Live data from Hacker News

CamScanner, a malicious Android app with more than 100M downloads in Google Play

kaspersky.com

91–100 of 155 posts

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#91

So what exactly did this malware do most of the time? In the original kaspersky report it says "For example, an app with this malicious code may show intrusive ads and sign users up for paid subscriptions.". So how/did it sign up users for paid subscriptions without user interaction? Does android allow something like that? Aren't all apps sandboxed? In general how is the android sandboxing and permission system nowad…

I don't know this particular case, but "malware" seems to be used to describe "adware" these days by some blogs to generate more clicks. Android is just as secure/unsecure as iOS. Some recent "malware" campaigns targeted both platforms but in general Apple silently removes them while Android gets scrutinized to death. Edit: to answer your questions, these apps still operate within the limits of the sandbox. Which is…

This is clearly not the case. Not only is Android’s permission system more permissive, most Android phones don’t get updates as frequently and definitely not as far long as iOS.

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#92
post #13

Blogspam of https://www.kaspersky.com/blog/camscanner-malicious-android-... (Forbes contributor posts are almost always blogspam)

As if Kaspersky itself isn’t spamming. To make sure you never find yourself in such trouble, use a reliable antivirus for Android app and scan your smartphone from time to time. (The paid version of Kaspersky Internet Security for Android scans automatically.)

Inbound marketing is literally the opposite of spamming

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#93
post #13

Blogspam of https://www.kaspersky.com/blog/camscanner-malicious-android-... (Forbes contributor posts are almost always blogspam)

Ok, we've changed to that from https://www.forbes.com/sites/zakdoffman/2019/08/27/android-w.... Thanks!

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#95
post #7

Just to clarify the headline: the app didn't have malware when most of the users installed it. A recent update added the malware.

But the way Google pushes users to enable automatic updates, I would not be surprised if many of them had it automatically installed.

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#96
post #35

I've been using this app for years and also telling other people to use it, so this sucks. If anyone else is looking for a replacement there's a Microsoft app called "Office Lens" that seems to do a really nice job and is as safe a bet as anything.

I'm just using the Dropbox app, scanning is included.

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#97

So what do they do? Revoke the app and developer account of that guy who wrote the free transit-mapping app for Montreal. Google: hypocrisy on a colossal scale.

On the other hand, remember that guy whose complaint about Google termininating his developer account "for no reason" made the HN front page a couple of weeks back? https://medium.com/@tokata/how-google-play-terminated-a-deve...

According to his blog post, his "anti-piracy system" used "custom techniques including dynamic bytecode loading from a local app resource", the exact same technique used by this malicious code to hide from detection.

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#98

Guess what - this was caused by a third-party ad network: https://twitter.com/CamScanner/status/1166733219841986561/ph...

That is and for many, always an issue. Adverts help pay for content, be that a game or website - people literally make a living that way that it has become a bit of a defacto approach.

But when you are tied to including some code that goes off to a site that you have no or very little control over, you are outsourcing part of your company (web or app) into the hands of another in which, if they mess up. You are the the one that takes all the PR flack.

After all, if somebody slips an exploit into an AD hosted on a 3rd party site and offered up by a reputable AD serving company. Whilst the blame and fault may clearly be with the AD serving company for not screening what they offer. You are the ones that from a consumer and as it also transpires - the media as the one to blame. As we all know, corrections and retractions are always less viewed and eyeballed than the initial drama article based upon a small picture view of the issue/drama, instead of the root cause. Even with the best most respected media sites in the World, such retractions/corrections never get the same attention as the initial article of drama and doom.

That is one problem that even today, still prevails - media does an article with the finger pointing at one direction and the truth, even when it comes out and updated, never tracks as well as the initial finger pointing and is very much the old saying of "if enough mud is slung, some will stick".

{EDIT spelling and below}

With that all said, ad-blocking by the likes of https://pi-hole.net/ is more than just avoiding AD's, it's about privacy and more and more so - security.

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#99
post #35

I've been using this app for years and also telling other people to use it, so this sucks. If anyone else is looking for a replacement there's a Microsoft app called "Office Lens" that seems to do a really nice job and is as safe a bet as anything.

I've transitioned to using Adobe Scan a few months ago, and no complaints there

Re: CamScanner, a malicious Android app with more than 100M downloads in Google Play

#100
post #7

Just to clarify the headline: the app didn't have malware when most of the users installed it. A recent update added the malware.

That's not accurate, really. 100M+ users didn't install the thing overnight--they've downloaded it over the course of years. If they had it installed, and they had automatic updates turned on (which most people do), there was a several month window when they had a version of the app that contained malware, even if it was eventually removed.

Not sure how that's different from what I said, but yeah.
Post reply on HN