NSA; Malware through Google Play and Samsung App Store

Status
Not open for further replies.

Ink

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 8, 2011
22,361
"The NSA developed a plan to deliver malware through Google and Samsung app stores, according to newly published documents obtained by Edward Snowden and published by The Intercept. The documents details a program called IRRITANT HORN, which delivers malware by intercepting web traffic to and from mobile application servers.

One slide details Samsung's update protocol, while another pinpoints the Google Play servers in France, used to deliver updates to phones throughout northern Africa.

r32PLgO.png


Once the path to those servers was established, the NSA could intercept traffic before it reached the servers, injecting malware to specific users through a man-in-the-middle attack. The files would appear to come from a trusted app store, but they would really be coming from the NSA. From there, the NSA could deliver tools from its extensive catalog of surveillance programs, including pulling a user's contact list or reporting their location in near-real-time.

Both Samsung and Google employ TLS encryption to protect against man-in-the-middle attacks like this, but cryptographers have been speculating for years that the NSA has found a way to break or circumvent those protections."

Read more: NSA planned to hijack Google Play App Store and Hack Smartphones
https://firstlook.org/theintercept/2015/05/21/nsa-five-eyes-google-samsung-app-stores-spyware/
 
Last edited:

comfortablynumb15

Level 7
Verified
May 11, 2015
326
Is there nothing these people will not do? I hope Google publicly denounces it and takes their billions to further security instead of their own damned data collection.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top