Google deletes 29 malicious ‘beauty camera’ apps that steal user information

Agencies
February 4, 2019

Google has deleted 29 malicious "beauty camera" apps that were sharing pornographic content and forwarding users, particularly in India, to phishing websites to steal their information.

Some of these Android apps have been downloaded millions of times and a large number of the download counts originated from Asia -- particularly in India, said a report from US-based cyber security firm Trend Micro.

The apps have now been removed by Google from the Play Store.

"A user downloading one of these apps will not immediately suspect that there is anything amiss, until they decide to delete the app," said Trend Micro.

The app will push several full screen ads when users unlock their devices, including malicious ads (such as fraudulent content and pornography) that will pop up via the user's browser.

"During our analysis, we found a paid online pornography player that was downloaded when clicking the pop up," the report added.

None of these apps gave any indication that they were the ones behind the ads, thus users might find it difficult to determine where they're coming from.

Some of these apps redirected to phishing websites that asked the user for personal information, such as addresses and phone numbers.

"For example, the package com.beauty.camera.project.cloud will create a shortcut after being launched. However, it will hide its icon from the application list, making it more difficult for users to uninstall the app since they will be unable to drag and delete it," Trend Micro noted.

Furthermore, the camera apps used packers to prevent them from being analysed.

In the past too, Google has detected several fake apps on its platforms, which it has deleted. Most recently, a malware expert unearthed 15 fake navigation apps with adware and these apps had over 50 million installations. However, after this was revealed, Google removed the malicious apps.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
January 3,2020

Giving each and every app access to personal information stored on Android smartphones such as your contacts, call history, SMS and photos may put you in trouble as bad actors can easily use these access to spy on you, send spam messages and make calls anywhere at your expense or even sign you up for a premium "service", researchers from cybersecurity firm Kaspersky have warned.

But one can restrict access to such information as Android lets you configure app permissions. 

Giving an app any of these permissions generally means that from now on it can obtain information of this type and upload it to the Cloud without asking your explicit consent for whatever it intends to do with your data.

Therefore, security researchers recommend one should think twice before granting permissions to apps, especially if they are not needed for the app to work. 

For example, most games have no need to access your contacts or camera, messengers do not really need to know your location, and some trendy filter for the camera can probably survive without your call history, Kaspersky said. 

While decision to give permission is yours, the fewer access you hand out, the more intact your data will be.

Here's what you should know to protect your data.

SMS: An app with permission to send and receive SMS, MMS, and WAP (Wireless Application Protocol) push messages, as well as view messages in the smartphone memory will be able to read all of your SMS correspondence, including messages with one-time codes for online banking and confirming transactions.

Using this permission, the app can also send spam messages in your name (and at your expense) to all your friends. Or sign you up for a premium "service." You can see and conrol which apps have these rights by going to the settings of your phone.

Calendar: With permission to view, delete, modify, and add events in the calendar, prying eyes can find out what you have done and what you are doing today and in the future. Spyware loves this permission.

Camera: Permission to access the camera is necessary for the app to take photos and record video. But apps with this permission can take a photo or record a video at any moment and without warning. Attackers armed with embarrassing images and other dirt on you can make life a misery, according to Kaspersky.

Contacts: With permission to read, change, and add contacts in your address book, and access the list of accounts registered in the smartphone, an app can send your entire address book to its server. Even legitimate services have been found to abuse this permission, never mind scammers and spammers, for whom it is a windfall.

This permission also grants access to the list of app accounts on the device, including Google, Facebook, and many other services.

Phone: Giving access to your phone means permission to view and modify call history, obtain your phone number, cellular network data, and the status of outgoing calls, add voicemail, access IP telephony services, view numbers being called with the ability to end the call or redirect it to another number and call any number.

This permission basically lets the app do anything it likes with voice communication. It can find out who you called and when or prevent you from making calls (to a particular number or in general) by constantly terminating calls. 

It can eavesdrop on your conversations or, of course, make calls anywhere at your expense, including to pay-through-the-nose numbers, Kaspersky warned.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
June 30,2020

Washington, Jun 30: Researchers in China have discovered a new type of swine flu that is capable of triggering a pandemic, according to a study published Monday in the US science journal PNAS.

Named G4, it is genetically descended from the H1N1 strain that caused a pandemic in 2009.

It possesses "all the essential hallmarks of being highly adapted to infect humans," say the authors, scientists at Chinese universities and China's Center for Disease Control and Prevention.

The researchers then carried out various experiments including on ferrets, which are widely used in flu studies because they experience similar symptoms to humans -- principally fever, coughing and sneezing. 

G4 was observed to be highly infectious, replicating in human cells and causing more serious symptoms in ferrets than other viruses.

Tests also showed that any immunity humans gain from exposure to seasonal flu does not provide protection from G4.

According to blood tests which showed up antibodies created by exposure to the virus, 10.4 percent of swine workers had already been infected.

The tests showed that as many as 4.4 percent of the general population also appeared to have been exposed.

The virus has therefore already passed from animals to humans but there is no evidence yet that it can be passed from human to human -- the scientists' main worry.

"It is of concern that human infection of G4 virus will further human adaptation and increase the risk of a human pandemic," the researchers wrote.

The authors called for urgent measures to monitor people working with pigs.

"The work comes as a salutary reminder that we are constantly at risk of new emergence of zoonotic pathogens and that farmed animals, with which humans have greater contact than with wildlife, may act as the source for important pandemic viruses," said James Wood, head of the department of veterinary medicine at Cambridge University.

A zoonotic infection is caused by a pathogen that has jumped from a non-human animal into a human.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
March 11,2020

New Delhi, Mar 11: According to the Union health ministry, there are 62 confirmed cases of coronavirus in the country.

The Delhi High Court Wednesday sought the stand of the Centre and the Delhi government on a PIL seeking proper and adequate measures to combat coronavirus.

A bench of Chief Justice D N Patel and Justice C Hari Shankar issued notice to the Ministry of Health and the Delhi government seeking their replies on the public interest litigation (PIL) filed by an advocate.

The petition, by lawyer Triveni Potekar, seeks directions to the Centre and the Delhi government to make available important and relevant information on access to and availability of medical facilities for testing and treatment for the coronavirus disease.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.