Google deletes 29 malicious ‘beauty camera’ apps that steal user information

Agencies
February 4, 2019

Google has deleted 29 malicious "beauty camera" apps that were sharing pornographic content and forwarding users, particularly in India, to phishing websites to steal their information.

Some of these Android apps have been downloaded millions of times and a large number of the download counts originated from Asia -- particularly in India, said a report from US-based cyber security firm Trend Micro.

The apps have now been removed by Google from the Play Store.

"A user downloading one of these apps will not immediately suspect that there is anything amiss, until they decide to delete the app," said Trend Micro.

The app will push several full screen ads when users unlock their devices, including malicious ads (such as fraudulent content and pornography) that will pop up via the user's browser.

"During our analysis, we found a paid online pornography player that was downloaded when clicking the pop up," the report added.

None of these apps gave any indication that they were the ones behind the ads, thus users might find it difficult to determine where they're coming from.

Some of these apps redirected to phishing websites that asked the user for personal information, such as addresses and phone numbers.

"For example, the package com.beauty.camera.project.cloud will create a shortcut after being launched. However, it will hide its icon from the application list, making it more difficult for users to uninstall the app since they will be unable to drag and delete it," Trend Micro noted.

Furthermore, the camera apps used packers to prevent them from being analysed.

In the past too, Google has detected several fake apps on its platforms, which it has deleted. Most recently, a malware expert unearthed 15 fake navigation apps with adware and these apps had over 50 million installations. However, after this was revealed, Google removed the malicious apps.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
July 9,2020

New Delhi, Jul 9: The Central Board of Secondary Education has strongly defended its decision to drop topics like democratic rights, citizenship, federalism, secularism etc in the name of reducing the syllabus for Classes 9 to 12 due to COVID-19 pandemic. 

The board has claimed that the dropped lessons "are either being covered by the rationalised syllabus or in the Alternative Academic Calendar of NCERT".

The CBSE said it had to come up with the clarification after realizing its decision was "interpreted differently".

"The rationalisation of syllabus up to 30 per cent has been undertaken by the Board for nearly 190 subjects of class 9 to 12 for the academic session 2020-21 as a one-time measure only. The objective is to reduce the exam stress of students due to the prevailing health emergency situation and prevent learning gaps," it said.

While it has said that no questions can be asked from the reduced syllabus in the next board exams, the CBSE has also directed schools to follow alternative calendars prepared by the NCERT.

"Therefore each of the topics that have been wrongly mentioned in media as deleted have been covered under Alternative Academic Calendar of NCERT which is already in force for all the affiliated schools of the Board," it clarified.

On Wednesday, West Bengal CM Mamata Banerjee tweeted: "Shocked to know that the central Government has dropped topics like citizenship, federalism, secularism and partisan in the name of reducing CBSE course during the COVID crisis."

"We strongly object to this and appeal the HRD Ministry to ensure these vital lessons aren't curtailed at any cost," Banerjee added.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
May 22,2020

Kochi, May 22: During the nationwide COVID-19 lockdown, Kerala recorded the highest number of cyber attacks followed by Punjab and Tamil Nadu, a study by anti-virus software firm K7 Computing said on Thursday.

In a statement issued in Chennai, the company said its K7 Computing's Cyber Threat Report, a comprehensive analysis of cyber attacks during the lockdown has found that Kerala recorded the highest number of cyber attacks during this period. The report analyses various cyber attacks within India during the pandemic and reveals that threat actors targeted the state with COVID-themed attacks aimed at exploiting user trust.

In Kerala, regions like Kottayam, Kannur, Kollam, and Kochi saw the highest hits with 462, 374, 236, and 147 attacks respectively, while the state as a whole saw around 2,000 attacks during the period - the highest thus far in the country.

This was followed by Punjab with 207 attacks and Tamil Nadu with 184 attacks, the company said.

The sudden surge in the frequency of attacks witnessed from February 2020 to mid-April 2020 indicates that scamsters across the world were exploiting the widespread panic around coronavirus at both the individual and corporate level.

These attacks aimed to compromise computers and mobile devices to gain access to users' confidential data, banking details, and cryptocurrency accounts.

The key threats seen during this period ranged from phishing attacks to rogue apps disguised as COVID-19 information apps that targeted users' sensitive data. Phishing attacks were noticed more in Tier-II and Tier-III cities while the metros fared better. Smaller cities saw over 250 attacks being blocked per 10,000 users.

Users from Ghaziabad and Lucknow seem to have faced almost 6 and 4 times the number of attacks as Bengaluru users.

According to the statement, a majority of the recorded attacks were phishing attacks with sophisticated campaigns that could easily snare even the most educated users. These attacks were aimed at heightening users' fears and creating a sense of urgency to take action.

K7 Labs noticed phishing attacks where scamsters posed as representatives of the United States Department of Treasury, the World Health Organization (WHO), and the Centres for Disease Control and Prevention (CDC), the company said.

Users were encouraged to visit links that would automatically download malware on the host computer such as the Agent Tesla keylogger or Lokibot information-stealing malware, infamous banking Trojans such as Trickbot or Zeus Sphinx, and even disastrous ransomware.

Other attacks included infected COVID-19 Android apps like CoronaSafetyMask that scam users with promises of masks for an upfront payment; the spyware app Project Spy; and seemingly genuine apps that are infected with dangerous malware like banking Trojans such as Ginp, Anubis and Cerberus.

"Covid-19 has created an ideal situation for various threat actors to target individuals and enterprises alike. The panic caused by the stringent lockdown measures and rapid spread of this virus has left many people looking for more information on the situation," J. Kesavardhanan, Founder and CEO of K7 Computing was quoted as saying in the statement.

"Threat actors exploit this fear to their advantage and scam users into downloading malicious software and divulging sensitive information like banking codes. The need to be cyber cautious has never been greater. This is more so in the case of corporates who have adopted a work from home policy hurriedly without adequate cyber hygiene. We have seen an increase in attacks on enterprises and SME employees as well," he added.

Such attacks are expected to continue till normalcy returns. Social engineering attacks targeted at winning users' trust will gain momentum.

Healthcare institutions, well-known government offices, and international organisations will continue to be a prime target throughout the pandemic, the statement said.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
February 28,2020

Patna, Feb 28: Social and cultural activists from far and wide converged here on Thursday to lend their support to a massive rally that marked the conclusion of Kanhaiya Kumar's 'Jan Gan Man Yatra' across Bihar to galvanise public opinion against CAA-NPR-NRC.

Medha Patkar of the Narmada Bachao Andolan fame, Mahatma Gandhi's grandson Tushar Gandhi and former IAS officer Kannan Gopinathan, who gave up his career at a young age in protest against abrogation of Article 370, shared the stage with the former JNU students' leader.

Shabnam Hashmi -- founder of socio-cultural organisation ANHAD and sister of slain Marxist playwright and director Safdar Hashmi -- also joined them.

Congress MLA Shakil Ahmed Khan, a former president of JNU students' union himself who accompanied Kanhaiya during his tour that commenced at Champaran on January 30, Mahatma Gandhi's death anniversary, and leaders of state units of CPI and CPI(M) also addressed the rally held at Gandhi Maidan.

Kanhaiya began his speech with a one-minute silence held in the memory of those who lost their lives in Delhi violence.

Defending his frequent use of the term "azadi" (freedom) which supporters of the Sangh Parivar hold to be tantamount to supporting secession, Kanhaiya said, "We must talk about the virtues of azadi here since today happens to be the day when legendary revolutionary Chandrashekhar Azad had given up his life fighting the British."

Charging the ruling BJP with pitting Hindus against Muslims, he said, "Let us resolve to defeat their agenda by emulating the fabled friendship of Ram Prasad Bismil and Ashfaqullah Khan."

The young CPI leader, who made an unsuccessful debut from his native Begusarai Lok Sabha constituency last year, seemed unimpressed with the resolution passed by the Bihar Assembly earlier this week against NRC and inclusion of contentious clauses in NPR forms.

"Both the government and the opposition are busy congratulating themselves. I extend my congratulations as well. But to all those who are present here, I would say it is a half-victory. We must not allow our movement to fizzle out and draw inspiration from Gandhi's model of civil disobedience when the NPR exercise gets underway," he said.

"Villagers should ask their respective panchayat heads to ensure that no NPR official is allowed to come knocking in their areas of jurisdiction when NPR is scheduled to be undertaken in May," the CPI leader said.

"We have to brace for a long and tough fight. We are living under a regime which sends conscientious professionals like Dr Kafeel Ahmed behind the bars and declares anybody questioning its actions as an anti-national," said Kanhaiya, who has himself been slapped with a sedition case.

Earlier, in his address, Tushar Gandhi likened CAA, NPR and NRC to the "three bullets that killed the Mahatma" and asserted that these measures would "harm the poor, belonging to all religious communities and not just the Muslims".

"If the government does not care about the poor, we must tell those in power -- 'chale jaao' (go away) just as we had done to the British colonisers... it is going to be a long fight. Independence was achieved five years after the call for Quit India Movement," he said.

"We need to keep repeating the importance of non-violence over and over again while those with other value systems simply have to utter inciting statements," he said, in an oblique reference to the controversial poll campaign of Union minister and BJP leader Anurag Thakur during the recently-held Delhi Assembly elections, which the party lost.

Kannan Gopinathan said, "The claim that CAA is all about granting citizenship and not taking it away is bunkum. Any law which seeks to favour one section of the society on the basis of religion can be tweaked to harm another social segment... people say this government is Fascist. I am not sure of that but it is certainly stupid."

"This government brought in demonetisation and wrecked the economy but failed to achieve its promise of eradicating black money. It abrogated Article 370 and now it is clueless as to what to do with the situation in Kashmir," he said.

"Union minister Amit Shah had declared in Parliament that NRC will be implemented. Faced with public resistance, Prime Minister Narendra Modi had to say he does not know what NRC is. Keep up the stir for a little longer, he will start saying he does not know Amit Shah," said Kannan, evoking peals of laughter.

In the course of his speech, Kanhaiya also made the crowds sing after him the National Anthem but skipped a few words towards the end. Participants at the rally were viciously trolled on social media for the slip-up.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.