15 ms·
The Judy Malware: Possibly the largest malware campaign found on Google Play
- samdung 9y agoAndroid is the new Windows. Expecting some downvotes. But truth must be told. You're welcome.
- BoorishBears 9y agoPart of the issue is how lax attitudes are in mobile development when it comes to security. There are probably dozens of top apps out there that have insecure command and control type setups
- bluetwo 9y agoMaybe the Apple "walled garden" keeps the animals from eating your fruit.
- ge96 9y agoPartly related to ads I heard of something with Apple, somebody was able to change the checksum or something to an Apple app before it was submitted to a store and all the ad revenue went to that person. It was on a podcast I heard a few month(s) ago.
- bobsam 9y agoThat happens on a daily basis, on both stores. There is no way either company can manually inspect billion+ apps plus their updates. So they are putting AI in charge which people seem to ba able to fool once in a while.
- problems 9y agoNot really the truth - Android apps are all sandboxed and have relatively little access. In fact the only thing this oh-so-evil malware did was generate fake Google Ad clicks. Not really an offense against its users at all and it can be trivially uninstalled. I certainly wouldn't compare that to ransomware, DDoS botnets, search hijackers, etc that deeply nest themselves in your system and resist uninstallation so much that reinstalling the OS is often the suggested recovery option.
- freeflight 9y ago>I certainly wouldn't compare that to ransomware, DDoS botnets, search hijackers, etc that deeply nest themselves in your system and resist uninstallation so much that reinstalling the OS is often the suggested recovery option. Lot's of adware can be equally sticky because it keeps on loading new crap on the system if you just miss it in one place. Tbh the worst disaster system I've seen usually involved adware, sure it's not a total data loss but I'd guess it's far more widespread than ransomware. And I'd consider any behavior, that's not approved by the user, as an offense against the user. After all, this stuff is taking up resources that otherwise wouldn't be used (traffic, memory, CPU cycles and as such battery) I also consider having random ads pop up, with no way around them except clicking them, pretty offensive behavior towards the user. This stuff might, for now, be rather easy to uninstall but nobody can guarantee that won't change in the future and infected phones end up in a similar bad state like Windows systems with sticky adware infections.
- problems 9y ago> Lot's of adware can be equally sticky because it keeps on loading new crap on the system if you just miss it in one place. Tbh the worst disaster system I've seen usually involved adware, sure it's not a total data loss but I'd guess it's far more widespread than ransomware. Important to note that you're talking on Windows here. On Android it can't do anything of the sort. > And I'd consider any behavior, that's not approved by the user, as an offense against the user. After all, this stuff is taking up resources that otherwise wouldn't be used (traffic, memory, CPU cycles and as such battery) Nasty advertising practices are already quite common in the mobile world, compare with the apps that do push ads, notifications for in app purchases, full screen ads that are hard to click off, etc. > This stuff might, for now, be rather easy to uninstall but nobody can guarantee that won't change in the future and infected phones end up in a similar bad state like Windows systems with sticky adware infections. Short of sandbox breakouts becoming rampant - which would surely get noticed quickly - it can be guaranteed this will never become a concern on Android or any similar platform.
- yeukhon 9y agoAndroid permission has been critized for many years. Not sure if Google has done anything to address.
- ocdtrekkie 9y agoThey've done a little bit. Newer Android versions support setups where apps request permissions at runtime, instead of just having them all the time in the background. But the permissions are still too wide. Things like giving apps access to all your contacts, as opposed to having the OS only provide one contact, after the user picks it from a list.
- lallysingh 9y agoThere's a tradeoff in usability. I do wish Google (or a phone vendor! add real value!) would let users choose fine-grained or coarse-grained security at the UI level, and let developers just use fine-grained permissions APIs.
- ocdtrekkie 9y agoThere really isn't a tradeoff. Bad security: App requests all your contacts and shows you a list of people you can invite to play Candy Crush. The user clicks one, but the app already has access to all of them. Good security: App requests a contact and the OS shows you a list of people you can invite to play Candy Crush. The user clicks one and the OS gives that contact info to the app. The user experience is quite similar, but the security design is far better.
- chickenbane 9y agoAt Google IO they just announced Android has 2B active devices, which makes it easily the largest platform today, must larger than Windows ever was. If you remember the bad days of ILOVEYOU or SqlSlammer, I think Android is much safer. Or compare this Judy with WannaCry. Don't believe the hype. You're welcome.
- bitmapbrother 9y agoNo, nothing can ever wash off the stank and damage done by Windows. When Android starts shutting down hospitals, holding companies for ransom, crippling foreign centrifuges then we can have this conversation. Until then we're just waiting for the next Windows armageddon.
- spcelzrd 9y agoThere will always be bad actors, but I can't understand why Google tolerates low level malware. At least make them work a little.
- Cyph0n 9y agoThis is the kind of malware that is difficult to block imo. As long as the auto clicking is done at a suitable interval, there really is no easy way to detect it. The question is: would such an attack work on Apple devices? I'm assuming that the iOS API provides similar functionality to apps running on the device.
- JKCalhoun 9y agoI would expect the malware developers already to have targeted iOS if it were possible?
- flashdance 9y agoThere are over twice as many android devices as ios devices, so if you're a malware creator it might make sense only to target the biggest fish.
- mtgx 9y agoThis is why no matter how much Google brags about its machine learning-powered anti-malware protection, it can't rely solely on it to defend Android users, because it's still a cat and mouse game with sophisticated attackers. They need to find a way to patch all devices in a timely manner.
- openasocket 9y agoThis isn't really an issue with a vulnerability, AFAICT. The App is basically just automatically clicking ads in the background. I'm not sure there's an easy way to prevent this from happening at the end user level, except by static and dynamic analysis on the part of Google to keep the Play store free of malicious Apps.
- ry_ry 9y agoIt'd be obvious on the ads side though - If this was activated across multiple apps simultaneously, their clickthrough rate would have gone through the roof. Heck, even if it was dripped out slowly, average % clickthrough - even on mobile where ads get fat fingered more often - is a tiny fraction of views. They would have been reporting some pretty crazy numbers. No way in the world this wasn't easily spotted, when clickfraud is already a well known thing and Google are in the business of tracking things to sell more ads.
- michaelbuckbee 9y agoI'm curious if anyone has a sense for how much they made from this? I just don't have a good sense for scale and dimensions of this. If it went undetected for so long they must not have been at least somewhat conservative in their approach, so say 5mil DAU times 1 click a day at $0.25/click. So, million-ish dollars a day?
- H1Supreme 9y agoSo, this was an ad-referral click of some sort (article doesn't say)? AdWord clicks generate revenue for Google, not advertisers.
- bobsam 9y agoFTA: Upon clicking the ads, the malware author receives payment from the website developer, which pays for the illegitimate clicks and traffic
- UseofWeapons1 9y agoPer a Forbes article on the subject [0] "Check Point estimated the firm was making millions from the ad clicks, in the region of $300,000 per month." I imagine your price per click is over-estimated by a couple orders of magnitude, but that's just a guess. [0] https://www.forbes.com/sites/thomasbrewster/2017/05/26/google-shuts-down-massive-ad-fraud-on-play-store/#780741487807 https://www.forbes.com/sites/thomasbrewster/2017/05/26/googl...
- ChuckMcM 9y agosomewhere between $250K - $400K a month seems to be the thoughts of various open sources on the matter. That would put it in the $3 - $5 million per year at its peak. Assuming their play took a while to ramp up maybe $25 million total? Google makes more than $25B/year in revenue so even with a 30/70 payout (30 percent to the fraudsters) maybe .001% of Google's ad revenue? And that is why people do this stuff. Other than getting booted off the store nothing else will happen to these people who just made tens of millions of dollars.
- problems 9y agoThis isn't really malware in the traditional sense, it doesn't damage users of the app itself or harvest information from them, this is simply ad fraud, it only damages Google and its advertisers. It seems to me like CheckPoint is fishing for internet points with this title.
- yeukhon 9y agoWell malware has many categories and one is adware.
- bobsam 9y agoIf I read the article correct it downloads JavaScript code to load ad pages. It never bypassed the sandbox. I don't think you can call this malware
- openasocket 9y agoI work in the security space, and I would definitely consider this malware. Generally, any software used with a malicious purpose is considered malware. As an example, keyloggers generally aren't exploiting any vulnerability (though malware often uses a vulnerability to install the keylogger in the first place), they're using the standard functionality of the computer as intended, but with malicious intent, and so keyloggers are considered malware. It's not breaking out of the sandbox, but it turns out the sandbox is a pretty big place with a lot of room to do what it wants, so why bother trying to break out?
- problems 9y agoYeah, technically I can see it as malware, but not really in the same way... keyloggers obviously harm the user in collecting data against them, there's no malicious intent against the user here. This is only a minor increase over the already quite nasty but common mobile advertising practices. In fact, I'd argue the information harvesting most mobile ad networks do is much more harmful than this click fraud. Do we ban all of those as malware too? Most them don't mention that they send things like unique device identifiers, connected wifi networks or Google account information.
- smilliken 9y agoIt looks like the common component across the apps mentioned is in the "net.shinhwa21.jsylibrary" namespace. I made a list of the apps with that namespace, preview here: https://mixrank.com/playstore/apps?expiration=2017-06-30&list.id=8ce2b11ce0&sharedby=scott%40deltaex.com&auth=5130e518573dd928 https://mixrank.com/playstore/apps?expiration=2017-06-30&lis... This list is a few times bigger than the ones mentioned in the article (been crawling for a long time, and try to be complete). If there's any security folks here that want access to the APKs for research, I'm happy to share (scott at mixrank).
- tyingq 9y agoNice work. Odd that you would be ahead of Google though. They pulled only the apps mentioned in the article so far.
- damienkatz 9y agoCould be that legit apps have legit versions of those components.
- jwoloz 9y agoWould you mind sharing the digests of the apps you discovered, only ten are visible and it looks like there are multiple steps to set up a mixrank account
- elliottcarlson 9y ago"Some of the apps we discovered resided on Google Play for several years, but all were recently updated. It is unclear how long the malicious code existed inside the apps, hence the actual spread of the malware remains unknown." If these apps were indeed popular, I would imagine the historical APK's are available for the various versions on pirate sites. Simply performing a Google search for "Fashion Judy: Snow Queen style apk" shows downloads for different versions of it. This can give a better idea of the length of infection.
- userbinator 9y agoUpon clicking the ads, the malware author receives payment from the website developer, which pays for the illegitimate clicks and traffic. Are they really certain of this, or could it just be the work of someone who wants to "poison the well" of Google's ad network data collection? It somehow reminds me of https://news.ycombinator.com/item?id=10611594 https://news.ycombinator.com/item?id=10611594 (Would CheckPoint also consider that malware?)
- weeks 9y agoIf the user isn't informed the app they installed is clicking on ads, it absolutely is malware.