Over 500K People Have Installed a Pokemon Go-Related App That Roots and Hijacks Android Devices (softpedia.com) 57
An anonymous reader writes: Over 500,000 people have downloaded an Android app called "Guide for Pokemon Go" that roots the devices in order to deliver ads and installs apps without the user's knowledge. Researchers that analyzed the malware said it contained multiple defenses that made reverse-engineering very difficult -- some of the most advanced they've seen -- which explains why it managed to fool Google's security scanner and end up on the official Play Store. The exploits contained in the app's rooting functions were able to root any Android released between 2012 and 2015. The trojan found inside the app was also found in nine other apps, affecting another 100,000 users. The crook behind this trojan was obviously riding various popularity waves, packing his malware in clones for whatever app or game is popular at one particular point in time.
Installed? (Score:5, Insightful)
Installed or downloaded? Android scans apps, even side loaded ones, during installation for malware. This app has been on the banned list for ages.
So 500k downloads could equal zero installs.
Re: (Score:1)
Installed or downloaded? Android scans apps, even side loaded ones, during installation for malware. This app has been on the banned list for ages.
So 500k downloads could equal zero installs.
But you know it doesn't.
Re: (Score:2)
So, if you like using your Android for fun stuff, like most people do, you're fucked?
Re: (Score:2)
Given that Android has about 80% global market share, you're full of shit.
http://www.statista.com/statis... [statista.com]
Because god forbid all those people use their phones for fun. Are you a fun-shamer? Or just an asshole?
Re: (Score:3, Informative)
Installed or downloaded? Android scans apps, even side loaded ones, during installation for malware. This app has been on the banned list for ages.
So 500k downloads could equal zero installs.
That's in the paragraph below the one quoted by TFA:
If it roots on activation it's odd to say that there have been 500K installs but only around 6K roots. 500K downloads and
Re: (Score:3)
No every Android phone with the installed app / root kit may have some Kaspersky security product delivering telemetry. This makes those numbers a bit difficult to interpret understand.
I do not believe that both numbers (the 500k and the 6000) can be related and compared. In the end you can only conclude what is written in the text: at least 6000 phones are compromised, with the implicit knowledge that this number may be much higher, possibly in the 500 k range.
An interesting information would be to know ho
Re: (Score:3)
500k seems to be the number of downloads, so I'd imagine that between people who don't have side-loading enabled, who see the warnings during installation and change their minds, who have AV that blocks it, that got the Play update that blocks it or who have incompatible devices (there is no universal root exploit for Android, they are all kernel/bootloader specific) the number of infected devices is probably quite low.
How did this get out, dammit! (Score:3)
Oh, you're not talking about the "genuine" variant?
Oh. Never mind, carry on...
Gotta catchem all. (Score:2, Funny)
Looks like they caught a "peekatyou".
Re: (Score:2)
Re: Gotta catchem all. (Score:1)
ROOT!? (Score:1)
Does it root any Android device? Does anybody knows how dies it work?
Because I have been trying to root mine for ages...
Re: (Score:2)
I admit that I am an Android noob, but when I searched about rooting my Nexus 5, I got the impression that doing so will factory reset my device, and I will lose some of my data unless I backed it up first. Except that the even the best backup apps would not back up everything, unless the phone is already rooted...
Malware (Score:5, Funny)
Malware, gotta catch 'em all.
Ultimate Root App (Score:4, Insightful)
The trojan roots all Android devices released between 2012 and 2015?
Without needing to unlock the bootloader, install custom recovery, etc.?
Awesome! Where do I sign up!?
Re: (Score:1)
So are they no longer able to play? (Score:2)
Re: (Score:2)
Since cheating in Pokemon pretty much means faking your GPS position, I'd say that they do have a vested interesting in having no cheaters in the game, yes...
But I thought Android was secure (Score:2)
This just goes to show what happens when you put an operating system in the hands of millions/billions of every day users. It can be Windows, Linux, OSX, iOS, Android, it doesn't matter. People are idiots and they will install anything. I didn't really think it was possible to root a phone simply by installing an app. That definitely is a failing in the security. But there isn't really anything you can do to completely stop all attacks if people are going to install random software.
Re: (Score:2)
People are idiots and they will install anything.
Most people would say it's reasonable to install from the google play market, because it's curated/vetted. You on the other hand, think they're idiots. Can you talk us through what you would do, if you saw an app in the market that was interesting to you? Go through the code, maybe? Maybe nothing would ever be of interest to you, because you're not an idiot?
The important thing is you declared your smartness to slashdot. I think that's all that matters in the end, no?
Re: (Score:2)
That's why Apple generall
It Really Pisses Me Off (Score:2, Insightful)
It really pisses me off that these apps can supposedly root Android and install all sorts of apps, yet trying to get root on my Galaxy is a convoluted game of Twister requiring the setting of permissions, installing special PC software, installing special (skecthy as fuck) boot loaders, custom (sketchy as fuck) recovery environments, and more.
And, rooting Amazon fire tablets is either impossible or it's utterly bricked in the attempt.
How is it that these bullshit apps can so easily get root and install hidd
Re: It Really Pisses Me Off (Score:1)
Re: It Really Pisses Me Off (Score:1)
Re: (Score:2)
The problem if you're trying to get root to do useful stuff, like a root shell and other things. Plus, you probably want it untethered.
The apps just need root to insta
Guide for Pokemon go (Score:2)
There are literally hundreds of such apps, which probably most the time just contain a few buttons with nice pokemon images and some sections of the FAQ ... and of course a lot of ads. This makes it really hard to find good apps, like pokevision (RIP) or Pokeradar or some useful pokedex, which has the weaknesses of the pokemon as they are in pokemon go.
Re: (Score:2)
I did once (July) install an app with that name, but there are many with the same name on the Play store. I uninstalled it the next day because it was crap. Screenshots look familiar, but I'm not sure.
At least I don't see any suspicious files with setuid permissions, but then: /system/xbin/su is also mode rwx. I guess I'll reflash my ROM (CM13) this weekend, just to be sure...
This is big news: (Score:2)
Vintage Leather satchel bags (Score:1)