TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

The Judy Malware: Possibly the largest malware campaign found on Google Play

89 点作者 blaqkangel将近 8 年前

8 条评论

smilliken将近 8 年前
It looks like the common component across the apps mentioned is in the &quot;net.shinhwa21.jsylibrary&quot; namespace.<p>I made a list of the apps with that namespace, preview here: <a href="https:&#x2F;&#x2F;mixrank.com&#x2F;playstore&#x2F;apps?expiration=2017-06-30&amp;list.id=8ce2b11ce0&amp;sharedby=scott%40deltaex.com&amp;auth=5130e518573dd928" rel="nofollow">https:&#x2F;&#x2F;mixrank.com&#x2F;playstore&#x2F;apps?expiration=2017-06-30&amp;lis...</a><p>This list is a few times bigger than the ones mentioned in the article (been crawling for a long time, and try to be complete). If there&#x27;s any security folks here that want access to the APKs for research, I&#x27;m happy to share (scott at mixrank).
评论 #14449194 未加载
评论 #14457018 未加载
评论 #14450304 未加载
problems将近 8 年前
This isn&#x27;t really malware in the traditional sense, it doesn&#x27;t damage users of the app itself or harvest information from them, this is simply ad fraud, it only damages Google and its advertisers.<p>It seems to me like CheckPoint is fishing for internet points with this title.
评论 #14449313 未加载
评论 #14448092 未加载
评论 #14448432 未加载
spcelzrd将近 8 年前
There will always be bad actors, but I can&#x27;t understand why Google tolerates low level malware. At least make them work a little.
评论 #14447692 未加载
userbinator将近 8 年前
<i>Upon clicking the ads, the malware author receives payment from the website developer, which pays for the illegitimate clicks and traffic.</i><p>Are they really certain of this, or could it just be the work of someone who wants to &quot;poison the well&quot; of Google&#x27;s ad network data collection?<p>It somehow reminds me of <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=10611594" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=10611594</a> (Would CheckPoint also consider that malware?)
评论 #14450110 未加载
michaelbuckbee将近 8 年前
I&#x27;m curious if anyone has a sense for how much they made from this? I just don&#x27;t have a good sense for scale and dimensions of this.<p>If it went undetected for so long they must not have been at least somewhat conservative in their approach, so say 5mil DAU times 1 click a day at $0.25&#x2F;click. So, million-ish dollars a day?
评论 #14447894 未加载
评论 #14447884 未加载
elliottcarlson将近 8 年前
&quot;Some of the apps we discovered resided on Google Play for several years, but all were recently updated. It is unclear how long the malicious code existed inside the apps, hence the actual spread of the malware remains unknown.&quot;<p>If these apps were indeed popular, I would imagine the historical APK&#x27;s are available for the various versions on pirate sites. Simply performing a Google search for &quot;Fashion Judy: Snow Queen style apk&quot; shows downloads for different versions of it. This can give a better idea of the length of infection.
mtgx将近 8 年前
This is why no matter how much Google brags about its machine learning-powered anti-malware protection, it can&#x27;t rely solely on it to defend Android users, because it&#x27;s still a cat and mouse game with sophisticated attackers. They need to find a way to patch all devices in a timely manner.
评论 #14448260 未加载
samdung将近 8 年前
Android is the new Windows. Expecting some downvotes. But truth must be told. You&#x27;re welcome.
评论 #14447782 未加载
评论 #14447761 未加载
评论 #14448738 未加载
评论 #14448107 未加载
评论 #14448804 未加载
评论 #14447687 未加载