Vulnerabilities / Threats
8/17/2010
01:20 PM
50%
50%

Spyware Hidden In Android Snake Tap Game

Free app is paired with GPS Spy, software that monitors a targeted device's location.

Spyware Hidden In Android Snake Tap Game
(click image for larger view)
Spyware Hidden In Android Snake Tap Game
At first glance, the Android Market game Tap Snake appears to be a free, touchscreen clone of the popular "snake" computer game that dates from the 1970s -- and it is. But that's not all.

"It turns out to be a client for a commercial spying application called GPS Spy," according to Mikko Hypponen, chief research officer at F-Secure.

One giveaway that Tap Snake isn't just a game is that it accesses GPS services. Another is that even if a user attempts to disable the game, it still runs in the background.

According to the developer's description, tracking a phone with GPS Spy requires installing Tap Snake on the target phone and registering an e-mail address in the application, which generates a unique code. Input this code and the related e-mail into GPS Spy, and you can see a trace of the target phone's location for 24 hours, in 15-minute increments.

That's because every 15 minutes, Snake Tap will transmit its location "to an application running on Google's free App Engine service," according to Symantec's Security Response blog. "The silver lining here is that for the application to really be used maliciously, an attacker would need to have access to the phone to install the program."

Alternately, an attacker could trick someone into installing the program as well as accepting the application's requests to use specific APIs. "This would probably require a dash of social engineering as well -- something like 'Hey, let me show you this cool game,'" said Symantec. "Think cheating spouses or keeping tabs on children."

Of course, plenty of applications already provide such functionality, and clearly disclose what they do. In contrast, Snake Tap does not, which is why it's earning a "Trojan application" classification from antivirus providers.

"We expect Google to remove Tap Snake from Android Market soon," said F-Secure's Hypponen. It remains to be seen, however, whether Google might also trigger an Android-wide remote application removal.

Comment  | 
Email This  | 
Print  | 
RSS
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
All Videos
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-0279
Published: 2015-03-26
JBoss RichFaces before 4.5.4 allows remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via the do parameter.

CVE-2015-0635
Published: 2015-03-26
The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.10.xS through 3.13.xS before 3.13.1S allows remote attackers to spoof Autonomic Networking Registration Authority (ANRA) responses, and consequently bypass intended device an...

CVE-2015-0636
Published: 2015-03-26
The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.10.xS through 3.13.xS before 3.13.1S allows remote attackers to cause a denial of service (disrupted domain access) via spoofed AN messages that reset a finite state machine,...

CVE-2015-0637
Published: 2015-03-26
The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.10.xS through 3.13.xS before 3.13.1S allows remote attackers to cause a denial of service (device reload) via spoofed AN messages, aka Bug ID CSCup62315.

CVE-2015-0638
Published: 2015-03-26
Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3, when a VRF interface is configured, allows remote attackers to cause a denial of service (interface queue wedge) via crafted ICMPv4 packets, aka Bug ID CSCsi02145.

Dark Reading Radio
Archived Dark Reading Radio
Good hackers--aka security researchers--are worried about the possible legal and professional ramifications of President Obama's new proposed crackdown on cyber criminals.
UPCOMING!
Wednesday, April 15, 1pm EDT

Information Security, Risk, and The Road Ahead
FULL SCHEDULE | ARCHIVED SHOWS