Posts tagged with “mobile security”

File notification APIs leak user activity across major OSes

Researchers at Graz University of Technology in Austria have shown that the file-change notification features in Linux, Android, Windows and macOS can be used to spy on other users of the same system. The information exposed ranges from the rhythm of someone's typing to the websites they visit.

All four operating systems let applications ask to be told when files are created, modified or deleted. Text editors, file managers, sync clients and antivirus tools rely on this. It needs no elevated privileges, only read access to the watched location.

The attacks never reveal what is inside a file. The researchers found that file names and the timing of events are enough to piece together what users, applications and the system are doing. Most scenarios assume an attacker who can already run code on the machine under a separate account. On Android, that attacker could be an app that asks for no permissions at all.

Read More


RemControl Android banking malware hits Europe and Canada

A newly discovered Android malware-as-a-service (MaaS) platform called RemControl is going after banking customers in Europe, Canada and the Middle East. According to Group-IB, the malware spreads through malvertising campaigns that impersonate TVTap, an IPTV streaming app.

Researchers say the infrastructure behind RemControl has been running since at least May. The first samples appeared in July and already carried more than 30 phishing overlays built to capture banking credentials. Targeted countries include Italy, France, Spain, Poland and Portugal, as well as Canada and several Middle Eastern states.

Fake Google Play pages and ad-driven traffic

Victims land on fake Google Play pages that pose as the TVTap download. At least one Italian campaign used geofencing and checked mobile User-Agent strings, so only visitors who matched the intended profile would see the malicious content.

Read More