Live data from Hacker News

New 'unremovable' xHelper malware has infected 45,000 Android devices

zdnet.com

41–50 of 110 posts

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#41
post #30
post #5

Earlier quoted context omitted.

It seems like they could get a better outcome by having levels of trust for unsanctioned apps. Like the default for side-loaded apps would be just as an app only. No background processing, notifications, loading services. To get the latter functionality you could make the user jump through a bunch of hoops with nasty warning messages or even just not allow it.

Note that if you enforce this for all side loaded apps are turning Android closer to the walled garden that is iOS. There are already many legitimate apps distributed outside of Google Play for various reasons, such as weird Google policies or simply being booted out with no or spurious reason & the developer not being able to ever reach a human to fix this. So be careful what you wish for.

This actually seems broadly similar to the issue with "self-XSS" and the developer console in browsers (which is hidden behind a couple of menus). So far most of the mitigations involve the site printing messages into the console telling users to not paste in anything here unless they are a developer.

Maybe it's a good idea to hide the "Allow sideloaded apps" under the developer menu in Android or something, or generally to display a scarier message.

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#42
post #13
post #6

Wonder if it's written itself into recovery. Or the SIM card/baseband - SIM card in particular usually includes functionality for triggering a sideload of apps (eg for carrier apps), sending notifications, etc into the main SOC so it fits. Maybe the second instance of SIM card malware ever. https://www.youtube.com/watch?v=31D94QOo2gY There are only so many places it can be hiding if it's surviving a factory reset. --…

I'd wager that the firmware came pre-infected by the manufacturer (or an update to the firmware has the infection). Based on the reddit thread at least one of the devices is from a no-name manufacturer. https://www.reddit.com/r/antivirus/comments/bj6isa/xhelper_k...

This happened to me with the Triada virus, on a Nomu S10 - it came with factory ota. That one patched the Zygote process and became invisible and unremovable without reflashing.

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#43
post #41
post #30

Earlier quoted context omitted.

Note that if you enforce this for all side loaded apps are turning Android closer to the walled garden that is iOS. There are already many legitimate apps distributed outside of Google Play for various reasons, such as weird Google policies or simply being booted out with no or spurious reason & the developer not being able to ever reach a human to fix this. So be careful what you wish for.

This actually seems broadly similar to the issue with "self-XSS" and the developer console in browsers (which is hidden behind a couple of menus). So far most of the mitigations involve the site printing messages into the console telling users to not paste in anything here unless they are a developer. Maybe it's a good idea to hide the "Allow sideloaded apps" under the developer menu in Android or something, or gener…

The end result of this is largely to discourage competition. The Google Play Store is not good at security, and the prohibition on sideloading is far less effective at preventing infection than it is at preventing app developers from avoiding Google's 30% app tax.

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#44
post #2

I know IOS isn't perfect, however, when I read articles like this, I just have to smile. There's something to be said for a tightly controlled platform and ecosystem.

What do you think iOS reviewers were thinking when carefully auditing these apps - https://mashable.com/2017/06/12/apple-app-store-subcription-... https://9to5mac.com/2019/10/25/malware-iphone-apps/ https://www.techtimes.com/articles/235985/20181204/apple-rem... https://www.wired.com/2015/09/apple-removes-300-infected-app... They get so much wrong, so often, you have to wonder if they really look at the apps at all o…

If shady devs can get a malicious app past Apple they can definitely get one past the average user. Does Apple get it right 100% of the time? Of course not. Does Apple get it right far more often than I would? Without a doubt.

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#45

Earlier quoted context omitted.

Maybe not this malware, but there is other malware on the Play Store. https://www.digitaltrends.com/mobile/google-play-store-malwa...

Of course there is, just like on the Apple web store.

The Apple web store only sells official Apple hardware shipped directly from Apple.

Put more thought into your posts. This isn’t reddit.

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#46

Earlier quoted context omitted.

How do you prove this? What if they start randomizing?

Through screenshots (and photographs, if needed) of the actual malware running on example devices, or in sandbox environments, or both, and what Play store install pages they're sending people to. I'd certainly hope that there's some team of people at Google doing exactly this already. Also from bulk analysis tools running against known-malware hosting http daemons out on the Internet. Anybody who's used an android p…

Suppose they send you to one of 20 hardcoded applications in the playstore, only one of which is theirs and the other 19 are innocent third parties being used as cover. Do you ban all 20?

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#47
post #2

I know IOS isn't perfect, however, when I read articles like this, I just have to smile. There's something to be said for a tightly controlled platform and ecosystem.

Sure, except that once you get past the idea of trusting others for your security, and instead learning and securing stuff yourself, you quickly realize that "tightly controlled" is just a synonym for "you don't really own your device, we just let you use it how we see fit". As so recently demonstrated by Apples ability to remove the HKmap.live app.

In general really wonder why people still defend Apple these days. Even if you overlook a combination of stuff like infinite attempts for icloud logins that led to the Fappening, their role in HK protests, and of course their pretty terrible labor practices that go so far as even to supposedly break the Chinese labor laws (which is a feat in itself), there is still issues with stuff they produce. Their hardware and software quality has been on a hard decline, especially if you compare it to alternatives rather than on its own merit. They don't really innovate despite opposite marketing claims, and they still participate in this "technology as a jewelry" thing with their $1000 monitor stands.

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#48
I'm really confused. How is it possible something like this survives a factory reset? To be fair, I have a very limited knowledge of hardware like this, but my assumption is a factory reset should remove EVERYTHING that didn't come on the phone put of the box.

Some other comments are questioning weather this is happeneing to 'budget' devices sold by sketchy manufacturers. Would that explain something like this.

I sure as hell hope thats not the case on a phone from reputable manufacturer. If I can't wipe everything, including malware from my android device by doing a factory reset, I'm going to throw it in the garbage tomorrow & buy an iPhone.

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#49

Earlier quoted context omitted.

If you refer to the theory that AV actually wrote viruses (it's not clear), that's as realistic as saying that police commits crimes so that they can get extra reward from the new tasks. I've followed the VX scene for years (it died long ago) and there has never been shortage of new malware. Even if we wanted to give some credit to the theory, which type of virus would the AV companies develop? Something trivial, tha…

As a victim of such a falsified crime, testified by half a dozen police officers who couldn't get their stories straight but whom "somehow" were believed, you're only adding credence to the claim with that analogy.

Not really. I'm not doubting that you have been wronged by the judicial system, as I've seen this first hand with a close friend. However, a bold claim like this requires solid evidence that such practices are the norm.

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#50
post #48

I'm really confused. How is it possible something like this survives a factory reset? To be fair, I have a very limited knowledge of hardware like this, but my assumption is a factory reset should remove EVERYTHING that didn't come on the phone put of the box. Some other comments are questioning weather this is happeneing to 'budget' devices sold by sketchy manufacturers. Would that explain something like this. I sur…

Android devices have multiple storage partitions. "Factory reset" generally refers to wiping the data partitions, but not the system partitions. It does not mean reflashing the phone's entire storage from an external image as you would expect.

I would imagine this malware modifies one of the partitions that is not customarily wiped. And I would expect that doing a proper full reflash from a computer (eg starting from `fastboot flash bootloader ...`) would remove it, assuming it wasn't already baked into that image at the manufacturer.

Post reply on HN