6 ms·
This isn't really malware in the traditional sense, it doesn't damage users of the app itself or harvest information from them, this is simply ad fraud, it only
by problems 9y ago
This isn't really malware in the traditional sense, it doesn't damage users of the app itself or harvest information from them, this is simply ad fraud, it only damages Google and its advertisers.
It seems to me like CheckPoint is fishing for internet points with this title.
- yeukhon 9y agoWell malware has many categories and one is adware.
- bobsam 9y agoIf I read the article correct it downloads JavaScript code to load ad pages. It never bypassed the sandbox. I don't think you can call this malware
- openasocket 9y agoI work in the security space, and I would definitely consider this malware. Generally, any software used with a malicious purpose is considered malware. As an example, keyloggers generally aren't exploiting any vulnerability (though malware often uses a vulnerability to install the keylogger in the first place), they're using the standard functionality of the computer as intended, but with malicious intent, and so keyloggers are considered malware. It's not breaking out of the sandbox, but it turns out the sandbox is a pretty big place with a lot of room to do what it wants, so why bother trying to break out?
- problems 9y agoYeah, technically I can see it as malware, but not really in the same way... keyloggers obviously harm the user in collecting data against them, there's no malicious intent against the user here. This is only a minor increase over the already quite nasty but common mobile advertising practices. In fact, I'd argue the information harvesting most mobile ad networks do is much more harmful than this click fraud. Do we ban all of those as malware too? Most them don't mention that they send things like unique device identifiers, connected wifi networks or Google account information.
- wnevets 9y ago>there's no malicious intent against the user here Eating up their battery/resources running hidden code that pretends to be them is kinda malicious. I also count hidden bitcoin miners as malicious.
- problems 9y agoFor sure, but any extra battery and resource consumption here would be extremely minor compared to a bitcoin miner. Many apps do various forms of push advertising and background reporting which does quite similar things, do you consider that to be malware too? Ultimately the only difference here is that this one abuses Google and their advertisers instead of the user, which seems to be an accepted and common advertising practice. In my opinion at least, it's not significantly different from those behaviors.
- yeukhon 9y agoWhat if this is a self-modifying code? Now instead of clicking ad now DoDDS? Malicious is basically bad intent. This is an unauthorized activity so it is malicious.
- problems 9y agoIt's not self-modifying code, it's looking specifically for google.com frames, see the source in the link. This is hardly worse intent than any other mobile ad these days.
- cortesoft 9y agoIsn't that all ads, then? I mean, as an end user, which is more harmful to you - downloading a bunch of ads and filling your screen with them, or downloading a bunch of ads and not displaying them? You are going to use more battery and resources actually displaying the ads, not to mention the worse user experience. If I had to pick between the two, I would prefer 'download and don't display' over 'download and display'
- bobsam 9y ago> keyloggers generally aren't exploiting any vulnerability That's a very odd definition you have. Rest assured, nobody is saying this kind of apps are acceptable. But calling them malware is not right when they technically don't use more than they been given access to (network + some cpu time)?
- openasocket 9y agoWhich part is odd? You can use standard APIs like GetAsyncKeyState() or various utilities for screen scraping and reading the paste buffer to make a key logger, no vulnerabilities required. We still consider such a thing malware of course. The point is exploiting vulnerabilities is not a necessary condition for something to be considered malware.
- yeukhon 9y agoHe's probably referring to injecting/deploying the keylogger in the first place. Either it came with a malicious software, via a system exploit, or someone installed it having physical access.
- openasocket 9y agoOr, like in the case of Judy, people installed it willingly, because it was hidden inside a game. If a game or some sort of application people install on their machine had a key logger component, we'd consider that malware, and still no vulnerabilities needed, just basic social engineering.
- dafrankenstein2 9y agoagree
- TylerE 9y agoSo if I'm on a metered data connection, getting hit with would result in...?
- problems 9y agoProbably not much more than viewing a few ads in the first place. They can't cheat that hard or they'll get caught.
- rhizome 9y agoA sandbox bypass would be an exploit, much more severe than malware.
- wnevets 9y agoI gotta agree, even tho technically it is malware.
- astrodust 9y agoIt's malware in the traditional sense: "Programs that do things you wouldn't expect or authorize them to do that are harmful either to yourself or to others."
- eternalban 9y agoI certainly didn't "expect" (nor ever authorize) my browser to maintain open SSL connections to servers in googleplex sending them God knows what. Does that mean Chrome is malware, too?
- whatshisface 9y agoWe'd probably be a lot further along if we all considered greasy hidden behaviors just as bad as greasy hidden behaviors written by those who don't pay taxes.
- RKearney 9y agoIf it makes you feel any better, Google hasn't supported SSL for some time. Open TLS connections on the other hand, well now that's a different story.