-2-5-billio... That's what, 0.0018% of devices infected?

So far?

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#40

Earlier quoted context omitted.

a not insignificant portion of generic weird mediatek chipset android phones come rooted from the manufacturer, because the OS is built with a root/developer configuration. This also helps malware like this spread on the sub-$80 android phones sold to non technically sophisticated users in the developing world.

I remember reading something about mediatek based phones saving on the BOM by utilizing virtualization on a single SoC to run the baseband RTOS and the Smartphone OS.

That’s actually kind of brilliant.
Post reply on HN