Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.7K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Android malware on the Google Play Store gets 2 million downloads

Android malware on the Google Play Store gets 2 million downloadsPost Views: 46
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-3.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes
Cybersecurity researchers have discovered adware and information-stealing malware on the Google Play Store last month, with at least five still available and having amassed over two million downloads.
Adware infections displaying unwanted advertisements that can be particularly intrusive, degrade the user experience, deplete the battery, generate heat, and even cause unauthorized charges.

This software generally tries to hide by masquerading as something else on the host device and makes money for remote operators by forcing the victim to perform views or clicks on affiliated advertisements.

However, information-stealing Trojans are far more nefarious, stealing login credentials for other sites you frequent, including your social media and online banking accounts. Infiltrating the Google Play StoreAnalysts at Dr. Web antivirus report that adware apps and data-stealing Trojans were among the most prominent Android threats in May 2022.

At the top of the report are spyware apps that can steal information from other apps’ notifications, primarily to snatch one-time 2FA passcodes (OTP) and take over accounts.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png Among the many threats that managed to infiltrate the Google Play Store, the following five are still available:

* PIP Pic Camera Photo Editor – 1 million downloads, malware masquerading as image-editing software, but which steals the Facebook account credentials of its users.
* Wild & Exotic Animal Wallpaper – 500,000 downloads, an adware trojan that replaces its icon and name to ‘SIM Tool Kit’ and adds itself to the battery-saving exceptions list.
* ZodiHoroscope – Fortune Finder – 500,000 downloads, malware that steal Facebook account credentials by tricking users into entering them, supposedly to disable in-app ads.
* PIP Camera 2022 – 50,000 downloads, camera effects app that is also a Facebook account hijacker.
* Magnifier Flashlight – 10,000 downloads, adware app that serves videos and static banner ads.
https://www.bleepstatic.com/images/news/u/1220909/Android%20malware/applications.png
<figcaptionThree malicious applications still available on the Play Store
Bleeping Computer has contacted Google to inform them about the above applications and verify if the existing versions were cleaned and resubmitted or are still as dangerous as described in Dr. Web’s report.

However, judging from recent user reviews, these apps are still demonstrating malicious functionality and don’t deliver on their features promises.
https://www.bleepstatic.com/images/news/u/1220909/Android%20malware/user-reviews.png
<figcaptionRecent user reviews for PIP Pic Camera Photo Editor (Play Store)
See Also: This new Linux malware is ‘almost impossible’ to detect Other applications spotted by Dr. Web’s antivirus team on the Play Store in May 2022 include a racing game, a deleted image recovery tool, a fake state compensation app targeting Russian users, and a “free access” app for the Only Fans platform.
https://www.bleepstatic.com/images/news/u/1220909/Android%20malware/driving-real.png
<figcaptionFake game app that pushed advertisements (Dr. Web)
These apps have since been removed from the Play Store, but users who installed them on their devices need to remove them and also run a full AV[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Android malware on the Google Play Store gets 2 million downloads Android malware on the Google Play Store gets 2 million downloadsPost Views: 46 Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon…
scan to uproot any remnants as well.
See Also: Recon Tool: Domain Analyzer Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com Hydra malware infiltrationResearchers at Cyble have also spotted the Hydra banking trojan on the Google Play Store, recently observed targeting banking customers in Europe.

The malware masqueraded as a PDF document manager with text to PDF and QR code scanning features and amassed 10,000 downloads.
https://www.bleepstatic.com/images/news/u/1220909/Android%20malware/pdf-hydra.webp
<figcaptionHydra hiding in a PDF manager app on the Play Store (Cyble)
Cyble told Bleeping Computer that the malicious app was on the Play Store until June 9, 2022, but Google has since removed it.

However, the same PDF app is still available on third-party stores like APKAIO.com and APKCombo.com, so beware.
See Also: The Difference between Vulnerability Assessment and Pentesting
Source: bleepingcomputer.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Linux-90x90.jpg New Linux rootkit, Syslogk uses magic packets to trigger backdoor1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Header-Python-Packages-Blog-Final-Image-90x90.jpg PyPI package ‘keep’ mistakenly included a password stealer2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/venom_superhero_movie_tom11_hardy-wallpaper-1920x1080-980x551-1-90x90.jpg This new Linux malware is ‘almost impossible’ to detect5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/ran-download-33-1-e1639685560151-90x90.jpeg Black Basta Ransomware Teams Up with Malware Stalwart Qbot6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/InstallerFileTakeOver-Zero-Day-Security-Vulnerability-All-Windows-OS-Versions-90x90.jpg New ‘DogWalk’ Windows zero-day bug gets free unofficial patches7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/ipad_update_1200x675-90x90.jpg Security Fixes Won’t Require Full iOS Update in iOS 16, Will Be Installed Automatically1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Confluence-90x90.jpg Exploit released for Atlassian Confluence RCE bug, update now1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/be60-article-210907-confluence-body-text-90x90.png Critical Atlassian Confluence zero-day actively used in attacks2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Microsoft-releases-solutions-for-a-zero-day-vulnerability-90x90.jpg New Windows Search zero-day added to Microsoft protocol nightmare2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/3266-90x90.jpg Hackers steal WhatsApp accounts using call forwarding trick2 weeks ago
The post Android malware on the Google Play Store gets 2 million downloads first appeared on Black Hat Ethical Hacking.
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Callow

Is there anyway to use "Callow" to brute force a website with no username. The website im trying it on is for an internet mystery and the page only needs a password no username but the program requires one (to the best of my knowledge. GitHub for Callow (edit: grammar)

submitted by /u/_TheOneTrueBean_
[link] [comments]
hacking: security in practice
How do I turn off tamper protection through powershell?

I'm trying to do a reverse shell attack on my windows computer from my linux vm, and the to run the powershell script on the client side, i need to disable real time protection manually, but i figured out a way to disable it by a powershell script, but to run the script and disable real time protection, first i need to disable tamper protection...So is there a way to disable tamper protection through a powershell command?

submitted by /u/Aryangsuktekar
[link] [comments]
hacking: security in practice
DrayTek Bruteforce

Hi, few days ago i got my hands on a DrayTek Vigor2760 router to use as a modem for my home network, however once i reset the router, it did not go back to the default credentials, i got in touch with DrayTek, and they advised it is likely for it to be a custom firmware, and they are unable to help, They advised its best to get in touch with the supplier of the router for the default credentials. not knowing who the supplier is, i attempted to bruteforce the webapp using OWASP zap. after having a look at the post request that is sent to the router, i could see that the fields that are sent out are more than username and password.

aa=dGVzdA%3D%3D&ab=AA%3D%3D&sslgroup=-1&sFormAuthStr=R8riZC8XxeWxi5t

breaking this down i could see that there are these fields: aa: this seems to be the username is BASE64 encoding ab: password in BASE64 sslgroup: looking at the name i can see its probably has to do with the HTTPS or smth but please let me know if im wrong. and lastly, sFormAuthStr.

looking at these fields, what is the best way to attack this webapp, any ideas or approaches i need to try? any links that i can have a look at that guides me to the right direcion?

it is worth mentioning that there is nothing illegal going on and i own the router, it was given to me by a friend who had this collecting dust in his attic.

Thank you :)

submitted by /u/h0ly_k0w
[link] [comments]