Sideloading – INDIA NEWS https://www.indiavpn.org News Blog Tue, 20 Feb 2024 15:44:33 +0000 en-US hourly 1 https://wordpress.org/?v=6.7.1 New Malicious PyPI Packages Caught Using Covert Side-Loading Tactics https://www.indiavpn.org/2024/02/20/new-malicious-pypi-packages-caught-using-covert-side-loading-tactics/ https://www.indiavpn.org/2024/02/20/new-malicious-pypi-packages-caught-using-covert-side-loading-tactics/#respond Tue, 20 Feb 2024 15:44:33 +0000 https://www.indiavpn.org/2024/02/20/new-malicious-pypi-packages-caught-using-covert-side-loading-tactics/ [ad_1]

Feb 20, 2024NewsroomMalware / Supply Chain Security

Malicious PyPI Packages

Cybersecurity researchers have discovered two malicious packages on the Python Package Index (PyPI) repository that were found leveraging a technique called DLL side-loading to circumvent detection by security software and run malicious code.

The packages, named NP6HelperHttptest and NP6HelperHttper, were each downloaded 537 and 166 times, respectively, before they were taken down.

“The latest discovery is an example of DLL sideloading executed by an open-source package that suggests the scope of software supply chain threats is expanding,” ReversingLabs researcher Petar Kirhmajer said in a report shared with The Hacker News.

Cybersecurity

The name NP6 is notable as it refers to a legitimate marketing automation solution made by ChapsVision. In particular, the fake packages are typosquats of NP6HelperHttp and NP6HelperConfig, which are helper tools published by one of ChapsVision’s employees to PyPI.

In other words, the goal is to trick developers searching for NP6HelperHttp and NP6HelperConfig into downloading their rogue counterparts.

Malicious PyPI Packages

Contained within the two libraries is a setup.py script that’s designed to download two files, an actual executable from Beijing-based Kingsoft Corporation (“ComServer.exe”) that’s vulnerable to DLL side-loading and the malicious DLL to be side-loaded (“dgdeskband64.dll”).

In side-loading the DLL, the aim is to avoid detection of the malicious code, as observed previously in the case of an npm package called aabquerys that also leveraged the same technique to execute code capable of deploying a remote access trojan.

The DLL, for its part, reaches out to an attacker-controlled domain (“us.archive-ubuntu[.]top”) to fetch a GIF file that, in reality, is a piece of shellcode for a Cobalt Strike Beacon, a post-exploitation toolkit used for red teaming.

Cybersecurity

There is evidence to suggest that the packages are part of a wider campaign that involves the distribution of similar executables that are susceptible to DLL side-loading.

“Development organizations need to be aware of the threats related to supply chain security and open-source package repositories,” security researcher Karlo Zanki said.

“Even if they are not using open-source package repositories, that doesn’t mean that threat actors won’t abuse them to impersonate companies and their software products and tools.”

Found this article interesting? Follow us on Twitter and LinkedIn to read more exclusive content we post.



[ad_2]

Source link

]]>
https://www.indiavpn.org/2024/02/20/new-malicious-pypi-packages-caught-using-covert-side-loading-tactics/feed/ 0
Google Starts Blocking Sideloading of Potentially Dangerous Android Apps in Singapore https://www.indiavpn.org/2024/02/08/google-starts-blocking-sideloading-of-potentially-dangerous-android-apps-in-singapore/ https://www.indiavpn.org/2024/02/08/google-starts-blocking-sideloading-of-potentially-dangerous-android-apps-in-singapore/#respond Thu, 08 Feb 2024 14:33:48 +0000 https://www.indiavpn.org/2024/02/08/google-starts-blocking-sideloading-of-potentially-dangerous-android-apps-in-singapore/ [ad_1]

Feb 08, 2024NewsroomData Protection / Mobile Securit

Android Apps

Google has unveiled a new pilot program in Singapore that aims to prevent users from sideloading certain apps that abuse Android app permissions to read one-time passwords and gather sensitive data.

“This enhanced fraud protection will analyze and automatically block the installation of apps that may use sensitive runtime permissions frequently abused for financial fraud when the user attempts to install the app from an Internet-sideloading source (web browsers, messaging apps or file managers),” the company said.

The feature is designed to examine the permissions declared by a third-party app in real-time and look for those that seek to gain access to sensitive permissions associated with reading SMS messages, deciphering or dismissing notifications from legitimate apps, and accessibility services that have been routinely abused by Android-based malware for extracting valuable information.

Cybersecurity

As part of the test, users in Singapore who attempt to sideload such apps (or APK files) will be blocked from doing so via Google Play Protect and displayed a pop-up message that reads: “This app can request access to sensitive data. This can increase the risk of identity theft or financial fraud.”

“These permissions are frequently abused by fraudsters to intercept one-time passwords via SMS or notifications, as well as spy on-screen content,” Eugene Liderman, director of the mobile security strategy at Google, said.

The change is part of a collaborative effort to combat mobile fraud, the tech giant said, urging app developers to follow best practices and review their apps’ device permissions to ensure it does not violate the Mobile Unwanted Software principles.

Android Apps

Google, which launched Google Play Protect real-time scanning at the code level to detect novel Android malware in select markets like India, Thailand, Singapore, and Brazil, said the effort allowed it to detect 515,000 new malicious apps and that it issued no less than 3.1 million warnings or blocks of those apps.

The development also comes as Apple announced sweeping changes to the App Store in the European Union to comply with the Digital Markets Act (DMA) ahead of the March 6, 2024, deadline. The changes, including Notarization for iOS apps, are expected to go live with iOS 17.4.

Cybersecurity

The iPhone maker, however, repeatedly emphasized that distributing iOS apps from alternative app marketplaces exposes E.U. users to “increased privacy and security threats,” and that it does not intend to bring them to other regions.

“This includes new avenues for malware, fraud and scams, illicit and harmful content, and other privacy and security threats,” Apple said. “These changes also compromise Apple’s ability to detect, prevent, and take action against malicious apps on iOS and to support users impacted by issues with apps downloaded outside of the App Store.”

Found this article interesting? Follow us on Twitter and LinkedIn to read more exclusive content we post.



[ad_2]

Source link

]]>
https://www.indiavpn.org/2024/02/08/google-starts-blocking-sideloading-of-potentially-dangerous-android-apps-in-singapore/feed/ 0