[FSec] Bad Bad Piggies On Google Play

Newsfeed

Nachrichtenbote
One of these things is not like the others.

Bad_Bad_Piggies_Google_play_01.png


No, not the "Full Guide" — we're referring to the "Bad Pigs" by Dan Stokes.

The app's description:

Bad_Bad_Piggies_Google_play_02.png


Wow. More than 10,000 installs since May 25, 2013.

AppBrain, an Android app portal, doesn't correct for relevance, so "Bad Pigs" ranks first.

Bad_Bad_Piggies_Google_play_03.png


Dan's contact address is: [email protected].

That's fishy.

Bad_Bad_Piggies_Google_play_04.png


AppBrain has a very nice feature which lists "Concerns" as well as permissions required.

Bad_Bad_Piggies_Google_play_05.png


Boy, that's a long list of extra permissions. These particular piggies aren't just bad — they're evil.

Dan Stokes has a few other apps as well.

Bad_Bad_Piggies_Google_play_06.png


"Fruit Chop Ninja" also has more than 10,000 installs.

And here's an interesting note: the app ID, and therefore the URL, includes the word "Rovio".

Bad_Bad_Piggies_Google_play_07.png


Our Mobile Security product detects and blocks this as Android/FakeInst.CI.

We've reported the issue to Google (and Rovio) and the apps are no longer indexed by Google's search.

Stay safe out there.
On 12/06/13 At 03:11 PM

Weiterlesen...
 
Zurück
Oben