Live data from Hacker News

Android Backdoor GhostCtrl Can Silently Record Your Audio, Video, and More

blog.trendmicro.com

61–66 of 66 posts

Re: Android Backdoor GhostCtrl Can Silently Record Your Audio, Video, and More

#61

Why is this being called a backdoor? Is there any indication that that's what it is? Except for the headline, the only claim even remotely as serious made in the article is that it can root some devices, and figuring out which ones is left as an exercise for the reader...

Reading anything written by a company like trendmicro can be really annoying.

They tend to litter all their discoveries with FUD in order to maximize their sales.

Re: Android Backdoor GhostCtrl Can Silently Record Your Audio, Video, and More

#62
post #50
post #3

> The malware masquerades as a legitimate or popular app that uses the names App, MMS, whatsapp, and even Pokemon GO. OK, so the attack vector here is installing dodgy stuff off the Play store? Or not the play store but from another source, such as an ad?

I believe it's only from 'third party' app stores..The official Google Play store already scans applications for such malicious content.

Even random apks are analyzed by the same service that is used by the play store.

It is still more dangerous, but known signatures are detected.

Re: Android Backdoor GhostCtrl Can Silently Record Your Audio, Video, and More

#63
post #59
post #13

Earlier quoted context omitted.

On consumer shops Android 4.4 and 5.1 devices are still the ones being sold on the 100€ price range. The permissions system was introduced on 6.0.

I just got a Samsung G550T, which is just north of your stated price range (currently $120 on Amazon https://www.amazon.com/Samsung-T-Mobile-Unlocked-Galaxy-Smar... ) but does have Marshmallow.

There's also the Nextbit Robin (https://www.amazon.com/gp/product/B01D9LVCAI) for just a hair more (currently $129 on Amazon). The product description says it's got Marshmallow, but, according to https://www.amazon.com/forum/-/Tx16RURIU0E0P5O , it's actually been upgraded to Nougat.

Re: Android Backdoor GhostCtrl Can Silently Record Your Audio, Video, and More

#64
post #60
post #58

Earlier quoted context omitted.

Yes it is possible to install a back door, after you've gained access. I'm fine with calling GhostCtrl a phishing attack that installs a back door. The big question here is which part of the attack elevates access to user or root level? The miscommunication here between us is that you're looking at what GhostCtrl does after it already gained access. Because the first point of contact, the initial entry point, is usin…

If you scroll back, this started with "Why is this being called a backdoor? Is there any indication that that's what it is?". I linked to a glossary entry I think reflects the common usage in malware context. Any payload is not a back door, payloads can be also ransomware, ddos bots, etc.

Okay, I think we're agreeing on the definition. You do agree that this particular backdoor depends on a successful phishing attack, right?

FWIW, I don't think that glossary entry you linked is very good. It calls a backdoor an application, but a backdoor is not always an application -- which I think you already know & mentioned in this thread. A RAT (remote access tool) is definitely not synonymous with backdoor in the common understanding. A backdoor can also be an open port, a bad password, or a variety of other entry methods. Wikipedia's entry on backdoor is better than the one you linked. https://en.m.wikipedia.org/wiki/Backdoor_(computing)

If a backdoor were always an application, and that was the common definition, then I think the question above wouldn't have been asked. One problem is that backdoor sometimes implies a vulnerability exists before any malware is installed. To call something a backdoor can send the wrong message about what someone concerned about this should do to mitigate the risks. Knowing it's a phishing attack is pretty important because it means you can and should be suspicious of apps asking for credentials and permissions. If you think it's primarily a back door, you might wrongly assume that you need to update a security patch, or that there's nothing you can do to reduce your risks.

This is why I believe @debatem1's question is reasonable and agree with it - to title this a backdoor is technically true, but it seems misleading.

Re: Android Backdoor GhostCtrl Can Silently Record Your Audio, Video, and More

#65
post #64
post #60

Earlier quoted context omitted.

If you scroll back, this started with "Why is this being called a backdoor? Is there any indication that that's what it is?". I linked to a glossary entry I think reflects the common usage in malware context. Any payload is not a back door, payloads can be also ransomware, ddos bots, etc.

Okay, I think we're agreeing on the definition. You do agree that this particular backdoor depends on a successful phishing attack, right? FWIW, I don't think that glossary entry you linked is very good. It calls a backdoor an application, but a backdoor is not always an application -- which I think you already know & mentioned in this thread. A RAT (remote access tool) is definitely not synonymous with backdoor in t…

I think this is going around in circles: we already covered the backdoor term in malware vs product name in contexts, and the payload vs phishing thing. If you Google for backdoor payloads, you see that it is common usage.

Re: Android Backdoor GhostCtrl Can Silently Record Your Audio, Video, and More

#66
post #21

Earlier quoted context omitted.

Well it's not like there's any option to deny them. You can only not install the app, unless the app chooses to build for the Android 6 permission system.

"You can only not install the app" That's what I actually do. I refuse to install apps that require broad permissions not related to their primary purpose. Though I do realize that I belong to that insignificant minority group of users.

Unfortunately, that would make my phone basically pointless. I wouldn't install damn near anything.
Post reply on HN