{"id":12425,"date":"2023-10-09T12:03:08","date_gmt":"2023-10-09T12:03:08","guid":{"rendered":"https:\/\/news.pakistaninewspaperlist.com\/many-android-devices-come-with-unkillable-backdoor-the-express-tribune\/"},"modified":"2023-10-09T12:03:08","modified_gmt":"2023-10-09T12:03:08","slug":"many-android-devices-come-with-unkillable-backdoor-the-express-tribune","status":"publish","type":"post","link":"https:\/\/pakistaninewspaperlist.com\/news\/many-android-devices-come-with-unkillable-backdoor-the-express-tribune\/","title":{"rendered":"Many Android devices come with unkillable backdoor | The Express Tribune"},"content":{"rendered":"<div id=\"\">\n<p>Security researcher, Daniel Milisic, discovered a cheap Android TV streaming box called the T95 was infected with malware right out of the box. His findings were backed by other researchers as well. This week, Human Security unveiled new details of the infected devices and the hidden, interconnected web of fraud schemes linked to the streaming boxes.<\/p>\n<p>The researchers found seven Android TV boxes and one tablet with the backdoors installed, along with 200 other Android devices, an exclusive report shared with The Wire revealed. While Human Security has taken down advertising fraud linked to the scheme, these devices are still present in homes, businesses, and schools.<\/p>\n<p>\u201cThey\u2019re like a Swiss Army knife of doing bad things on the Internet,\u201d says Gavin Reid, the CISO at Human Security who leads the company\u2019s Satori Threat Intelligence and Research team. \u201cThis is a truly distributed way of doing fraud.\u201d<\/p>\n<p>Reid added that the company also shared details of facilities where the devices may have been manufactured with law enforcement agencies.<\/p>\n<p>The research has been divided into two areas; Badbox, involving the compromised Android devices and the ways they are involved in fraud and cybercrime, and Peachpit which is related to ad fraud operation involving at least 39 Android and iOS apps. Google says it has removed apps following Human Security\u2019s research, while Apple says it has found issues in several of the apps reported to it.<\/p>\n<p>Cheap Android streaming boxes, usually costing less than $50, were sold online and in brick-and-mortar shops, with no known brand. Human Security says in its report, its researchers spotted an Android app that appeared to be linked to inauthentic traffic and connected to the domain flyermobi.com. The researchers confirmed eight devices with backdoors installed\u2014seven TV boxes, the T95, T95Z, T95MAX, X88, Q9, X12PLUS, and MXQ Pro 5G, and a tablet J5-W.<\/p>\n<p>Human Security spotted at least 74,000 Android devices showing signs of a Badbox infection around the world\u2014including some in schools across the US.<\/p>\n<p>The devices are built in China, though it is not known where a firmware backdoor is added. \u201cUnbeknownst to the user, when you plug this thing in, it goes to a <a rel=\"nofollow\" href=\"https:\/\/www.feroot.com\/education-center\/what-is-a-command-and-control-c2-server\/#:~:text=A%20command%2Dand%2Dcontrol%20(C2)%20server%20is%20a,%2C%20malicious%20scripts%2C%20and%20more.\">command and control<\/a> (C2) in China and downloads an instruction set and starts doing a bunch of bad stuff,\u201d Reid says.<\/p>\n<p>Multiple types of fraud were linked to the compromised devices including advertising fraud, residential proxy service, fake Gmail and WhatsApp accounts and remote code installation.<\/p>\n<p>Trend Micro found a \u201cfront end company\u201d for the group it investigated in China, Yarochkin says.<\/p>\n<p>\u201cThey were claiming that they have over 20 million devices infected worldwide, with up to 2 million devices being online at any point of time,\u201d he says. \u201cThere was a tablet in one of the museums somewhere in Europe,\u201d Yarochkin says, adding he believes it is possible that swaths of Android systems may have been impacted, including in cars. \u201cIt\u2019s easy for them to infiltrate the supply chain,\u201d he says. \u201cAnd for manufacturers, it&#8217;s really difficult to detect.\u201d<\/p>\n<p>The company identified 39 Android, iOS, and TV box apps that were involved in an app-based fraud element, called Peachpit. \u201cThese are template-based applications\u2014not very high quality,\u201d says Joao Santos, a security researcher at the company. Apps about developing six-pack abs and logging the amount of water a person drinks were included.<\/p>\n<p>The apps not only had hidden advertisements but also spoofed web traffic and malvertising. Human Security\u2019s research says the ads involved were making 4 billion ad requests per day, with 121,000 Android devices impacted and 159,000 iOS devices impacted. There had been 15 million downloads in total for the Android apps, the researchers calculated.<\/p>\n<p>Google spokesperson Ed Fernandez confirms the 20 Android apps reported by Human Security have been removed from the Play Store. Apple spokesperson Archelle Thelemaque says that it found five of the apps Human reported breaching its guidelines, and the developers were given 14 days to make them follow the rules.<\/p>\n<p>These attacks, though now much slowed, are still in people&#8217;s homes with dangerous malware that is very hard to remove. \u201cYou can think of these Badboxes as kind of like sleeper cells. They&#8217;re just sitting there waiting for instruction sets,\u201d Reid says.<\/p>\n<\/div>\n<p><script async defer crossorigin=\"anonymous\" src=\"https:\/\/connect.facebook.net\/en_US\/sdk.js#xfbml=1&#038;version=v5.0&#038;appId=419051588770002&#038;autoLogAppEvents=1\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security researcher, Daniel Milisic, discovered a cheap Android TV streaming box called the T95 was infected with malware right out of the box. His findings were backed by other researchers as well. This week, Human Security unveiled new details of the infected devices and the hidden, interconnected web of fraud schemes linked to the streaming [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":12426,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"fifu_image_url":"https:\/\/i.tribune.com.pk\/media\/images\/939984-androidstoryreuterscopy-1439848342\/939984-androidstoryreuterscopy-1439848342.jpg","fifu_image_alt":"","footnotes":""},"categories":[8],"tags":[],"class_list":["post-12425","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/pakistaninewspaperlist.com\/news\/wp-json\/wp\/v2\/posts\/12425","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pakistaninewspaperlist.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pakistaninewspaperlist.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pakistaninewspaperlist.com\/news\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/pakistaninewspaperlist.com\/news\/wp-json\/wp\/v2\/comments?post=12425"}],"version-history":[{"count":0,"href":"https:\/\/pakistaninewspaperlist.com\/news\/wp-json\/wp\/v2\/posts\/12425\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/pakistaninewspaperlist.com\/news\/wp-json\/wp\/v2\/media\/12426"}],"wp:attachment":[{"href":"https:\/\/pakistaninewspaperlist.com\/news\/wp-json\/wp\/v2\/media?parent=12425"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pakistaninewspaperlist.com\/news\/wp-json\/wp\/v2\/categories?post=12425"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pakistaninewspaperlist.com\/news\/wp-json\/wp\/v2\/tags?post=12425"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}