Live data from Hacker News

New 'unremovable' xHelper malware has infected 45,000 Android devices

zdnet.com

51–60 of 110 posts

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#51

Earlier quoted context omitted.

What do you think iOS reviewers were thinking when carefully auditing these apps - https://mashable.com/2017/06/12/apple-app-store-subcription-... https://9to5mac.com/2019/10/25/malware-iphone-apps/ https://www.techtimes.com/articles/235985/20181204/apple-rem... https://www.wired.com/2015/09/apple-removes-300-infected-app... They get so much wrong, so often, you have to wonder if they really look at the apps at all o…

If shady devs can get a malicious app past Apple they can definitely get one past the average user. Does Apple get it right 100% of the time? Of course not. Does Apple get it right far more often than I would? Without a doubt.

Getting a malicious app past Apple in this context might mean as little as getting past a cursory review from a single indifferent employee. Apple has let enough bad apps through that, without further information, my default assumption is that the reviewer is doing little more than checking some boxes.

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#52
post #48

I'm really confused. How is it possible something like this survives a factory reset? To be fair, I have a very limited knowledge of hardware like this, but my assumption is a factory reset should remove EVERYTHING that didn't come on the phone put of the box. Some other comments are questioning weather this is happeneing to 'budget' devices sold by sketchy manufacturers. Would that explain something like this. I sur…

Probably calling as pre-installed service in the ROM. Definitely baked in by the manufacturer.

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#53
post #2

I know IOS isn't perfect, however, when I read articles like this, I just have to smile. There's something to be said for a tightly controlled platform and ecosystem.

I don't know why you're being downvoted. You've got a point. There's no perfection in the App Store when it comes to review, but it's an ecosystem that is built around trying to create a sense of control and privacy. Sorry if you don't disagree but I reckon facts overwhelmingly disagree with you if you do.

That's not to say in any way ANDROID BAD or anything like that, it's just a broader attack vector that you're up against with Android unless you're a very careful experienced customer. Most people aren't. :/

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#55

Earlier quoted context omitted.

I remember reading something about mediatek based phones saving on the BOM by utilizing virtualization on a single SoC to run the baseband RTOS and the Smartphone OS.

That’s actually kind of brilliant.

Until you get bugs like "3D games lag when in fast moving car due to constant cell handovers" and "4G doesn't work at the same time as playing a 1080p60 video, so netflix/youtube are broken unless on wifi".

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#56

Earlier quoted context omitted.

That’s actually kind of brilliant.

Until you get bugs like "3D games lag when in fast moving car due to constant cell handovers" and "4G doesn't work at the same time as playing a 1080p60 video, so netflix/youtube are broken unless on wifi".

Sure but the phones $80. Getting to that price point requires some compromises. You’d think they’d also set the baseband VM at highest QOS.

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#57

Earlier quoted context omitted.

Until you get bugs like "3D games lag when in fast moving car due to constant cell handovers" and "4G doesn't work at the same time as playing a 1080p60 video, so netflix/youtube are broken unless on wifi".

Sure but the phones $80. Getting to that price point requires some compromises. You’d think they’d also set the baseband VM at highest QOS.

I'm currently using a Xiaomi Redmi Go that was a bit less than that and I think it's remarkable how few compromises it has.

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#58

Earlier quoted context omitted.

Are you smiling because people who chose other options than you are having issues?

The people who made choices that enable these issues, while complaining about other options that prevent these issues?

One needn't badmouth iOS in order to use Android. Indeed, many who use Android don't know that iOS exists.

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#59
post #54
post #34

Earlier quoted context omitted.

Links please

There are some just above in this thread.

Those aren't links to malware. Those are links to stories about malware that was removed from the App Store. Kinda makes the opposite point of what you're implying, doesn't it?

Re: New 'unremovable' xHelper malware has infected 45,000 Android devices

#60

> The ads and notifications redirect users to the Play Store, where victims are asked to install other apps -- a means through which the xHelper gang is making money from pay-per-install commissions. Software publishers which have been proven to be paying out commission money from "bait and install" app links, for things published in the Play Store, should have their entire app and developer profile removed with extr…

That's a bold demand, considering that majority of free games in Play Store monetize themselves via partner installs. For all we know, developers of involved apps are paying a "legit" advertising company for installs, and malware authors act as ordinary partners of that company (likely using a bunch of throwaway accounts).
Post reply on HN