Showing posts with label Mobile Spyware. Show all posts
Showing posts with label Mobile Spyware. Show all posts

Friday, 22 May 2015

NSA Wanted To Infect Android Users On Google App Store


The US National Security Agency has set up a project in the past which attempted to infect users of the Google Play Store and Samsung App Store with spyware, according to documents from whistleblower Edward Snowden of late 2011 and early 2012 date.

According to the documents sought the NSA and British, Canadian, New Zealand and Australian intelligence agencies to find ways to attack smartphone users. Through the previously disclosed XKEYSCORE system smartphone traffic was identified.Through another project that had looked into development of the connection from the user to the aforementioned app stores was to hijack so that could then be controlled via a man-in-the-middle attack malignant "implants" to the smartphone .


In this way the intelligence services could monitor the target then. In addition to using the app stores as a springboard for the spread of spyware intelligence also sought ways to hijack them and spread misinformation among targets. Also wanted the intelligence to access the app store servers so that they could gather information about users, so notify the intercept and CBC News .

UC Browser


The documents also show that the intelligence services had discovered vulnerabilities in UC Browser, an immensely popular browser in Asia, and particularly China and India. Worldwide, 500 million people would use the program. The browser was found to leak all kinds of information over the phone. Information used by the intelligence services too. Canadian CitizenLab UC Browser has studied because the documents in April and discovered numerous vulnerabilities, which have now been remedied through an update. Google declined to comment on the findings and Samsung has given no substantive response.

Full Document Report

Friday, 15 May 2015

Provider Mobile Spyware Hacked, Customer Data Leaked


Attackers have managed at a popular provider of mobile spyware to break into and subsequently stolen and put online database with customer data. The software in question is mSpy that own words almost 2 million users have.

According to the attackers in the hack, which is unknown how that occurred, captured the data of more than 400,000 people.IT journalist Brian Krebs , however, that the actual number of customers affected can not be determined. However, concerns sensitive information such as emails, text messages, pay and location data, passwords, Apple ID, photos and calendar data.In total, there were hundreds of gigabytes of data stolen.

Through mSpy users can use the phone a different monitors, such as incoming and outgoing calls, text messages, emails, GPS location, chat conversations, Internet and can access the address book and calendar are obtained. For this purpose it is required that the user has physical access to the device of the other, so that the mSpy can be installed. The software itself has not yet responded to the burglary.

Monday, 9 March 2015

Malware Infected Xiaomi Smartphone Appears Counterfeiting


Last week there was a fuss about Chinese smartphone manufacturer Xiaomi standard that malware would be delivered, but now it is confirmed that it is a counterfeit device. Bluebox security company published last Thursday a blog posting about malware that was found on the Xiaomi Mi 4 LTE smartphone. The company had bought the unit in China.

When scanning of the apps on the smartphone was found one suspect app, allowing users of information risk could walk.Initially the Chinese smartphone manufacturer would not have responded to the findings of Bluebox. After publication of the research did however a response, which the company claimed that there was possibly purchased a manipulated device.

Bluebox had purchased over the phone namely a physical supplier, while Xiaomi China does not sell equipment through "third-party" parties. The aircraft would only online and through the shops of telecom providers are offered. Then again Bluebox responded with criticism, because it was apparently possible for stores or anyone in the distribution chain to adjust the devices.

Counterfeit
After an extensive testing on the basis of all kinds of pictures is now been established that it is a counterfeit Mi 4. The unit was so well imitated that it initially also managed to circumvent a special app Xiaomi for detecting counterfeit devices. The latest version of the app can now detect the counterfeit version.

According Bluebox let the incident shows how important it is for companies to take researchers reports seriously and work together. Further notes the security of the supply chain, where it happens that consumers compromised smartphones can purchase. Finally, the tools to identify counterfeit goods must be improved.

Tuesday, 24 February 2015

Location Smartphone To Monitor Power Consumption Through


Owners of a smartphone is not only to follow through their location information, also the power consumption can make clear where one has been. That have researchers from Stanford University in the United States and the National Research and Simulation Center Rafael determined from Israel.

A malicious app on the phone can measure the power consumption and thus determine the position of the owner. "Our approach allows the identification of known routes, real-time tracking and new routes possible by measuring the power consumption," said Yan Michalevsky opposite Technology Review . The idea behind the theory is that the power consumption of the smartphone is dependent on the distance to the base station.

If a user travels changing this distance, whereby the power consumption increases or decreases. The power consumption is therefore highly dependent on the phone's movements and the route taken by the user. Given different routes that a user can take, the power profile will show which route the user has actually taken.

The researchers concluded an Android app called "PowerSpy" develop to prove the theory in practice. The app on different devices was then tested, with 43 different user profiles for four different routes were collected. On the basis of the power consumption, the researchers with an accuracy of 93% were able to determine the selected route. The power consumption of other existing apps, according to the researchers to easily eliminate.

To protect users against this form of tracking apps would have to gain access to power, although this is probably overkill. A better option is apps only allow access to the power that is not associated with radio communications. One option that is also easy to implement. The research and presentation ( ppt to find) the researchers are online.