Your Android device could be at risk from a new class of attack that allows for full takeover of the smartphone. Researchers at Georgia Tech recently discovered an attack known as Cloak and Dagger. It gives cyberattackers the opportunity to undertake malicious control of an Android device without users noticing the errant activity.

Overall, malicious malware is becoming a frequent issue in the app marketplace. Researchers recently uncovered several Android apps that masqueraded as a Funny Videos app on the Google Play Store but distributed a banking Trojan.

How Is Your Device Affected?

The Cloak and Dagger attack abuses a pair of legitimate app permissions that are used across certain features on Androids. These permissions are known as SYSTEM_ALERT_WINDOW (“draw on top”) and BIND_ACCESSIBILITY_SERVICE (“a11y”). The first permission allows apps to overlap on a device’s screen, and the second lets disabled users enter inputs via voice commands.

Abuse of these permissions makes it easier for cybercriminals to potentially develop and then submit a malicious app to Google Play Store. Mashable reported that an actor could use these accepted permissions paired with a “God-Mode” app to access messages and calls, keylog and clickjack a smartphone.

In this specific attack case, the user does not necessarily need to grant permission and is not even notified of a change in device behavior. In fact, the researchers performed a 20-person user study, and no one could detect malicious activity.

How Is the Issue Being Resolved?

These attacks affect all recent versions of Android, including 7.1.2, and researchers suggested that the flaws are not yet fixed. They also said the problem could be difficult to resolve because the issues involve two standard features in Android OS.

A Google spokesperson told The Register that the technology giant has been in close contact with the researchers in Georgia. The spokesperson added the company refreshed Google Play Protect to prevent the installation of malware and detect any similar malicious apps in the future.

Google said it already built new security protections into Android O that will strengthen protection in the future. However, Google O is scheduled for release later this year, and users will need to wait for higher levels of protection.

How Should Users React?

Georgia Tech said users should check which applications have access to the draw on top and the a11y permissions. They can also disable the draw on top permission used in Android 7.1.2.

The Hacker News explained the most comprehensive way to avoid hacking is to download apps from trusted and verified developers in the Google Play Store. The article also advised users to check for app permissions before installation.

News of this attack comes in the wake of a continuing run of stories involving mobile malware and banking Trojans. Users should stay alert to potential security risks and ensure app permissions are both monitored and restricted. If an app seems to ask for more permissions than necessary, avoid it all together.

More from

Bridging the 3.4 Million Workforce Gap in Cybersecurity

As new cybersecurity threats continue to loom, the industry is running short of workers to face them. The 2022 (ISC)2 Cybersecurity Workforce Study identified a 3.4 million worldwide cybersecurity worker gap; the total existing workforce is estimated at 4.7 million. Yet despite adding workers this past year, that gap continued to widen.Nearly 12,000 participants in that study felt that additional staff would have a hugely positive impact on their ability to perform their duties. More hires would boost proper risk…

The Evolution of Antivirus Software to Face Modern Threats

Over the years, endpoint security has evolved from primitive antivirus software to more sophisticated next-generation platforms employing advanced technology and better endpoint detection and response.  Because of the increased threat that modern cyberattacks pose, experts are exploring more elegant ways of keeping data safe from threats.Signature-Based Antivirus SoftwareSignature-based detection is the use of footprints to identify malware. All programs, applications, software and files have a digital footprint. Buried within their code, these digital footprints or signatures are unique to the respective…

How Do Threat Hunters Keep Organizations Safe?

Neil Wyler started his job amid an ongoing cyberattack. As a threat hunter, he helped his client discover that millions of records had been stolen over four months. Even though his client used sophisticated tools, its threat-hunting technology did not detect the attack because the transactions looked normal. But with Wyler’s expertise, he was able to realize that data was leaving the environment as well as entering the system. His efforts saved the company from suffering even more damage and…

The White House on Quantum Encryption and IoT Labels

A recent White House Fact Sheet outlined the current and future U.S. cybersecurity priorities. While most of the topics covered were in line with expectations, others drew more attention. The emphasis on critical infrastructure protection is clearly a top national priority. However, the plan is to create a labeling system for IoT devices, identifying the ones with the highest cybersecurity standards. Few expected that news. The topic of quantum-resistant encryption reveals that such concerns may become a reality sooner than…