Researchers Reveal New Toast Overlay Attack on Android Devices

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Feb 4, 2016
2,520
Mobile security experts from Palo Alto Networks have detailed a new attack on Android devices that uses "Toast" notifications to help malware in obtaining admin rights or access to Android's Accessibility service — often used to take over users' smartphones.

During the past few years, most of the top Android malware has used the same trick to get full control over a user's device.

That trick relied on malware fooling users during an app installation process to grant it the permission to display content on top of other apps — via the "Draw on top" permission.

Once malicious apps obtained this permission, they would use it to display intrusive popups on the user screen, asking the user to confirm some message or take some action. In reality, the app would request access to the Android Accessibility service but use the "Draw on top" permission to display fake messages on top of the "Activate" button.

AndroidCloakDagger.png


Similarly, malicious apps would use the same "Draw on top" permission to display fake content on top of the popup that grants the attacker admin rights.

This technique was known and used in live attack for at least two years but was explained for the first time in depth in a research paper named "Cloak & Dagger," a name that's now used to describe this entire attack routine.
 

Solarquest

Moderator
Verified
Staff Member
Malware Hunter
Well-known
Jul 22, 2014
2,525
From the article above some good news .

...
All Android versions up to 7.0 are affected
Palo Alto says all versions of Android, except the latest (Android 8.0 Oreo), are vulnerable to Toast overlay attacks.

....
Android OS versions with the September 2017 security patch levels are safe against Toast overlay attacks.
...
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top