Custom Search

Bad Bad Piggies On Google Play

One of these things is not like the others.

No, not the “Full Guide” — we’re referring to the “Bad Pigs” by Dan Stokes.

The app’s description:

Wow. More than 10,000 installs since May 25, 2013.

AppBrain, an Android app portal, doesn’t correct for relevance, so “Bad Pigs” ranks first.

Dan’s contact …

5 signs you’ll notice if your social media account has been hacked

We wrote in the article How to protect your social media account 10 tips how to protect your account.

But … do you know if your account has been hacked?

Here are some tips which can give you a pretty clear indication that your account has been hacked:

1. You notice posts that your account …

Fraudulent Adult Dating Services Turn 10 Years Old, Still Evolving

McAfee Mobile Research monitors adult one-click-fraud applications on Google Play that are targeted at Japanese users. Although the attackers appeared to have stopped uploading these apps in May, they have now resumed the attacks. We have confirmed about 600 malicious applications have been published since the beginning of April.

We have also confirmed that another type …

For Your Satisfaction – Android:Satfi-A [Trj]

We all have our favorite apps for all the things we do. I use Shazam when I don’t know what song is playing, Maps when I’m lost, FlightRadar24 when I’m curious about the plane flying over my head. These apps are there for my satisfaction; they meet some need.

Each of us …

1Password – your desert island second choice

In April we asked our community which app they would choose above all others take with them to a desert island for a month. While on the island they would have internet access but could not download any further apps.

The clear winner was WhatsApp with over 400 votes, and last week we covered Facebook …

Homemade Browser Targeting “Banco do Brasil” Users

Cybercriminals in Brazil appear to have come up with a new tactic to lure users into giving up their login information. A few days ago, we found a post on a Brazilian forum offering a browser that could access the website of the Banco do Brasil without using the needed security plugin.

Figure 1. …

Meet the new paid-archive malware families

In a previous post, “Fake apps: Behind the effective social strategy of fraudulent paid-archives,” we exposed the social engineering technique behind Win32/Pameseg - our detection for a family of “paid-archives.”

We described the use of “low-ball” techniques and explained how users are led to believe they are making an informed choice. However, the choice ultimately leads to …

Apparent security certificate turns out to be Android malware – Offered app sneakily gains access to mTANs

The email

Potential victims receive an email with an impersonal form of address and more or less detailed information about the EV-SSL certification process. G Data SecurityLabs have registered four different email designs so far.

Here is a selection of subject lines encountered so far:

EV-SSL-Zertifikat-App im Smartphone Betriebssystem EV-SSL-Zertifikat. Smartphone Betriebssystem Extended Validation-Zertifikate …

Who Viewed Your Profile – More ways to experience Facebook – Scam

Scam Message: Who Viewed Your Profile – Introducing the new “Who Viewed Your Profile” feature on facebook!

The scam creators cleverly import the profile pictures of the user’s Facebook friends to make the scam appear more legitimate.

Scam Type: Profile Viewer, Rogue Browser Extension

Trending: March 2013

Why it’s a Scam:

Clicking the scam link takes you to an external …

Compromised Yahoo accounts spread Android malware

The surest way to know that an attack method is working for a malware gang is seeing the method repeated over a period of several months. In Commtouch’s October Trend Report we described an attack targeting Android users. Last week saw a repeat of the attack with a few refinements. The main elements:

Single link …

Hello from Malaysia

In mid-February 2013 a Kaspersky user from Malaysia asked us to check a Google Play application called My HRMIS & JPA Demo developed by Nur Nazri.

The user was suspicious about the large number of permissions required by the app, though its only stated function was to open four websites.

Airpush exploited to spread Trojans onto Android devices

Russian anti-virus company Doctor Web is warning users that the Airpush Mobile Ad network is often being exploited to spread Android.SmsSend Trojans. Unfortunately, messages displayed by Airpush can confuse users into downloading malware.

Doctor Web has been receiving complaints regarding false positives by Dr.Web for Android; the anti-virus had been detecting Android.SmsSend.315.origin in the application …

Malware infects Android and Windows at the same time

Thousands of new malwares come to our virus lab daily. The target could be both Android devices and Windows computers. They’re being detected under the Android:Ssucl-X name. The malwares are being spread through false apps to free up memory of the devices and enhance their performance. They were available at Google Play as Superclean (published …