Tag: bypass security

Snowblind malware abuses Android security feature to bypass security
News

Snowblind malware abuses Android security feature to bypass security

A new Android attack vector is taking use of a security feature in apps that handle sensitive user data to get beyond anti-tampering measures already in place. This malware is being monitored as Snowblind. The intention behind Snowblind is to repackage a target app so that it can't be detected when it abuses accessibility services to collect user input (like credentials) or obtains remote control access to perform malicious operations. In contrast to other Android malware, however, Snowblind takes advantage of a Linux kernel feature called "seccomp," or secure computing, which Android utilizes to verify the integrity of apps, in order to shield users from harmful activities like repackaging software. After obtaining a sample from i-Sprint, the mobile app security business Promon ...