Join the Talk | 87,163 members - 319,866 posts Featured Stories |4G | Advertise | Have a scoop? Tip us!

Android users hit with data theft by malicious app

29 July 2010 by Shane McGlaun



The wait to get apps on the Apple App Store thanks to the long vetting process Apple uses on all apps allowed to run on the iPhone has been the source of much developer and user ire. That vetting process is looking good today after reports that millions of Android users may have had data stolen by a nefarious app.

AppleInsider reports that an app that was on the Android Market that offered custom background pictures was downloaded in the range of 1.1 million to 4.6 million times. The exact number of downloads is unknown because the data isn’t offered.

The app was actually a malicious program that collected the users browsing history, text messages, SIM card number, and voice mail password among other things. All of that data was then forwarded to servers in China. It’s not clear what the app was called, but if you downloaded anything like that, it’s time to change passwords.

  • Digg
  • Sphinn
  • del.icio.us
  • Facebook
  • Mixx
  • Google Bookmarks
  • Slashdot
  • SphereIt
  • Technorati
  • blogmarks
  • Blogosphere News
  • email
  • NewsVine
  • StumbleUpon
  • FriendFeed
  • Live
  • Reddit
  • Twitter
  • Wikio
  1. Wow!!! Are you cats pro or anti Android??? The app doesn't have permissions to do half of whats been claimed and the company Lookout had contacted other sites to tell them that they are overstating what the app can do.

    And the Apple vetting process doesn't look all that much better since a kid was able to sneak a tethering app into the market as a flashlight. So what else is in the Apple market that Apple doesn't know about. Apple only found out about that from outside. If you look at the article that this Android security story is coming from it also says that there are even more Apple apps getting access to your contacts and personal data behind the scenes than there are Android apps. On iOS you can't see what permissions the apps are asking for so there could potentially be all kinds of data theft going on in the walled garden. But I'd think an Android site would do a tiny bit of research first.
  2. So apple insider reported that an unknown wallpaper app was stealing data? I heard that some iPhone app might cause cancer when you install it, can't remember the name though. Wasn't there a blackberry app that would call you, and if you answer you die seven days later?
  3. Wow. An app this dangerous and the sites reporting it aren't naming it? WTF?

    It's like saying "4 million people bought poisoned meat at the store, but we don't know what kind of meat or what brand." Good way to scare folks.

    At least the first comment suggests a name of the company, but it's not clear what the app is.

    If the app's that bad, maybe Google would/should exercise that remote kill switch that made all the news a few weeks ago.

    As for the vetting process with Apple, talkbackdroid's right, who knows what's slipping past Apple given the multiple apps that have been pulled post-release because of things hidden in them that Apple didn't catch.

    However, Android's warnings about what access the app you're installing have are so overkill that the vast majority of users surely just say okay no matter what. After all, they want the app. Virtually every app I install pops up warnings about access to my data, hardware, whatever. I think this is false sense of security to think that these warnings are doing any good for the bulk of users.
  4. its great to start the day with a good laugh
  5. I don't buy the story from Apple Insider for one bit. No app name given and it would raise a pretty big red flag if a background app request all kind of access permission in the warning. Distortedloop does have a good point that most people won't look at the warning at all. At the end of the day, I'd be fine if it's like programs on windows, doing your own filtering.
  6. Yeah totally, WTH an app that does all that and no one is reporting which one....calling Bull****!! This is another antenna trick.

    sent from SVGS using the Almighty "Android" app
  7. I think we would all be in poor judgement to think this hasn't/won't happen, however as everyone has said the lack of information really makes this a dubious claim at best....
  8. Okay, Android Central has much more data on this, even screen shots of the app wallpaper. They look pretty cool! LOL.

    Anyways, it's wallpapers by jakeey. The guys who found the stuff are cautious to actually say malicious activity, but they're saying it's odd to have a wallpaper app phone home with your contact information. I certainly agree with that.
  9. Quote:
    Originally Posted by storm14k View Post
    The app doesn't have permissions to do half of whats been claimed and the company.
    Well, let's take the app called Backgrounds as an example. Now, for the record, I have NO idea if this is the app they're talking about.

    It can (among other things):
    • Read contact data.
    • Full internet access (this is the most important, see below).
    • Read SD contents (any app can do this without additional permissions).

    So as it stands right there, that's enough to grab all your contact information (names, address, date of births, pictures of them, etc), and everything on your SD card that includes stuff other apps store like caches of Tweets, emails, or anything else stored by an app if you use Apps2SD. It could then send all that to anywhere on the internet.

    But that's not all...

    Remember this article: http://androidandme.com/2010/06/news...eth-apps-away/

    Quote:
    the real purpose of the app was to expose [...] a security flaw and that is the ability to have an app retrieve new executable code without the users permission once it is installed.
    In other words, any app with full internet access can retrieve new executable code that can do anything it likes, and run it without the user ever being aware, as demonstrated by the app mentioned in the article I linked, and as removed by Google remotely using their remote REMOVE_ASSET command.

    Which brings me to my next point... if this were true, I'm sure Google would have used that REMOVE_ASSET features already, especially given their already strained relationship with China and user privacy.
  10. Quote:
    Originally Posted by extorian View Post
    Well, let's take the app called Backgrounds as an example. Now, for the record, I have NO idea if this is the app they're talking about.

    It can (among other things):
    • Read contact data.
    • Full internet access (this is the most important, see below).
    • Read SD contents (any app can do this without additional permissions).

    So as it stands right there, that's enough to grab all your contact information (names, address, date of births, pictures of them, etc), and everything on your SD card that includes stuff other apps store like caches of Tweets, emails, or anything else stored by an app if you use Apps2SD. It could then send all that to anywhere on the internet.

    But that's not all...

    Remember this article: http://androidandme.com/2010/06/news...eth-apps-away/



    In other words, any app with full internet access can retrieve new executable code that can do anything it likes, and run it without the user ever being aware, as demonstrated by the app mentioned in the article I linked, and as removed by Google remotely using their remote REMOVE_ASSET command.

    Which brings me to my next point... if this were true, I'm sure Google would have used that REMOVE_ASSET features already, especially given their already strained relationship with China and user privacy.
    And there u go people..knowledge. Info.. Use it, would u like your computer to restrict u? Or to b in control before of what u download? Imagine no choice of sites to visit or programs to download people... U r responsible. Or do u want to b told what to do? I know I don't

    "If ignorance is bliss..then knock the smile off my face" RATM

    U wouldn't believe the amount of people that d load blindly..


    Sent from my Nexus One using Android Community App
  11. Yup.. my brother got a new Droid X and was installing all sorts of new apps yesterday. He doesn't even look at permissions at all. I asked why not but he said who cares. They install so fast and all work fine. Not all android users are as smart or cautious as us enthusiasts. Ya know.

    He actually downloaded one of that guys apps last night. I just checked n uninstalled it. Then showed him the ppermissions. I doubt it will help.

    I work on computers and fix PCs for a part time job and you would be amazed at how much dumb **** and unsafe things people do and have on there computers.. as android gets bigger Google will need to implement some sort of approval process eventually. I'm guessing.

    Interesting story. Still seems pretty meh and overdone.
  12. Quote:
    Originally Posted by xguntherc View Post
    you would be amazed at how much dumb **** and unsafe things people do and have on there computers.
    I once spent two hours cleaning up a friend's computer. She had 4 free virus scanners on it, about 100 toolbars in I.E., and a virtual pet dog that hops around the desktop eating icons if you don't feed it every 5 minutes. The free virus scanners weren't doing much, because it was riddled with spyware and viruses, which my commercial AV program detected and removed.

    Anyway, she sat down to view a few web pages. Including one I've never even heard of before that she used to find torrents, which can only be downloaded if you click a bunch of adverts. Of course her browser popped up a security warning. Did she read it? Did she click Cancel? Did she hell! I watched in HORROR as she quickly (very practised, you see) clicked Accept, and then when Windows popped up its access control warning she instantly clicked on Continue to allow it to run as Admin. She then started complaining that "It's doing that thing again!".
  13. Hahaha

    Sent from my Nexus One using Android Community App
  14. People like that should have to pass a test to use a computer!
  15. There's more information on this here: http://gizmodo.com/5599435/over-1m-a...-malicious-app

    And all we know is the author of the app is "jackeey,wallpaper". You can see a list of all of their apps here: http://www.androidzoom.com/android_d...aper_bofz.html
  16. Quote:
    Originally Posted by extorian View Post
    There's more information on this here: http://gizmodo.com/5599435/over-1m-a...-malicious-app

    And all we know is the author of the app is "jackeey,wallpaper". You can see a list of all of their apps here: http://www.androidzoom.com/android_d...aper_bofz.html
    Ur kidding me, 4 pages of wallpaper apps lol, y don't people just google an image? buggs me...

    Sent from my Nexus One using Android Community App
  17. Seems it was all a load of crap anyway. Google have investigated it and returned the app to the Market. http://gizmodo.com/5605160/google-re...android-market

Android Phone Accessories


Content Delivery Network
T-Mobile G1 Accessories
Palm Pre Accessories

© 2010 Android Community. Part of R3 Media Network

Contact | Advertising | About Us