[WARNING] Hacked websites auto-downloading malware to Android devices

r314bd

Member
Joined
Jan 29, 2010
Messages
858
Reaction score
23
Just saw a thread about this on reddit. Someone was browsing his local pest control company's website on his Android device and a split second after visiting the page, a download masquerading as an official update.apk started automatically. Apparently legitimate websites are now being unwittingly infected by this malicious code.

A rep from Lookout posted in the thread saying they just added the exploit ("NotCompatible") to their file system monitoring/install monitoring...but it was only added within the last couple hours so be warned that this stuff is popping up, and if you aren't using some sort of anti-virus software with download monitoring on your device, you probably should.

EDIT: Lookout just added a blog post about it on their website.
 

jntdroid

Super Moderator
Premium Member
Joined
Nov 18, 2009
Messages
6,436
Reaction score
312
Location
TX
thanks for sharing that!
 

JSM9872

Super Moderator
Staff member
Premium Member
Joined
Dec 21, 2010
Messages
12,820
Reaction score
279
Location
Pennsylvania...
Current Phone Model
Galaxy S22+
Thanks for the heads up SGM.
 

Adam74

Senior Member
Joined
Apr 5, 2012
Messages
98
Reaction score
42
Location
Michigan
Current Phone Model
Galaxy Note 7
I had no idea. Thank you for the heads up!!
 

JeffDenver

Member
Joined
Apr 29, 2010
Messages
924
Reaction score
4
Just an FYI...in order for this attack to work, your phone has to have "accept APKs from unknown sources" checked in your settings. This is something that is NOT checked by default, so unless you have deliberately enabled it, you are automatically immune to this attack.

In order to actually install the app to a device, it must have the “Unknown sources” setting enabled (this feature is commonly referred to as “sideloading”). If the device does not have the unknown sources setting enabled, the installation will be blocked.

The Official Lookout Blog | UPDATE: Security Alert: Hacked Websites Serve Suspicious Android Apps (NotCompatible)

From what I understand, even then you will still be prompted to install. It won't ninja install. I don't think any APKs can do that, even official ones. You don't need any security apps like Lookout installed. You can be immune to this attack using only native tools.
 

dolpns13

Member
Joined
May 10, 2010
Messages
416
Reaction score
0
Location
Dirty Jersey
JeffDenver said:
Just an FYI...in order for this attack to work, your phone has to have "accept APKs from unknown sources" checked in your settings. This is something that is NOT checked by default, so unless you have deliberately enabled it, you are automatically immune to this attack.

From what I understand, even then you will still be prompted to install. It won't ninja install. I don't think any APKs can do that, even official ones. You don't need any security apps like Lookout installed. You can be immune to this attack using only native tools.

Where is this option in the settings?
 

rherron

Member
Joined
Jul 1, 2011
Messages
294
Reaction score
5
No Amazon App Store without checking off to allow installation of non-Market applications.
 
Top