Android StrandHogg vulnerability demo | Exploit | PoC | Malware

  Рет қаралды 23,354

Android Infosec

Android Infosec

4 жыл бұрын

Android StrandHogg vulnerability
Vulnerability allows malicious app to masquerade as any other app on the device.
If you launch Facebook, malware is executed.
In the video is simple exploitation of the vulnerability.
More info: promon.co/security-news/stran...
SUBSCRIBE: / lukasstefankoinfosec
FOLLOW: / lukasstefanko

Пікірлер: 27
@mobilehacker
@mobilehacker 4 жыл бұрын
[Update] StrandHogg was used by Android banking Trojan (BankBot) found on Google Play in 2017 Using "taskAffinity" it impersonated Google Play Store app to request credit card details from the victim. I created a PoC video to demonstrate StrandHogg in this 2 years old malware: twitter.com/ESETresearch/status/1202154415584694272 More info: www.welivesecurity.com/2017/09/25/banking-trojan-returns-google-play/
4 жыл бұрын
Hello Lukas. I can't clean up fake Flash Player apps from my phone ( Samsung Note 5 ) That fake Player don't let me clean itself. PLEASE help me how can I do it ??
@codenamepk
@codenamepk 3 жыл бұрын
Which application is using in your phone to show the methods
@atalyy
@atalyy 4 жыл бұрын
Hello Lukas :) I have a quick question, will my mcafee mobile antivirus stop all or majority of viruses from play store? Thanks in advance.
@mobilehacker
@mobilehacker 4 жыл бұрын
Hey Monika, it depends because antivirus simply cant detect this single thing as issue however, if it is used in malicious app then your mobile antivirus should protect you. So, the quick answer is yes, your antivirus can protect you if it is used in app with malicious functionality.
@atalyy
@atalyy 4 жыл бұрын
@@mobilehacker Thank you
@user4gent416
@user4gent416 4 жыл бұрын
Download link for PoC please. I want to try it on my phone.
@truelies5431
@truelies5431 4 жыл бұрын
My old phone has it, it was disguised as Ccleaner, the phone had a lot of ads popping everywhere which made me install Ccleaner didn't help much so I decided to uninstall chrome (since ads were displaying as notifications from chrome) still didn't work ... Then decided to reinstall all apps.. Ads stopped popping but somehow the fake Ccleaner app keeps coming back ( it's called fireplo version 1.0) tried denying permissions..deleting "APPMARKET" folder which had pictures of ads in it...it just keeps coming back..how?
@nmsepic8798
@nmsepic8798 4 жыл бұрын
Because your phone infected with adware malware if you are using old Android version then just reset your phone clear phone cache as well Also try to update your Android version
@truelies5431
@truelies5431 4 жыл бұрын
@@nmsepic8798 Thanks buddy, I did that...I also realized there was a fake program on old family PC that pushed android malware whenever ADB was available
@lucamaina5001
@lucamaina5001 4 жыл бұрын
Do you know if and when the patch will be published?
@mobilehacker
@mobilehacker 4 жыл бұрын
I dont think there will be any, since Google doesn't recognize it as bug. This is a legit Android functionality but, it can be misused for phishing by malware.
@goodluck6948
@goodluck6948 4 жыл бұрын
@@mobilehacker that's really stupid, insanely easy phishing
@kimberlyanaya7963
@kimberlyanaya7963 4 жыл бұрын
dónde se descarga?
@shaiksohel9821
@shaiksohel9821 3 жыл бұрын
Call data app hack how to plz bro
@MikeHansondev
@MikeHansondev 4 жыл бұрын
Couldn't you just put the Facebook icon and name over the clean activity in this demo? lol
@mobilehacker
@mobilehacker 4 жыл бұрын
That would do the trick however, that is why after testing the first PoC I actually launched Facebook to demonstrate that it is the real one. :).
@arthursumer6012
@arthursumer6012 4 жыл бұрын
I also successfully tested this code and I will record an attack video
@xdevman
@xdevman 4 жыл бұрын
:)
@oryonsf
@oryonsf 4 жыл бұрын
where is exploit ?
@mobilehacker
@mobilehacker 4 жыл бұрын
Exploit is on my local disk. I will not publish PoC code, since the issue is not fixed.
@yuval6508
@yuval6508 4 жыл бұрын
Skiddie...
@MrDamuni
@MrDamuni 4 жыл бұрын
Yuval 🖕🏼
@blurryface7840
@blurryface7840 4 жыл бұрын
I have the exploit! DM : bboyben234@gmail.com
@MrDamuni
@MrDamuni 4 жыл бұрын
Marsh Arcan it's better by telegram or protonmail bro.
StrandHogg 2.0: Explained
21:45
Wultra
Рет қаралды 1,9 М.
Was ist im Eis versteckt? 🧊 Coole Winter-Gadgets von Amazon
00:37
SMOL German
Рет қаралды 31 МЛН
WHO DO I LOVE MOST?
00:22
dednahype
Рет қаралды 80 МЛН
StrandHogg- The New Android Vulnerability
2:27
Securemetric
Рет қаралды 12 М.
CVE-2021-44228 (log4shell) Vulnerable minecraft server showcase
0:13
Marek Vospěl
Рет қаралды 1,8 М.
How to Remove Spyware from Android | Identify Spyware Apps
5:26
MalwareFox
Рет қаралды 365 М.
CVE-2019-11932 PoC Demonstration
1:02
Trend Micro
Рет қаралды 9 М.
MAJOR EXPLOIT: This GIF can Backdoor any Android Phone (sort of)
12:00
Stagefright Exploit Demo - CVE 2015-3864 Metasploit Module
1:50
Android.Elite (Android Malware)
8:51
danooct1
Рет қаралды 662 М.
Blue Mobile 📲 Best For Long Audio Call 📞 💙
0:41
Tech Official
Рет қаралды 1 МЛН
В России ускорили интернет в 1000 раз
0:18
Короче, новости
Рет қаралды 1,5 МЛН