Live data from Hacker News

The Judy Malware: Possibly the largest malware campaign found on Google Play

blog.checkpoint.com

71–80 of 85 posts

Re: The Judy Malware: Possibly the largest malware campaign found on Google Play

#71

Earlier quoted context omitted.

It's malware in the traditional sense: "Programs that do things you wouldn't expect or authorize them to do that are harmful either to yourself or to others."

I certainly didn't "expect" (nor ever authorize) my browser to maintain open SSL connections to servers in googleplex sending them God knows what. Does that mean Chrome is malware, too?

If it makes you feel any better, Google hasn't supported SSL for some time.

Open TLS connections on the other hand, well now that's a different story.

Re: The Judy Malware: Possibly the largest malware campaign found on Google Play

#72

Upon clicking the ads, the malware author receives payment from the website developer, which pays for the illegitimate clicks and traffic. Are they really certain of this, or could it just be the work of someone who wants to "poison the well" of Google's ad network data collection? It somehow reminds me of https://news.ycombinator.com/item?id=10611594 (Would CheckPoint also consider that malware?)

If the user isn't informed the app they installed is clicking on ads, it absolutely is malware.

Re: The Judy Malware: Possibly the largest malware campaign found on Google Play

#73
post #28
post #19

Earlier quoted context omitted.

Who's to say they haven't already?

From the article: "The company develops mobile apps for both Android and iOS platform" The apps are probably removed from both stores by now so we will never know ;)

They develop apps for both, but that doesn't necessarily mean they had the same adware in the iOS version.

Re: The Judy Malware: Possibly the largest malware campaign found on Google Play

#74

Earlier quoted context omitted.

This is not so much a matter of debate as of reading up. https://en.wikipedia.org/wiki/Malware > Some malware is used to generate money by click fraud, making it appear that the computer user has clicked an advertising link on a site, generating a payment from the advertiser. It was estimated in 2012 that about 60 to 70% of all active malware used some kind of click fraud, and 22% of all ad-clicks were fraudulent If…

Does this encompass malware that sends unique device identifiers to 3rd parties? Google account names? Or are those extremely common practices not considered malicious at all? In my opinion those are much more malicious actions. The only way to compare malicious with malicious is indeed relative. If one arguably malicious action is prohibited but another is not, you have to question the motivations. "More malicious t…

Yes, I absolutely agree that plenty of commonly practiced or even accepted things are malicious, too, at least with the way they're hand waved away ("to improve our service" and worse).

Re: The Judy Malware: Possibly the largest malware campaign found on Google Play

#75

It looks like the common component across the apps mentioned is in the "net.shinhwa21.jsylibrary" namespace. I made a list of the apps with that namespace, preview here: https://mixrank.com/playstore/apps?expiration=2017-06-30&lis... This list is a few times bigger than the ones mentioned in the article (been crawling for a long time, and try to be complete). If there's any security folks here that want access to the…

Could be that legit apps have legit versions of those components.

Re: The Judy Malware: Possibly the largest malware campaign found on Google Play

#76
post #73
post #28

Earlier quoted context omitted.

From the article: "The company develops mobile apps for both Android and iOS platform" The apps are probably removed from both stores by now so we will never know ;)

They develop apps for both, but that doesn't necessarily mean they had the same adware in the iOS version.

But why not? This is not some complex exploit, just standard JavaScript.

I saw the same attitude after the xcode backdoor. "There is no reason to believe any personal data has been affected", well if apple didn't even knew this thing existed how could they possibly know if it was activly used??

Edit: according to reddit apple just pulled all apps made by these guys. Not a proof of anything but still something to consider

Re: The Judy Malware: Possibly the largest malware campaign found on Google Play

#77
post #76
post #73

Earlier quoted context omitted.

They develop apps for both, but that doesn't necessarily mean they had the same adware in the iOS version.

But why not? This is not some complex exploit, just standard JavaScript. I saw the same attitude after the xcode backdoor. "There is no reason to believe any personal data has been affected", well if apple didn't even knew this thing existed how could they possibly know if it was activly used?? Edit: according to reddit apple just pulled all apps made by these guys. Not a proof of anything but still something to cons…

The simple reason is if they thought that App Review might catch their shenanigans then they might decide to not do it on iOS, because being caught means having their apps pulled. I'm not surprised that Apple pulled their apps anyway, it's what I'd expect of them since they've demonstrated a willingness to put adware in their apps, even if it was only on Android.

So basically, maybe they put the adware in the iOS apps, maybe they didn't, but we can't tell from the article. But one would think that if they did, the article might have mentioned that, because it's a much better story to say "malware in the iOS app store" than it is to say "malware in the Google Play store".

Re: The Judy Malware: Possibly the largest malware campaign found on Google Play

#78
post #77
post #76

Earlier quoted context omitted.

But why not? This is not some complex exploit, just standard JavaScript. I saw the same attitude after the xcode backdoor. "There is no reason to believe any personal data has been affected", well if apple didn't even knew this thing existed how could they possibly know if it was activly used?? Edit: according to reddit apple just pulled all apps made by these guys. Not a proof of anything but still something to cons…

The simple reason is if they thought that App Review might catch their shenanigans then they might decide to not do it on iOS, because being caught means having their apps pulled. I'm not surprised that Apple pulled their apps anyway, it's what I'd expect of them since they've demonstrated a willingness to put adware in their apps, even if it was only on Android. So basically, maybe they put the adware in the iOS app…

I don't understand your comment. Apple and Google have the same mostly-automatic approval process.

(You didnt think apple would manually inspect billions of apps and their updates? 2 weeks per app * 1 billion apps * 3 updates = 115 million man years)

Re: The Judy Malware: Possibly the largest malware campaign found on Google Play

#79
post #78
post #77

Earlier quoted context omitted.

The simple reason is if they thought that App Review might catch their shenanigans then they might decide to not do it on iOS, because being caught means having their apps pulled. I'm not surprised that Apple pulled their apps anyway, it's what I'd expect of them since they've demonstrated a willingness to put adware in their apps, even if it was only on Android. So basically, maybe they put the adware in the iOS app…

I don't understand your comment. Apple and Google have the same mostly-automatic approval process. (You didnt think apple would manually inspect billions of apps and their updates? 2 weeks per app * 1 billion apps * 3 updates = 115 million man years)

Apple does not have an automatic approval process. They do a lot of automatic screening, because there's plenty that can be caught that way, but yes, every single app and update gets manual review by a human being.

And your math is very wrong. Very few apps update every 2 weeks, most of the apps on the app store probably haven't even been updated in the past few months, and there's not even close to a billion apps. In an interview back in January Phil Schiller said the App Store had 2.2 million apps.

Re: The Judy Malware: Possibly the largest malware campaign found on Google Play

#80
post #79
post #78

Earlier quoted context omitted.

I don't understand your comment. Apple and Google have the same mostly-automatic approval process. (You didnt think apple would manually inspect billions of apps and their updates? 2 weeks per app * 1 billion apps * 3 updates = 115 million man years)

Apple does not have an automatic approval process. They do a lot of automatic screening, because there's plenty that can be caught that way, but yes, every single app and update gets manual review by a human being. And your math is very wrong. Very few apps update every 2 weeks, most of the apps on the app store probably haven't even been updated in the past few months, and there's not even close to a billion apps. I…

Nope, you missread my numbers.

I assume it takes one person 2 weeks to fully analyze an app (we are after all looking for well hidden malware, possibly downloaded from network after some use). Times 2.2 million apps. Times an average of 3 updates during its life time.

There are not enough apple employees to pull what you calim. Hence approval is semi automatic, just like Google.

Edit: 1 billion changed to 2.2 million, my bad.

Post reply on HN