Schneier on Security's Journal
 
[Most Recent Entries] [Calendar View]

Tuesday, February 16th, 2021

    Time Event
    3:15p
    Malicious Barcode Scanner App

    Interesting story about a barcode scanner app that has been pushing malware on to Android phones. The app is called Barcode Scanner. It’s been around since 2017 and is owned by the Ukrainian company Lavabird Ldt. But a December 2020 update included some new features:

    However, a rash of malicious activity was recently traced back to the app. Users began noticing something weird going on with their phones: their default browsers kept getting hijacked and redirected to random advertisements, seemingly out of nowhere.

    Generally, when this sort of thing happens it’s because the app was recently sold. That’s not the case here.

    It is frightening that with one update an app can turn malicious while going under the radar of Google Play Protect. It is baffling to me that an app developer with a popular app would turn it into malware. Was this the scheme all along, to have an app lie dormant, waiting to strike after it reaches popularity? I guess we will never know.

    << Previous Day 2021/02/16
    [Calendar]
    Next Day >>

Schneier on Security   About LJ.Rossia.org