Vulnerabilities / Threats
8/17/2010
01:20 PM
50%
50%

Spyware Hidden In Android Snake Tap Game

Free app is paired with GPS Spy, software that monitors a targeted device's location.

Spyware Hidden In Android Snake Tap Game
(click image for larger view)
Spyware Hidden In Android Snake Tap Game
At first glance, the Android Market game Tap Snake appears to be a free, touchscreen clone of the popular "snake" computer game that dates from the 1970s -- and it is. But that's not all.

"It turns out to be a client for a commercial spying application called GPS Spy," according to Mikko Hypponen, chief research officer at F-Secure.

One giveaway that Tap Snake isn't just a game is that it accesses GPS services. Another is that even if a user attempts to disable the game, it still runs in the background.

According to the developer's description, tracking a phone with GPS Spy requires installing Tap Snake on the target phone and registering an e-mail address in the application, which generates a unique code. Input this code and the related e-mail into GPS Spy, and you can see a trace of the target phone's location for 24 hours, in 15-minute increments.

That's because every 15 minutes, Snake Tap will transmit its location "to an application running on Google's free App Engine service," according to Symantec's Security Response blog. "The silver lining here is that for the application to really be used maliciously, an attacker would need to have access to the phone to install the program."

Alternately, an attacker could trick someone into installing the program as well as accepting the application's requests to use specific APIs. "This would probably require a dash of social engineering as well -- something like 'Hey, let me show you this cool game,'" said Symantec. "Think cheating spouses or keeping tabs on children."

Of course, plenty of applications already provide such functionality, and clearly disclose what they do. In contrast, Snake Tap does not, which is why it's earning a "Trojan application" classification from antivirus providers.

"We expect Google to remove Tap Snake from Android Market soon," said F-Secure's Hypponen. It remains to be seen, however, whether Google might also trigger an Android-wide remote application removal.

Comment  | 
Email This  | 
Print  | 
RSS
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
All Videos
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2011-4403
Published: 2015-04-24
Multiple cross-site request forgery (CSRF) vulnerabilities in Zen Cart 1.3.9h allow remote attackers to hijack the authentication of administrators for requests that (1) delete a product via a delete_product_confirm action to product.php or (2) disable a product via a setflag action to categories.ph...

CVE-2012-2930
Published: 2015-04-24
Multiple cross-site request forgery (CSRF) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to hijack the authentication of administrators for requests that (1) add a user via an adduser action to admin/index.php or (2) conduct static PHP code injection attacks in .htusers...

CVE-2012-2932
Published: 2015-04-24
Multiple cross-site scripting (XSS) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to inject arbitrary web script or HTML via the (1) selitems[] parameter in a copy, (2) chmod, or (3) arch action to admin/index.php or (4) searchitem parameter in a search action to admin/...

CVE-2012-5451
Published: 2015-04-24
Multiple stack-based buffer overflows in HttpUtils.dll in TVMOBiLi before 2.1.0.3974 allow remote attackers to cause a denial of service (tvMobiliService service crash) via a long string in a (1) GET or (2) HEAD request to TCP port 30888.

CVE-2015-0297
Published: 2015-04-24
Red Hat JBoss Operations Network 3.3.1 does not properly restrict access to certain APIs, which allows remote attackers to execute arbitrary Java methos via the (1) ServerInvokerServlet or (2) SchedulerService or (3) cause a denial of service (disk consumption) via the ContentManager.

Dark Reading Radio
Archived Dark Reading Radio
Join security and risk expert John Pironti and Dark Reading Editor-in-Chief Tim Wilson for a live online discussion of the sea-changing shift in security strategy and the many ways it is affecting IT and business.
UPCOMING!
Tuesday, June 2, 1pm EDT

How to Develop a Data Breach Incident Response Plan
FULL SCHEDULE | ARCHIVED SHOWS