A new Android attack vector is taking use of a security feature in apps that handle sensitive user data to get beyond anti-tampering measures already in place. This malware is being monitored as Snowblind.
The intention behind Snowblind is to repackage a target app so that it can’t be detected when it abuses accessibility services to collect user input (like credentials) or obtains remote control access to perform malicious operations.
In contrast to other Android malware, however, Snowblind takes advantage of a Linux kernel feature called “seccomp,” or secure computing, which Android utilizes to verify the integrity of apps, in order to shield users from harmful activities like repackaging software.
After obtaining a sample from i-Sprint, the mobile app security business Promon was able to examine how Snowblind accomplishes its objective covertly read more about Snowblind malware abuses Android security feature to bypass security.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
