8 ms·
2FA app with 10k Google Play downloads loaded well-known banking trojan
- connordoner 5y ago…Yikes.
- austincheney 5y agoI work for a bank. This is why we ship our own 2FA app.
- alamortsubite 5y agoAn honest yet pointed question: what permissions does your bank's 2FA app request? My guess is, as a bank, they're doing the right thing. However, permissions overreach is a real issue that even "legitimate" apps are exploiting to vacuum as much user data as possible.
- moviuro 5y ago> My guess is, as a bank, they're doing the right thing Banks can and will do everything wrong. * https://reports.exodus-privacy.eu.org/en/reports/fr.creditagricole.androidapp/latest/ https://reports.exodus-privacy.eu.org/en/reports/fr.creditag... * https://reports.exodus-privacy.eu.org/en/reports/fr.lcl.android.customerarea/latest/ https://reports.exodus-privacy.eu.org/en/reports/fr.lcl.andr... * https://reports.exodus-privacy.eu.org/en/reports/com.caisseepargne.android.mobilebanking/latest/ https://reports.exodus-privacy.eu.org/en/reports/com.caissee... * https://reports.exodus-privacy.eu.org/en/reports/fr.banquepopulaire.cyberplus/latest/ https://reports.exodus-privacy.eu.org/en/reports/fr.banquepo... * https://reports.exodus-privacy.eu.org/en/reports/com.fullsix.android.labanquepostale.accountaccess/latest/ https://reports.exodus-privacy.eu.org/en/reports/com.fullsix...
- austincheney 5y agoWhat solution would you recommend? Strangely, those are all banks I have never heard of. My employer had no search results on that site. I guess they aren't doing everything wrong.
- matheusmoreira 5y ago> My guess is, as a bank, they're doing the right thing. In my country, banks used to mandate use of a "security module". I decided to see what this thing was doing and caught it intercepting every single network connection.
- ncmncm 5y agoI will not install your sketchy app. Do you supply source and repeatable build info?
- throwawayboise 5y agoExactly. I would never ever install a bank's app on my phone. Aside from almost certainly being closed-source it was probably developed by the cheapest off-shore bidder for the project. But who knows? That's the point. They won't tell you anything because they "take security very seriously."
- somevar 5y agowhat a nightmare, imagine a unique 2FA app for every account!
- crtasm 5y agoIf I put up an app that looks like yours how quickly will it be noticed by your bank/google?
- encryptluks2 5y agoMy bank's 2FA consist of text verification which has notable issues.
- kosasbest 5y agoRight now, Google Play is the wild west. The app store admins are far too lenient when it comes to things like this. No vetting of apps. No inspection of source code for red flags. And the sketchy apps can be rated five stars by a bunch of bots artificially inflating its popularity. Clown show.
- sebzim4500 5y agoAre there any app stores where the developer needs to submit the source code for inspection?
- dane-pgp 5y agoWould it be unreasonable to answer that with "F-Droid"? I guess the implicit (and reasonable) assumptions of your question are that the source code is fully reviewed by the people running the app store, and it is a "store" in the sense that people routinely pay money for the apps available there.
- myko 5y ago> No vetting of apps. This is not true, apps are reviewed now. IMO this is theater and useless, though. > No inspection of source code for red flags. This is also untrue, Google scans apps for known malware. Not sure how this was missed, though. > And the sketchy apps can be rated five stars by a bunch of bots artificially inflating its popularity. This is true. It's also a problem on the App Store and similar sites. The App Store is not immune to these issues, either: https://twitter.com/jonathandata1/status/1486458526767661060 https://twitter.com/jonathandata1/status/1486458526767661060
- joshstrange 5y agoI know the App Store isn't immune but I'm having a hard time remembering a time when an app on iOS was reaching into other app's data or doing something like a keylogger system-wide. Often it's things like "It's listening to you, grabbing your clipboard, etc". While far from "good" or "ok", it's a far cry from some random app being able to steal my banking session.
- baobabKoodaa 5y agoSo much for the walled garden. Remind me again, what is Google offering in exchange for their 30% cut?
- Saris 5y agoYou would think if googles malware scanning was doing anything useful it would have flagged this purely because of the wide permissions it requests.
- paulpauper 5y ago"malware scanning" it is trivially easy to evade scanning -obfuscation -renaming -a long web of external obfuscated files -a blank or unregistered domain which is activated and calls a script as soon as it goes live (this is the most effective way)
- UncleMeat 5y agoCloaking is real but is itself a fun signal. Most apps (outside of the chinese market) don't use cloaking so observing behavior that seems like cloaking can be strong signal that an app is malicious even if you cannot determine what the behavior actually is.
- deleted 5y ago[deleted]
- gruez 5y agoHalf of the "extraordinary number and breadth of system permissions it required" listed in the article seem benign * android.permission.INTERNET * android.permission.FOREGROUND_SERVICE * android.permission.RECEIVE_BOOT_COMPLETED * android.permission.WAKE_LOCK The rest are fishy, but not really anything that facilitates a virus. * android.permission.QUERY_ALL_PACKAGES - allows you to enumerate what apps are installed * android.permission.SYSTEM_ALERT_WINDOW - google says it's used for overlays. for a TOTP app this seems plausible for stuff like showing the code while you're entering it into the app that's requesting it * android.permission.REQUEST_INSTALL_PACKAGES - I'm not even sure what this permission does. You can install an apk from chrome/firefox, which doesn't have this permission. * android.permission.DISABLE_KEYGUARD - disables lockscreen. unless the attacker also has physical access, this is pointless.
- bigyellow 5y agoLet's definitely not put the name of the app in the title, so people are forced to visit our shitty site loaded with dozens of tracking domains and scripts.
- alexbakker 5y agoIt sucks to see your open source work being abused like this, and there's seemingly nothing we can do about it. Every now and then I scour the play store to see if I can find any Aegis clones. We've reported a couple that didn't have a link to the source code and/or were linking proprietary libraries (as per our license), but they're still up. Of course, those cases aren't as bad as this one where actual malware was included, but it's pretty telling about the state of the Google Play Store.
- sschueller 5y agoEither way Google should be contacting the relevant police in the country the owner of the account lives. A developer account is not free so someone had to pay, if the credit card was stolen then also report that to Visa etc. If Google doesn't have enough information then maybe they should require a government ID to get a developer account. I mean Facebook requires ID for some users.
- Aulig 5y agoIf deemed high-risk, Google already asks for proof of identity whe registering a developer account
- 0xdeadb00f 5y agoAegis is my TOTP app of choice! Keep up the great work, I really love it.
- alexbakker 5y agoGlad to hear you like it!
- butz 5y agoOpen source app includes link to donation page? Ban! And disable their account while at it. Shady 2FA app? Keep it, what harm can it do?
- tramtrist 5y agoNot to be confused with: https://2fas.com/ https://2fas.com/ https://play.google.com/store/apps/details?id=com.twofasapp https://play.google.com/store/apps/details?id=com.twofasapp Right?
- Cwizard 5y agoI looked into using this app a while back because I liked the UI. But Im a bit hesitant because the app is completely free (and no ads) just wonder what the incentive is for them? Anyone have any idea on who made this?
- tramtrist 5y agoHopefully this explains it... https://twitter.com/2FAS_com/status/1487063320804929537 https://twitter.com/2FAS_com/status/1487063320804929537
- 12ian34 5y agoif you're on Android I'd strongly recommend Aegis via F-Droid.
- ncmncm 5y agoThey don't say it is on FDroid. Figures, as they would have had to provide source code, and FDroid would build it themselves. With all those permissions it demands, people must have reported it earlier.
- bityard 5y agoFor those who can't be bothered to click, the name of the app is "2FA Authenticator".
- xroche 5y agoRemoved from Google Play. But what about the users who fell in the trap ? Will the app be removed automatically ?
- richij 5y agoYes, it should automagically go into the Play Protect blocklist: https://support.google.com/android/answer/2812853 https://support.google.com/android/answer/2812853
- throwawayboise 5y agoMy rule is that I never install an app from a small publisher. I only install apps from Google, or other large established publishers. I know they all spy on me, but I do trust that they won't steal my bank credentials and drain my accounts. Another bit of advice, never do banking on your phone.
- jpeter 5y agoAre there really Banking trojans in Android? I thought malocious apps can't access data of other apps because everything is sandboxed
- mdp2021 5y agoE.g. through VNC. Which is the case of Vultur, which is the relevant case of this contaminated 2FA app. https://arstechnica.com/gadgets/2021/07/new-bank-fraud-malware-called-vultur-infects-thousands-of-devices/ https://arstechnica.com/gadgets/2021/07/new-bank-fraud-malwa... > Vultur is among the first Android threats to record a device screen whenever one of the targeted apps is opened. Vultur uses a real implementation of the VNC screen-sharing application to mirror the screen of the infected device to an attacker-controlled server > The typical modus operandi for Android-based bank-fraud malware is to superimpose a window on top of the login screen presented by a targeted app. The “overlay,” as such windows are usually called, appears identical to the user interface of the banking app, giving victims the impression they’re entering their credentials into a trusted piece of software. Attackers then harvest the credentials, enter them into the app running on a different device, and withdraw money (Also: some disable sandboxing through rooting - yet do not use the device consistently)
- josephcsible 5y agoBut all the big scary warnings when I enabled sideloading told me that only getting apps from the Play Store would protect me from this!