Bitdefender researchers recently analyzed 25 apps that made it into Google Play, at least for a time, packing aggressive adware SDKs that bombarded users with ads and avoided removal by hiding their presence. Cumulatively, the apps were apparently downloaded almost 700,000 times by Google Play users.
While Google has gone to great lengths to ban malicious or potentially unwanted applications from the official Android app store, malware developers are nothing if not imaginative when coming up with new ideas to dodge Google Play Protect.
Some of the key techniques found for dodging security vetting revolve around using open source utility libraries (used by Evernote, Twitter, Dropbox, etc.) to run jobs in the background, using different developer names to submit identical code, and even hiding code that is triggered remotely by command & control servers.
For a more detailed technical analysis, please check out the technical paper below:
tags
Liviu Arsene is the proud owner of the secret to the fountain of never-ending energy. That's what's been helping him work his everything off as a passionate tech news editor for the past few years.
View all postsJune 08, 2023
May 02, 2023
January 11, 2023
January 05, 2023