this post was submitted on 11 Dec 2025
13 points (100.0% liked)

Cybersecurity

8766 readers
115 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 2 years ago
MODERATORS
top 5 comments
sorted by: hot top controversial new old
[–] DemBoSain@midwest.social 11 points 22 hours ago (1 children)

Android users are advised not to side-load APKs from outside Google Play unless the publisher is a trusted source.

I'm going to be upset if we learn someone at Google is behind this.

[–] Peruvian_Skies@sh.itjust.works 8 points 22 hours ago

Don't worry, we won't learn that. Even though it's probably true.

[–] specialwall@midwest.social 1 points 16 hours ago

The malicious apps introduce the main payload via an update request and then ask for Device Admin and Accessibility Services permissions, which let it to perform fraudulent activities.

So to get compromised, you have to give an untrusted app full control of your computer? For a moment, I thought another actual permissionless vulnerability might have been discovered, but it seems not.

[–] AmbiguousProps@lemmy.today 1 points 17 hours ago (1 children)

It looks like you have to grant it full access to get it to "lock" your phone. If I installed an app and it prompted me for that for no reason, I would immediately uninstall.. but I guess if you have no idea what you're doing and are able to get as far as installing a third party apk, it could get you.

I wonder if it can be removed with adb.

[–] Pika@sh.itjust.works 1 points 11 hours ago

it wouldn't matter sadly. the program changes the pin on the device, the only solution would be a factory wipe and restore from backup if it's given full access.