• About
  • Sitemap
  • Privacy Policy
  • Facebook
  • Contact Us
Welcome to oklandloaded....
  • Home
  • NEWS
    • FUNNY POST
    • DOWNLOAD
    • OTHERS
  • ENTERTAINMENT
    • LIFESYTLE
    • EVENTS
  • MUSIC
  • SPORT
  • TECHNOLOGY
  • EDUCATION
Home » Tech » Warning: BEWARE of Android Apps Contains Code that Spy on Your Text Messages

Warning: BEWARE of Android Apps Contains Code that Spy on Your Text Messages

A large number of third-party Android apps have reportedly been discovered grabbing copies of all text messages received or sent to infected devices and sending them to the attackers' server.
 More than 63,000 Android applications use Taomike SDK – one of the biggest mobile advertisement solutions in China – to help developers display ads in their mobile apps and generate revenue.
 However, around 18,000 of these Android apps contains a malicious code that spy on users text messages, according to researchers at Palo Alto Networks, who made the discovery.

Taomike provides a Software Development Toolkit (SDK) and services to the Android app developers using which they can:
Displaying advertisements to users
Offer in-app purchases (IAPs)

 Android Apps Stealing SMS Messages
Focussing on distributing the app and techniques for building revenue, "Not all apps that use the Taomike library steal SMS messages," security researchers said.
 The security researchers gave the following details:
The samples that contain the embedded URL, hxxp://112.126.69.51/2c.php performs such functions.
The software sends SMS messages as well as the IP address belongs to the Taomike API server used by other Taomike services to the above URL.
More than 63,000 Android apps in WildFire include the Taomike library, but around 18,000 Android apps include the SMS stealing functionality since August 1, 2015.
Some of the infected apps even contain or display adult content.

 "Wildfire" is Palo Alto Networks own cloud-based service that integrates with the Palo Alto Firewall and provides detection and prevention of malware.
 

In Android version 4.4 (KitKat), Google began preventing apps from capturing SMS messages unless they were defined as the "default" SMS app.

     How Does the Spying Attack Work?

 The Taomike library, dubbed 'zdtpay', is a component of Taomike's IAP system.
 This library requires both SMS and network related permissions while downloading an app. The library also registers a receiver name com.zdtpay.Rf2b for both SMS_RECEIVED and BOOT_COMPLETED actions.
 The receiver Rf2b reads the messages as soon as they arrive in the phone and then collects both the message body as well as the sender.
 Also, if the device is rebooted, the MySd2e service is started to register a receiver for the Rf2b.
 SMS message information collected by the receiver is stored in a hashmap with 'other' as the key and then sent to a method that uploads the message to 112.126.69.51 address

The researchers claim that the library is blindly fetching and uploading all SMS messages received by infected phone and not just those that are relevant to Taomike’s platform.
 The users who are not at risk because of this SMS Stealing library are:
Users from other countries than China.
Users that download apps only from the official Google Play store.
 As this threat is discovered with the current update of the library, researchers said that this SMS uploading behavior is not present in the earlier versions of the SDKs.
Posted by Unknown on Thursday, 17 December 2015 - Rating: 4.5
Title : Warning: BEWARE of Android Apps Contains Code that Spy on Your Text Messages
Description : A large number of third-party Android apps have reportedly been discovered grabbing copies of all text messages received or sent to infecte...

Share this post on

Facebook Google+ Twitter

0 Response to "Warning: BEWARE of Android Apps Contains Code that Spy on Your Text Messages"

Post a Comment

YOUR COMMENT IS HIGHLY APPRECIATED, THANKS AND GOD BLESS

Newer Post
Older Post
Home
Subscribe to: Post Comments (Atom)
Posts
Atom
Posts
Comments
Atom
Comments
Posts
Atom
Posts
Comments
Atom
Comments

Blog Archive

  • ►  2017 (39)
    • ►  August (21)
    • ►  May (2)
    • ►  March (2)
    • ►  February (6)
    • ►  January (8)
  • ►  2016 (175)
    • ►  December (3)
    • ►  November (7)
    • ►  October (7)
    • ►  September (21)
    • ►  August (18)
    • ►  July (6)
    • ►  June (25)
    • ►  May (2)
    • ►  April (7)
    • ►  March (62)
    • ►  February (6)
    • ►  January (11)
  • ▼  2015 (195)
    • ▼  December (21)
      • Enjoy 2015/2016 Glo Introduced Night and Weekend P...
      • Mavie Record Queen finally reveals her baby’s face
      • Guus Hiddink wants MLS star Didier Drogba as Chels...
      • Lagos PDP Gives Faleke Ultimatum To Declare Pollin...
      • How to Use MTN Free 150MB On Java Phones and Sym...
      • Warning: BEWARE of Android Apps Contains Code that...
      • This Simple Trick Requires Only Your Phone Number ...
      • WAEC releases November/December WASSCE results 2015
      • LASTEST UPDATE:-FG Declares December 25, 26, Janua...
      • Why Does The Naira Keep Losing Value?
      • UPDATE: Coach Jose Mourinho exits Chelsea
      • MTN now release new Weekend Bundle plan 3GB for #300
      • TECH: How to change IMEI without APPLICATION
      • Breaking News:Kogi State House of assembly Speaker...
      • JOKE:warning! warning!! warning!!!
      • KOGI: I won't be available for swearing in with Be...
      • HOW TO WATCH LIVE TV ON ANDROID AND BLACKBERRY USE...
      • REBIRTH : MTN MUSICPLUS :MTN BIS :OPENVPN Now work...
      • FINALLY INEC declares Yahaya Bello winner of Kogi ...
      • TESTED N CONFIRMS: how to Get Free mtn awoof airti...
      • Photos From The Clash Between Faleke & Bello Suppo...
    • ►  November (15)
    • ►  October (34)
    • ►  September (15)
    • ►  August (28)
    • ►  July (16)
    • ►  June (18)
    • ►  May (48)
  • ►  2014 (102)
    • ►  December (3)
    • ►  November (6)
    • ►  October (13)
    • ►  August (1)
    • ►  July (3)
    • ►  June (17)
    • ►  May (59)

Followers

FOLLOW US ON NETWORKBLOG

Propellerads

Featured post

FULL ALBUM DOWNLOAD: Yunique

   It’s here, it’s hot collaborates with Hajji . Ky star,Itabriz and a host lot of others Artist ” Yunique Ft Hajj Ohinoyi Eva(2 KING) Yu...

Google Translate

Popular Posts

  • [Tech] Tips To Increase Your Laptop Battery
    The problem that plagues most laptops these days is the battery’s tendency to lose capacity over time.The age old nickel-cadmium and nickel...
  • TECH: EASILY WAY TO UNLOCK VISAFONE Zte modem [AC2766 MTS]
     Before starting you have to download these softwares;  CDMA WORKSHOP and Ac2766 UNLOCKER 1.open cdma workshop                             ...
  • MTN HAVE NTRODUCED GOOD MORNING NIGERIA FREE CALL
    wow MTN have introduce good morning Nigeria (GMN) to all their plans.. to enjoy this free call, they have to make a 3-minute straight cal...
  • Nigerian Navy Recruitment Exercise 2016 is Ongoing
    Hello friends? Do you want to join the Nigerian Navy? I'll help you by providing the information you need to apply online and all the ...
  • Double your Bitcoin with trusted AIMBTC investment authority 100% Profit
    Hi oklandloaded Bitcoin users, . The best way to enjoy your coins is to make investment with it, its high time you leave all this free s...
  • Another Hideout: Another ritualist den uncovered in Lagos (Photos)
    Barely two days after a ritualist den was uncovered under the bridge at Obadeyi bus-stop, Ijaiye, Lagos-Abeokuta road, the police in Lagos...
  • Tech: Watch live TV from your android phones using Mobdro app (tested n confirm)
    Hi oklandloaded Reader's, i've got something new and special today! In this world of technology. So many want privacy and they...
  • Mtn Bis and BBC Free Unlimited Subscription On All Devices…
    Mtn bis BBC Free Unlimited Subscription for blackberry users. Here is a tips on How To Subscribe For Mtn Free on your blackberry Tex...
  • Tech:-How To Install Google Play Store On BlackBerry 10 Smartphone
    Hi Reader's...... Before it's impossible to install a fully functional version of the original Google Play Store on a Blackber...
  • If I buy Arsenal, the first thing I will do is to SACK Wenger instantly- Aliko Dangote says
    In a recent interview with Bloomberg, Africa's richest man, Aliko Dangote, said that the first thing he would do if he buys Arsenal ...

Categories

  • breaking news
  • Download
  • Entertainment
  • Events
  • F.B.T
  • FREE BROSWING
  • Free browsing
  • Gossip
  • Joke
  • jokes
  • Lifestyle
  • Mobile Zone
  • More
  • NEWS
  • OKLAND MUSIC
  • Online Money
  • Social Media
  • SPORT
  • Tech
  • TECHNOLOGY
  • TUTORIALS

ABOUT ME

Unknown
View my complete profile

Like oklandloaded on facebook

Oklandloaded's BLOG

LIke Oklandloaded on Facebook

Don't show again | X

Like oklandloaded on Facebook

Join us on Facebook...

oklandloaded-Facebook
Copyright © 2013 Welcome to oklandloaded.... - All Rights Reserved
Design by SEDRICK TIJANI OHIANI - Blogger Templates - Powered by Blogger