Irish Sun
27 May 2017, 07:25 GMT+10
CALIFORNIA, U.S. - Researchers from UC Santa Barbara and Georgia Tech have discovered a new type of Android attack, called Cloak and Dagger.
A report noted that the Cloak and Dagger takes advantage of the Android UI and they need just two permissions to get rolling.
According to the researchers, the Cloak and Dagger operates secretly on the smartphone, allowing hackers to log keystrokes or install malicious softwares without alarming the owner.
Researchers pointed out that since Android OS automatically grants these permissions for any app from the Play Store, this would mean that once a hacker is in the system, it is possible to trick the user into granting the a11y permission.
They noted that the app hides a layer of malicious activity under seemingly harmless visuals and lures users to click on unseen buttons and keystroke loggers.
In their report, the researchers noted, "To make things worse, we noticed that the accessibility app can inject the events, unlock the phone, and interact with any other app while the phone screen remains off. That is, an attacker can perform a series of malicious operations with the screen completely off and, at the end, it can lock the phone back, leaving the user completely in the dark."
Further, one of the researchers, Yanick Fratantonio, said, "We've been in close touch with the researchers and, as always, we appreciate their efforts to help keep our users safer. We have updated Google Play Protect - our security services on all Android devices with Google Play - to detect and prevent the installation of these apps. Prior to this report, we had already built new security protections into Android O that will further strengthen our protection from these issues, moving forward."
Get a daily dose of Irish Sun news through our daily email, its complimentary and keeps you fully up to date with world and business news as well.
Publish news of your business, community or sports group, personnel appointments, major event and more by submitting a news release to Irish Sun.
More InformationTokyo, Japan: On June 28, Japan baked under intense heat for a fourth successive day, with temperatures breaking nearly 150-year-old ...
ALBANY, New York: A New York state judge has struck down a recent law giving 800,000 non-citizen New York City ...
DUBAI, UAE: The Arab states have built significant amounts of solar and wind power installations, and are in line to ...
LONDON, England: A second referendum on Scottish independence is set to be held in October 2023. The Scottish government, led ...
LISBON, Portugal: Tuvalu Foreign Minister Simon Kofe walked out of the opening cermonies of this week's United Nations Ocean Conference ...
SULAWESI, Indonesia: Using just a rope, an Indonesian man, supported by fellow villagers on the island of Sulawesi, captured a ...
LONDON, England: A second referendum on Scottish independence is set to be held in October 2023. The Scottish government, led ...
BERLIN, Germany: A German Interior Ministry spokesperson has said that in a bid to relieve airports overwhelmed by staff shortages ...
PARIS, France: In a written statement made this week confirming a report from broadcaster RTL, France's energy ministry said the ...
WATFORD, UK: Watford F.C. has cancelled a friendly match against the Qatar national team due to the Gulf country's human ...
JAKARTA, Indonesia: Indonesian President Joko Widodo has said that he will urge his Russian and Ukrainian counterparts to open peace ...
ISTANBUL, Turkey: Turkish police detained dozens of people after local authorities banned Istanbul's annual Pride parade from going ahead this ...