Earlier quoted context omitted.
Which part is odd? You can use standard APIs like GetAsyncKeyState() or various utilities for screen scraping and reading the paste buffer to make a key logger, no vulnerabilities required. We still consider such a thing malware of course. The point is exploiting vulnerabilities is not a necessary condition for something to be considered malware.
He's probably referring to injecting/deploying the keylogger in the first place. Either it came with a malicious software, via a system exploit, or someone installed it having physical access.
The Judy Malware: Possibly the largest malware campaign found on Google Play
61–70 of 85 posts
Re: The Judy Malware: Possibly the largest malware campaign found on Google Play
#62Earlier quoted context omitted.
I work in the security space, and I would definitely consider this malware. Generally, any software used with a malicious purpose is considered malware. As an example, keyloggers generally aren't exploiting any vulnerability (though malware often uses a vulnerability to install the keylogger in the first place), they're using the standard functionality of the computer as intended, but with malicious intent, and so ke…
Yeah, technically I can see it as malware, but not really in the same way... keyloggers obviously harm the user in collecting data against them, there's no malicious intent against the user here. This is only a minor increase over the already quite nasty but common mobile advertising practices. In fact, I'd argue the information harvesting most mobile ad networks do is much more harmful than this click fraud. Do we b…
This is not really that different than the spam "debate" - I've heard people argue that spam is no big deal because the bulk of it is caught. Tell that to people who run mail servers (but only if you brought your earplugs).
I suppose that, because many people put up with so much surveillance, they have difficulty drawing a line. I find this one a simple line to draw, but if you feel the need to place it elsewhere, the best predicate tipping point is based on intent.
Re: The Judy Malware: Possibly the largest malware campaign found on Google Play
#63This isn't really malware in the traditional sense, it doesn't damage users of the app itself or harvest information from them, this is simply ad fraud, it only damages Google and its advertisers. It seems to me like CheckPoint is fishing for internet points with this title.
It's malware in the traditional sense: "Programs that do things you wouldn't expect or authorize them to do that are harmful either to yourself or to others."
Does that mean Chrome is malware, too?
Re: The Judy Malware: Possibly the largest malware campaign found on Google Play
#64Earlier quoted context omitted.
It's malware in the traditional sense: "Programs that do things you wouldn't expect or authorize them to do that are harmful either to yourself or to others."
I certainly didn't "expect" (nor ever authorize) my browser to maintain open SSL connections to servers in googleplex sending them God knows what. Does that mean Chrome is malware, too?
Re: The Judy Malware: Possibly the largest malware campaign found on Google Play
#65Earlier quoted context omitted.
Isn't that all ads, then? I mean, as an end user, which is more harmful to you - downloading a bunch of ads and filling your screen with them, or downloading a bunch of ads and not displaying them? You are going to use more battery and resources actually displaying the ads, not to mention the worse user experience. If I had to pick between the two, I would prefer 'download and don't display' over 'download and displa…
Ads don't have malicious intent (usually). You may not like them, but displaying ads doesn't cause you harm. You could argue "having to see ads is inconvenient, which is a kind of harm" but just because software is inconvenient or doesn't do exactly what you want doesn't mean it's malicious. In this case, what makes Judy malicious is that it is using your machine to defraud advertisers.
Re: The Judy Malware: Possibly the largest malware campaign found on Google Play
#66Earlier quoted context omitted.
Yeah, technically I can see it as malware, but not really in the same way... keyloggers obviously harm the user in collecting data against them, there's no malicious intent against the user here. This is only a minor increase over the already quite nasty but common mobile advertising practices. In fact, I'd argue the information harvesting most mobile ad networks do is much more harmful than this click fraud. Do we b…
This is not so much a matter of debate as of reading up. https://en.wikipedia.org/wiki/Malware > Some malware is used to generate money by click fraud, making it appear that the computer user has clicked an advertising link on a site, generating a payment from the advertiser. It was estimated in 2012 that about 60 to 70% of all active malware used some kind of click fraud, and 22% of all ad-clicks were fraudulent If…
Re: The Judy Malware: Possibly the largest malware campaign found on Google Play
#67Earlier quoted context omitted.
Yeah, technically I can see it as malware, but not really in the same way... keyloggers obviously harm the user in collecting data against them, there's no malicious intent against the user here. This is only a minor increase over the already quite nasty but common mobile advertising practices. In fact, I'd argue the information harvesting most mobile ad networks do is much more harmful than this click fraud. Do we b…
If you're using my cycles, bandwidth, memory, power, etc. without my permission, it is malware. This is not really that different than the spam "debate" - I've heard people argue that spam is no big deal because the bulk of it is caught. Tell that to people who run mail servers (but only if you brought your earplugs). I suppose that, because many people put up with so much surveillance, they have difficulty drawing a…
So, what of intent - are those people taking unique device identifiers, account names, installed package lists, etc not of a malicious intent with them? I'd say so. I'd say that intent is far more malicious than defrauding some advertisers.
Re: The Judy Malware: Possibly the largest malware campaign found on Google Play
#68Are they really certain of this, or could it just be the work of someone who wants to "poison the well" of Google's ad network data collection?
It somehow reminds me of https://news.ycombinator.com/item?id=10611594 (Would CheckPoint also consider that malware?)
Re: The Judy Malware: Possibly the largest malware campaign found on Google Play
#69Earlier quoted context omitted.
If I read the article correct it downloads JavaScript code to load ad pages. It never bypassed the sandbox. I don't think you can call this malware
So if I'm on a metered data connection, getting hit with would result in...?
Re: The Judy Malware: Possibly the largest malware campaign found on Google Play
#70Earlier quoted context omitted.
Ads don't have malicious intent (usually). You may not like them, but displaying ads doesn't cause you harm. You could argue "having to see ads is inconvenient, which is a kind of harm" but just because software is inconvenient or doesn't do exactly what you want doesn't mean it's malicious. In this case, what makes Judy malicious is that it is using your machine to defraud advertisers.
It often takes my personal information, unique device identifiers etc and sends them over the internet without my consent. That causes harm. IMO, much more so than defrauding some advertisers.
I'm not really interested in having that argument here, since it's really off topic for this article.