顯示具有 android 標籤的文章。 顯示所有文章
顯示具有 android 標籤的文章。 顯示所有文章

2020年7月15日 星期三

TrendLabs: New Android Spyware ActionSpy Revealed via Phishing Attacks from Earth Empusa

Figure 1. The Earth Empusa attack chain
REF: https://blog.trendmicro.com/trendlabs-security-intelligence/new-android-spyware-actionspy-revealed-via-phishing-attacks-from-earth-empusa/

TrendLabs: New Tekya Ad Fraud Found on Google Play

Figures 1 and 2. Apps with Tekya malware (Click to enlarge)
REF: https://blog.trendmicro.com/trendlabs-security-intelligence/new-tekya-ad-fraud-found-on-google-play/

2020年7月6日 星期一

TrendLabs: Barcode Reader Apps on Google Play Found Using New Ad Fraud Technique

Figure 1. Malicious code disguised using Facebook’s name

REF: https://blog.trendmicro.com/trendlabs-security-intelligence/barcode-reader-apps-on-google-play-found-using-new-ad-fraud-technique/

2020年3月21日 星期六

TrendLabs: Dissecting Geost: Exposing the Anatomy of the Android Trojan Targeting Russian Banks

Figure 2: Screen that requests device admin permission
REF: https://blog.trendmicro.com/trendlabs-security-intelligence/dissecting-geost-exposing-the-anatomy-of-the-android-trojan-targeting-russian-banks/

2020年2月10日 星期一

TrendLabs: Malicious Optimizer and Utility Android Apps on Google Play Communicate with Trojans that Install Malware, Perform Mobile Ad Fraud

Figure 2. A graphic representation of the relationships between the malicious ad configuration servers based on data obtained from VirusTotal
REF: https://blog.trendmicro.com/trendlabs-security-intelligence/malicious-apps-on-google-play-communicate-with-trojans-install-malware-perform-mobile-ad-fraud/

2020年1月7日 星期二

TrendLabs: First Active Attack Exploiting CVE-2019-2215 Found on Google Play, Linked to SideWinder APT Group

Figure. XX


Figure 1. The three apps related to SideWinder group
REF: https://blog.trendmicro.com/trendlabs-security-intelligence/first-active-attack-exploiting-cve-2019-2215-found-on-google-play-linked-to-sidewinder-apt-group/

2019年12月29日 星期日

FSF: Replicant needs your help to liberate Android in 2020




The Free Software Foundation (FSF) supports the work of several important free software projects through fiscal sponsorship in a program we call Working Together for Free Software.

Donations to any of the Working Together for Free Software projects directly benefit the work that can be done. Too often, these projects are underfunded and developers are putting in a lot of personal time and effort to keep the project moving forward. Because of the FSF fiscal sponsorship, they can receive donations and apply for funding.

REF: https://www.fsf.org/blogs/community/replicant-needs-your-help-to-liberate-android-in-2020

2019年12月4日 星期三

TrendLabs: 49 Disguised Adware Apps With Optimized Evasion Features Found on Google Play

Figure. 2
Figure 2. Screen captures of codes showing how the malicious app’s icon is hidden or removed
REF: https://blog.trendmicro.com/trendlabs-security-intelligence/49-disguised-adware-apps-with-optimized-evasion-features-found-on-google-play/

2019年11月20日 星期三

TrendLabs: Fake Photo Beautification Apps on Google Play can Read SMS Verification Code to Trigger Wireless Application Protocol (WAP)/Carrier Billing


Figure 1. Screenshot showing reviews about the app; one user noted how she lost mobile credits after installing the app
REF: https://blog.trendmicro.com/trendlabs-security-intelligence/fake-photo-beautification-apps-on-google-play-can-read-sms-verification-code-to-trigger-wireless-application-protocol-wap-carrier-billing/

2019年9月8日 星期日

TrendLabs: Adware Posing as 85 Photography and Gaming Apps on Google Play Installed Over 8 Million Times

Figure 1. Screenshot of the applications embedded with adware
REF: https://blog.trendmicro.com/trendlabs-security-intelligence/adware-posing-as-85-photography-and-gaming-apps-on-google-play-installed-over-8-million-times/

2019年4月25日 星期四

TrendLabs: New Version of XLoader That Disguises as Android Apps and an iOS Profile Holds New Links to FakeSpy


Figure 1. Screenshot of a fake website that hosts XLoader
REF: https://blog.trendmicro.com/trendlabs-security-intelligence/new-version-of-xloader-that-disguises-as-android-apps-and-an-ios-profile-holds-new-links-to-fakespy/

2019年3月24日 星期日

ADMIN: An Image Can Compromise Your Android Device

Three newly-found vulnerabilities (CVE-2019-1986, CVE-2019-1987, and CVE-2019-1988) can affect handsets running anything between Android 7.0 Nougat and current Android 9.0 Pie.

One of the three vulnerabilities allows a compromised PNG file to execute arbitrary code on unpatched Android devices.

REF: http://www.admin-magazine.com/News/An-Image-Can-Compromise-Your-Android-Device

2019年3月5日 星期二

2018年4月29日 星期日

RememBear Official Launch

RememBear Official Launch
If you’ve never used a password manager, RememBear will happily walk you through setting your account up with straightforward instructions and animations.

REF: https://www.remembear.com/blog/remembear-official-launch/

2017年12月4日 星期一

Samsung is testing Linux desktop

REF: http://www.linux-magazine.com/Online/News/Samsung-to-Bring-Linux-to-Desktop

The same year Canonical decide to pull out of the consumer space, Samsung is bringing a pure desktop Linux experience to PCs. Unlike Apple, Google, or Microsoft, Samsung doesn’t have any tightly integrated offering for professionals who need a desktop to get work done. Samsung came out with DeX, an accessory for Samsung Galaxy phones that connected with a monitor and offers a desktop-like interface. It’s an experience similar to Ubuntu Dock or Motorola Atrix Webtop.

2017年10月30日 星期一

Android getting “DNS over TLS”

DNS over TLS is a protocol where DNS queries will be encrypted to the same level as HTTPSand thus a DNS can’t actually log or see the websites you visit. This uses TLS, or Transport Layer Security, to achieve this encryption. This does require the DNS you are using to have DNS over TLS support, though, but it’s a start. Users can switch to Google’s DNS if they wish to benefit from DNS over TLS.
It appears that “DNS over TLS” support is being added to Android, according to several commits added to the Android Open Source Project (AOSP). The addition in the Android repository shows that a new setting will be added under Developer Options allowing users to turn on or off DNS over TLS. Presumably, if such an option is being added to Developer Options, then that means it is in testing and may arrive in a future version of Android such as version 8.1.
REF: https://www.xda-developers.com/android-dns-over-tls-website-privacy/

2017年10月22日 星期日

The Librem 5 Free Phone

Figure 1: A mockup of what the Librem 5 phone will look like.
REF: http://www.linux-magazine.com/Online/Features/Librem-5-and-the-Challenge-of-the-Free-Phone

2017年9月18日 星期一

TrendLabs: BankBot Found on Google Play


Figure 3. Fake Emirates banking app screen
Figure 3. Fake Emirates banking app screen
Figure 3. Fake Emirates banking app screen
REF: http://blog.trendmicro.com/trendlabs-security-intelligence/bankbot-found-google-play-targets-ten-new-uae-banking-apps/

TrendLabs: DoS to Android

A denial-of-service vulnerability we recently disclosed to Google can do exactly that and more. Designated as CVE-2017-0780, we’ve confirmed it to be in the latest Nexus and Pixel devices. The security flaw can let attackers illicitly and remotely crash their victims’ Android Messages app by sending a malformed multimedia message (MMS). The app will also be incapable of recovering from the crash even if the device/system is rebooted or booted in safe mode.

REF: http://blog.trendmicro.com/trendlabs-security-intelligence/cve-2017-0780-denial-service-vulnerability-android-messages-app/

Phones with free software

We don't have a freedom-respecting drop-in replacement for the iPhone. Apple's government-subsidized DRM and massive legal intimidation team make developing and distributing a freedom-respecting smartphone very difficult. But we are nonetheless getting closer. You can have a solid, basic smartphone today by running Replicant, a free software version of Android. You can install it yourself on supported models, or buy one pre-installed from Technoethical. You can give the Replicant project a boost, and help them to implement missing features, by donating. Also, check out F-Droid, an app repository of exclusively free software for Android.

REF: http://www.fsf.org/blogs/community/the-apple-is-still-rotten-why-you-should-avoid-the-new-iphone