ISC StormCast for Friday, January 18th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 18 January 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, January 18th, 2019 edition of the Santernet Storm Center's |
| 0:07.5 | Stormcast. My name is Johannes Ulrich and the time I'm recording from Jacksonville, Florida. |
| 0:14.8 | During Micro came across an interesting malicious application in Google's Play Store that |
| 0:20.7 | masked itself as a battery saver application. |
| 0:24.6 | Now, it appears to me that battery saver applications are sort of one of those favorites |
| 0:30.6 | to actually hide malware, probably because they don't really do much visibly to the user if they |
| 0:36.2 | do anything. |
| 0:37.9 | Now in this particular case, the developer of the malware actually jumped through some |
| 0:43.2 | additional hoops to make it more difficult to detect that malware is running. |
| 0:49.3 | The malware will only run if the phone is being moved. |
| 0:53.8 | Now, Trent Micro's assumption here is that the reason |
| 0:57.9 | for this is that if the malware is running in a sandbox, so someone is trying to analyze it, then |
| 1:04.2 | typically there are no motion sensors or if motion sensors are emulated by the sandbox, then they're stationary. |
| 1:12.0 | There is no motion being simulated. |
| 1:14.6 | So as a result, this particular malware will only run while the phone is being moved. |
| 1:21.2 | Now once the malicious code actually gets to run it, will then create a pop-up offering a system |
| 1:27.1 | update. |
| 1:34.9 | So this is how then the actual banking malware is being installed on the phone with the sufficient privileges of course to have access to the system. |
| 1:39.3 | Now about 5,000 users downloaded this particular malware. |
| 1:46.5 | The vast majority of the victims happened to be in Japan. |
| 1:51.7 | And Twitter fixed a 5-year-old vulnerability in its Android app that may have exposed protected |
| 2:00.0 | tweets. Now, in Twitter you have the option to send protected tweets which are limited. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

