Android Zero-Day exploited by 3 apps available on Google Play store
File manager and photography applications present on Google Play are found to hack and track user activities.
The applications found performing these malicious activities are Camero, FileCrypt, and callCam. These applications are found to be related to Sidewinder APT, a hacking group holding their specialty in cyber espionage attacks. Security researchers have reported that these apps were exploiting a critical vulnerability in android since March last year.
CVE-2019-2215 is the vulnerability of local privilege escalation issue that allows full root compromise of a vulnerable device. The vulnerability can also be remotely used when combined with a separate browser rendering flaw. FileCrypt and Camero act as droppers, as they connect to a command and control server to download a DEX file. This DEX file further downloads the callCam app and tries to install it by exploiting privilege escalation vulnerabilities.
NPAV recommends users to always download and update apps from trusted sources. Keeping the app up-to-date will help you with the latest security patches released by the developers. Users must always pay close attention to the permission requested by the applications. Use NPAV mobile application to shield your mobile phone and data from such virus attacks.
Use NPAV and join us on a mission to secure the cyber world.
- Other (42)
- Ransomware (124)
- Events and News (26)
- Features (44)
- Security (425)
- Tips (79)
- Google (22)
- Achievements (8)
- Products (33)
- Activation (7)
- Dealers (1)
- Bank Phishing (42)
- Malware Alerts (188)
- Cyber Attack (219)
- Data Backup (11)
- Data Breach (75)
- Phishing (138)
- Securty Tips (1)
- Browser Hijack (16)
- Adware (15)
- Email And Password (67)
- Android Security (55)
- Knoweldgebase (38)
- Botnet (15)
- Updates (3)
- Alert (70)
- Hacking (57)
- Social Media (7)
- vulnerability (53)
- Hacker (31)
- Spyware (8)
- Windows (6)
- Microsoft (21)
- Uber (1)
- YouTube (1)
- Trojan (2)
- Website hacks (3)
- Paytm (1)
- Credit card scam (1)
- Telegram (3)
- RAT (5)
- Bug (3)
- Twitter (2)
- Facebook (7)
- Banking Trojan (5)
- Mozilla (2)
- COVID-19 (5)
- Instagram (2)
- NPAV Announcement (5)
- IoT Security (1)
- Deals and Offers (1)
- Cloud Security (8)
- Offers (5)
- Gaming (1)
- FireFox (2)
- LinkedIn (2)
- WhatsApp (4)
- Amazon (1)
- DMart (1)
- Payment Risk (4)
- Occasion (2)
- firewall (1)
- Cloud malware (2)
- Cloud storage (2)
- Financial fraud (5)
- Impersonation phishing (1)
- DDoS (4)
- Smishing (2)
- Whale (0)
- Whale phishing (3)
- WINRAR (2)
- ZIP (2)