December 4, 2019 By Shane Schick 2 min read

An in-app security vulnerability dubbed StrandHogg is being exploited in at least 36 Android apps and triggering malicious code, researchers warned.

Initially discovered by Promon and Lookout, the flaw allows cybercriminals to take advantage of the way Android handles more than one process at a time, depending on which app is being displayed to a user. This means that, even while using a legitimate app, victims could be activating malware that shows phishing pages or asks for permissions that give cybercriminals unauthorized access to their device.

StrandHogg was discovered after financial institutions in the Czech Republic said they were seeing money disappear from customers’ accounts, the researchers said.

Second-Stage Payloads

The attacks most likely began after Android users downloaded malicious apps through the Google Play store, according to the report. Apps infected with StrandHogg were then downloaded separately, rather than through Google Play. This makes them second-stage payloads, according to the research.

All it takes is a tap of an app icon for the malicious code to execute through a feature in Android called task reparenting. Smartphone users probably wouldn’t notice this, however, and might easily assume any login screens or permission requests that pop up are legitimate.

Developers with the Android project were informed of the flaw more than three months ago but have yet to issue a fix, researchers added.

Unfortunately, StrandHogg could be used to wage malware attacks through the 500 most popular apps in the Google Play store, according to the report. This is true across all versions of Android up to the most recent, Android 10. Root access is unnecessary for the bug to be exploited, based on the researchers’ findings.

Stop StrandHogg Before It Starts

IBM experts recently noted a rise in evil downloaders in the Android mobile malware kill chain and suggested taking a close second look at apps that might be fake. These often betray themselves with a small file size and badly written descriptions, as well as design that looks a lot poorer in quality than legitimate apps.

If you’re not sure whether a device has been infected, though, there are tools available to detect malicious apps and identify those that would have been blacklisted by an IT department.

More from

Bypassing Windows Defender Application Control with Loki C2

10 min read - Windows Defender Application Control (WDAC) is a security solution that restricts execution to trusted software. Since it is classified as a security boundary, Microsoft offers bug bounty payouts for qualifying bypasses, making it an active and competitive field of research.Typical outcomes of a WDAC bypass bug bounty submission:Bypass is fixed; possible bounty awardedBypass is not fixed but instead "mitigated" by being added to the WDAC recommended block list. Likely no bounty awarded but honorable mention is typically givenBypass is not…

FYSA — VMware Critical Vulnerabilities Patched

< 1 min read - SummaryBroadcom has released a security bulletin, VMSA-2025-0004, addressing and remediating three vulnerabilities that, if exploited, could lead to system compromise. Products affected include vCenter Server, vRealize Operations Manager, and vCloud Director.Threat TopographyThreat Type: Critical VulnerabilitiesIndustry: VirtualizationGeolocation: GlobalOverviewX-Force Incident Command is monitoring activity surrounding Broadcom’s Security Bulletin (VMSA-2025-0004) for three potentially critical vulnerabilities in VMware products. These vulnerabilities, identified as CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226, have reportedly been exploited in attacks. X-Force has not been able to validate those claims. The vulnerabilities…

SoaPy: Stealthy enumeration of Active Directory environments through ADWS

10 min read - Introduction Over time, both targeted and large-scale enumeration of Active Directory (AD) environments have become increasingly detected due to modern defensive solutions. During our internship at X-Force Red this past summer, we noticed FalconForce’s SOAPHound was becoming popular for enumerating Active Directory environments. This tool brought a new perspective to Active Directory enumeration by performing collection via Active Directory Web Services (ADWS) instead of directly through Lightweight Directory Access Protocol (LDAP) as other AD enumeration tools had in the past.…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today