ISC StormCast for Monday, September 23rd 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 23 September 2019
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, September 23rd, 2019 edition of the Sandsenet Storm Storners, Stormcast. |
| 0:08.0 | My name is Johannes Ulrich, and I'm recording from London, England. |
| 0:13.8 | Mobile Security Company One Dara came across some suspicious applications in Google's Play Store. Both applications they looked at are selfie apps. |
| 0:24.5 | Essentially, applications allow you to apply different filters to images before you upload them, |
| 0:30.9 | and both have permissions and are using these permissions to display ads. Of course, there are plenty of mobile applications that use advertisements to monetize the |
| 0:43.3 | application itself. |
| 0:45.3 | In this case, however, they're going a little bit further than just displaying simple ads. |
| 0:51.3 | For example, this application creates a shortcut to itself, then deletes the actual |
| 0:58.3 | application icon, making it more difficult to delete the actual application. If a user now |
| 1:04.8 | deletes the shortcut, believing that they remove the application, well, they actually didn't. Next, |
| 1:10.8 | the application also obtains the system alert window permission. |
| 1:15.0 | This allows the application to display full page ads on the mobile device, |
| 1:19.9 | and it does at least one of these applications. |
| 1:23.9 | Also ask for the receive boot completed permission, |
| 1:27.4 | which allows it to launch itself once |
| 1:30.4 | the phone is started. |
| 1:32.1 | So in the end effect, what you end up with is an application that is hard to install and |
| 1:38.2 | that will display full page ads after your phone booted. |
| 1:43.8 | Now these applications had pretty bad ratings but still |
| 1:48.1 | somehow one and a half million users downloaded them. One of the problems may also be |
| 1:54.1 | that probably for many users the Android permission system is a little bit cryptic so they |
| 2:00.4 | tend to just click okay in this |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

