首页»版块 历史内容 历史内容 历史分类 官方人员翻译一下卡巴斯基的这篇文章

官方人员翻译一下卡巴斯基的这篇文章

[复制帖子标题和链接]

13759

荣耀粉丝18190343  LV6  发表于 2019-9-22 22:57:50 属地未知 来自:浏览器
官方人员翻译一下卡巴斯基的这篇文章

Malicious Android app had more than 100 million downloads in Google Play
August 27, 2019
Kaspersky researchers recently found malware in an app called CamScanner, a phone-based PDF creator that includes OCR (optical character recognition) and has more than 100 million downloads in Google Play. Various resources call the app by slightly different names such as CamScanner — Phone PDF Creator and CamScanner-Scanner to scan PDFs.

Official app stores such as Google Play are usually considered a safe haven for downloading software. Unfortunately, nothing is 100% safe, and from time to time malware distributors manage to sneak their apps into Google Play.

The problem is that even such a powerful company as Google can’t thoroughly check millions of apps. Keep in mind that most of the apps are updated regularly, so Google Play moderators’ jobs are never done.

CamScanner was actually a legitimate app, with no malicious intensions whatsoever, for quite some time. It used ads for monetization and even allowed in-app purchases. However, at some point, that changed, and recent versions of the app shipped with an advertising library containing a malicious module.

Kaspersky products detect this module as Trojan-Dropper.AndroidOS.Necro.n, which we have observed in some apps preinstalled on Chinese smartphones. As the name suggests, the module is a Trojan Dropper. That means the module extracts and runs another malicious module from an encrypted file included in the app’s resources. This “dropped” malware, in turn, is a Trojan downloader that downloads more malicious modules depending on what its creators are up to at the moment. These malicious modules may show intrusive ads and sign users up for paid subscriptions to external services (not to be mistaken with a legitimate premium subscription to CamScanner).

Although most reviews left by users of the CamScanner on the app’s Google Play page are positive, some of the users have reported on suspicious behavior of the app that they’ve encountered while using the infected version.

Kaspersky researchers examined a recent version of the app and found the malicious module there. We reported our findings to Google, and the app was promptly removed from Google Play.

It looks like app developers got rid of the malicious code with the latest update of CamScanner. Keep in mind, though, that versions of the app vary for different devices, and some of them may still contain malicious code.

What we can learn from this story is that any app — even one from an official store, even one with a good reputation, and even one with millions of positive reviews and a big, loyal user base —can turn into malware overnight. Every app is just one update away from a major change. To make sure you never find yourself in such trouble, use a reliable antivirus for Android app and scan your smartphone from time to time. (The paid version of Kaspersky Internet Security for Android scans automatically.)

We appreciate the willingness to cooperate that we’ve seen from CamScanner representatives, as well as the responsible attitude to user safety they demonstrated while eliminating the threat. We’ve rephrased the line above about paid subscription services to make it clear that the paid subscriptions initiated by malicious modules are not to be mistaken with a legitimate subscription model that many users adopted by choice. The malicious modules were removed from the app immediately upon Kaspersky’s warning, and Google Play has restored the app.


原文链接:https://www.kaspersky.com/blog/camscanner-malicious-android-app/28156/



评论9
荣耀粉丝18190343  LV6  发表于 2019-9-22 23:00 属地未知 来自:浏览器
https://appstore.huawei.com/app/C10068705
荣耀粉丝18190343  LV6  发表于 2019-9-22 23:04 属地未知 来自:浏览器
本帖最后由 蓝蓝的深海 于 2019-9-22 23:05 编辑


官方人员翻译一下卡巴斯基的这篇文章

https://securelist.com/dropper-in-google-play/92496/
荣耀粉丝91124246  LV1  发表于 2019-9-22 23:12 属地未知 来自:ALP-AL00
有一款恶意软件被植入了谷歌商店的游戏APP里下载上万,还有一个合法的程序CamScaner先是靠植入的广告赚钱后来新版本里也植入了木马病毒,这个木马病毒可以调起另一个木马病毒,这个恶意的木马病毒影响了之前无恶意那个软件的知名度,(简单来说就是两个程序互掐)从上面这个事件可以说明,所有的应用商店哪怕是官方的都可以一夜之间都变成恶意软件,所以推荐大家使用卡巴斯基。
您需要登录后才可以评论 登录 | 立即注册
简体中文 - China
快速回复 返回顶部 返回列表